For four days in July, a small UK power plant went dark — not from equipment failure, but from a cyberattack that media outlets including The Telegraph and the BBC have linked to Iran-affiliated hackers. The target wasn't the national grid. It was the facility's PLC — the industrial computer that acts as the brain of a plant's control systems — which attackers reportedly hijacked, blocking normal failover operations until staff manually clawed back control. The UK government confirmed the incident but has not formally attributed it to Iran.

The official reassurance about grid resilience tells only part of the story.

While officials from the Department for Energy Security and Net Zero stressed the wider grid was "never at risk," Energy Minister Michael Shanks still found it necessary to brief energy CEOs and issue fresh security guidance. That's not nothing.

What the government statements don't fully capture is the scope:

UK plant was offline four days in July; the facility name and precise attack method remain undisclosed

Attackers reportedly targeted the PLC controlling the plant's backup power systems

More than 30 US water facilities were disrupted in late July; incidents spread across at least 12 states

Attacks exploited internet-exposed PLCs, frequently using default or weak credentials

Neither UK nor US governments have formally attributed the attacks to Iran

Cynthia Kaiser, former FBI cyber official now at Halcyon Ransomware Research Center, describes the pattern plainly: Iran-affiliated actors are targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society." Private-sector analysts assess this isn't opportunistic crime. It's a deliberate campaign tied to Middle East tensions — pressure applied through infrastructure rather than missiles.

"This is not a theoretical risk — it is an active threat." — Joint US Advisory AA26-231A (NSA, CISA, FBI, DOE, EPA), August 2026

Attackers no longer need deep technical expertise — AI is filling the gap for them.

Using open-source tools like python-snap7 combined with AI-assisted scripting, attackers are now generating custom exploits targeting Siemens S7 Series PLCs — the industrial controllers underpinning water treatment, energy generation, chemical plants, and food production across multiple critical sectors. These tools disguise themselves as legitimate monitoring software while providing read/write access to plant controls. Think of it like Canva for industrial sabotage: AI handles the hard parts, dramatically cutting the skill and time required to build a working exploit.

That means groups that previously lacked the technical chops to target a power plant may not need them anymore.

US and UK agencies are urging operators to:

Pull PLCs off direct internet exposure

Treat any unfamiliar OT "monitoring" tool as a potential exploit framework until proven otherwise

The four-day UK outage makes the case for urgency more concisely than any advisory could.

The plant was small. The grid held. But the technique that took it offline is now cheaper, faster, and within reach of a far longer list of adversaries than it was six months ago. Official reassurance is fine. Assuming it stays that way isn't.

From the coolest cars to the must-have gadgets, GadgetReview's daily newsletter keeps you in the know. Subscribe - it's fun, fast, and free.