NewsMacroIran-linked hackers behind attack on UK energy facility

Iran-linked hackers behind attack on UK energy facility

Author: City AM Markets·

Key Takeaways

  • The attack is believed to be the first time Iranian-affiliated hackers have successfully shut down a UK energy facility.
  • The affected site was described by the government as a small-scale energy generator and was not considered critical infrastructure.
  • Officials said the wider energy system and overall power generation were never put at risk.
  • The government declined to identify the facility for national security reasons and sent advice to businesses and power company chief executives after the attack.
  • The NCSC has warned UK organisations to prepare for collateral impacts from Iran-linked hacking and said it has handled more than 200 cyberattacks on UK critical infrastructure in the year to May.
Iran-linked hackers behind attack on UK energy facility

An attack on an energy facility that was shut down for four days last month was carried out by hackers linked to the Iranian regime.

The cyberattack is believed to be the first time Iranian-affiliated hackers have successfully infiltrated a UK energy facility and shut it down. The incident adds to growing concern about how state-linked cyber activity can affect organisations outside the immediate target country, with UK officials already warning that fallout from regional conflicts can spill into domestic networks and services.

A government spokesperson for the Department for Energy Security and Net Zero (DESNZ) said the energy facility was a “small scale energy generator.” The spokesperson added that “at no point was there a risk to the wider energy system” or the country’s overall energy generation. It is understood that the site is not critical infrastructure.

Government officials would not confirm which site was affected, citing national security concerns. In response to the attack, the government wrote to businesses and issued advice to chief executives at power companies.

The cyberattack reportedly took place at the same time as a series of other attacks on US water infrastructure that affected 12 American states, according to the Telegraph.

Warnings over ‘collateral impacts’ of Iran-linked hacking

In March, the National Cyber Security Centre (NCSC), part of GCHQ and responsible for responding to serious cyber attacks in the UK, raised concerns over cyber security threats from Iranian-linked hackers following the conflict in the Middle East.

The NCSC warned that UK organisations “should prepare to respond to the risk of collateral impacts in the UK from Iran-linked hacktivists.”

“Iranian state and Iran-linked cyber actors almost certainly currently maintain at least some capability to conduct cyber activity,” the NCSC said.

In a speech in June, NCSC chief executive Richard Horne said the agency had successfully dealt with more than 200 cyberattacks affecting the UK’s critical infrastructure in the year to May, and said three quarters of those attacks were linked to hostile states.

Earlier this year, Horne warned that the most significant cyber attacks in the UK have been carried out by hostile states including Iran, China and Russia.