A summary of mainstream reporting, plus the facts and perspectives it leaves out. A more honest account of each story.
Back to all stories
MAPNA Group (Persian: گروه مپنا) is a group of Iranian companies involved in development and execution of thermal and renewable power plants, oil & gas, railway transportation and other industrial projects as well as manufacturing main equipment including gas and steam turbines, electrical gener
Photo: Parsa 2au | CC BY-SA 4.0 | Wikimedia Commons

Iran-Linked Hackers Briefly Shut U.K. Power Plant In July Cyberattack

Iran-linked hackers took a small U.K. power plant offline for four days in July 2026, British outlets reported, in what officials said did not threaten the country's overall electricity supply.[1]

U.S. officials say Iranian-linked actors also targeted water systems in roughly a dozen U.S. states, including New Jersey, Minnesota, Georgia and South Dakota.[1]

In July 2026, British outlets reported the plant went offline for four days and that the affected site was a small, isolated generation facility. U.S. investigators said roughly a dozen water systems were probed and that attackers used basic techniques such as scanning for exposed programmable logic controllers and exploiting default credentials.

British outlets said this is the first time Iranian-linked hackers have taken a U.K. power plant offline.[1] Security agencies estimate millions of such industrial controllers are deployed worldwide across energy, water, manufacturing, hospitals and transport, leaving many systems vulnerable to simple scans and default passwords.

  1. CBS News
Cybersecurity and Critical Infrastructure Iran Conflict and U.S. Security
Show source details & analysis (1 source)

📌 Key Facts

  • British outlets report Iranian-linked hackers took a U.K. power plant offline for four days in July 2026
  • The affected facility is described as small-scale and officials say the attack did not disrupt the U.K.'s overall power supply
  • U.S. officials say Iranian-linked hackers also targeted water systems in roughly a dozen U.S. states in July, including New Jersey, Minnesota, Georgia and South Dakota
  • Both attacks targeted programmable logic controllers using basic methods like scanning for exposed devices and exploiting default credentials
  • Security agencies estimate millions of such industrial controllers are deployed globally across energy, water, manufacturing, hospitals and transport systems

📰 Source Timeline (1)

Follow how coverage of this story developed over time