In late July, Iranian hackers broke into a British power plant's control systems and knocked it offline. It stayed dark for four days. The story didn't break until the London Telegraph reported it on August 22 — nearly a month later.
And it wasn't the only thing they hit.
The attack — believed to be the first time hackers affiliated with the Iranian regime successfully shut down a power generation facility in the United Kingdom — coincided with a coordinated cyber assault on over 30 community water utilities across 12 states here in the U.S. Same window. Same adversary. The NY Post reported that experts say the hacks reveal a critical weak spot on both the American and British grids, with Iran aiming to "maximize disruption."
Joe Slowik, Director of Threat Research at Dataminr, didn't mince words. "It is not a secret that these things have been taking place since the spring," Slowik said. "There have been disruptions in multiple critical infrastructure sectors. It's a big deal."
A big deal. That's one way to put it.
The British government's response was a masterclass in bureaucratic minimization. An unnamed government source told reporters, "We have thresholds for important generators to legally notify us of cyber activity, and this site is nowhere near. It's a very small-scale site, less than a rounding error compared to grid capacity." UK Minister of State Michael Shanks, whose title alone — Department for Energy Security and Net Zero — tells you everything about his priorities, offered this after the fact: "After the incident, we briefed energy CEOs and shared further advice with companies on the steps they should take to stay secure."
Briefed energy CEOs. Shared advice. Four days of an enemy state controlling your power infrastructure and the official response is a PowerPoint presentation.
But the cybersecurity professionals who actually understand what happened aren't buying the "nothing to see here" framing. Phil Tonkin, Field CTO at the industrial cybersecurity firm Dragos, pointed to the real danger: "The loss of a single facility like this can be well managed and as reported, doesn't constitute a major risk to stability, but these are often very repeatable attacks that could be deployed at scale."
Repeatable. At scale. That's the phrase that should keep people up at night.
James Griffiths, a former adviser at GCHQ — Britain's signals intelligence agency — and founder of UtopianKnight Consultancy, flagged something the government glossed over entirely. "Although nothing has been released about how this happened, what is interesting is that it took four days for the power plant to come back online." Four days isn't a glitch. Four days means they got deep enough into the operational systems that the facility couldn't just flip a switch and restart.
Muhammad Yahya Patel, a cybersecurity advisor at Huntress, stripped away the government spin completely: "The significance isn't the size of the facility, but that a cyberattack turned into four days of real-world operational disruption."
Meanwhile, UK Security Minister Dan Jarvis acknowledged in an April 2026 speech that "the nature of the threat is changing faster than any previous government has had to confront. AI is lowering the barrier to entry." So the British government knows the threat is accelerating. They said so publicly four months before Iranian hackers proved it.
Kurt Gaudette, Head of Intelligence at Dragos, described the targets as "very low-hanging fruit" — vulnerable systems including small utilities using default passwords with internet-exposed controllers. Default passwords. In 2026. On power generation infrastructure. In a country currently in an active military conflict with Iran, which fired ballistic missiles at the British territory of Diego Garcia as recently as March 2026.
The parallel American attacks hit over 30 municipal water systems. The Iran regime reportedly spends tens of millions per year funding hacking groups. And our critical infrastructure — water, power, the systems that keep a modern country functioning — is protected in some cases by the digital equivalent of leaving your front door unlocked with a welcome mat.
The British government's answer is the Cyber Security and Resilience Bill, expected to pass into law in late 2026. The Iranians are inside the grid now. Parliament is drafting legislation.
One side is moving at the speed of warfare. The other is moving at the speed of government.