A UK power plant went dark for four days in July. Around the same time, wastewater utilities in a dozen US states were fighting off intrusions that pushed pressure gauges to their limits and triggered boil-water notices. Trade press covered the two as separate stories: a British scoop about a first-of-its-kind outage, and an ongoing American saga about water-sector hacking. Read together, the coverage this past week says something neither story says alone: this is one campaign, run against the same class of exposed equipment, on both sides of the Atlantic, months after regulators told operators exactly how to close the gap.
What The Telegraph found, and who picked it up
The scoop belongs to The Telegraph, which reported that Iran-linked hackers disabled a small British power generation facility for four days, the first confirmed case of a cyberattack taking a UK electricity-generating asset offline. British officials declined to name the plant, citing security concerns, and said the outage did not touch the wider national grid because the facility was small. The attack is believed to date to late July.
Security Affairs picked up the Telegraph report and tied it explicitly to the concurrent US water-sector intrusions, framing the UK incident as a “proof of concept” for hackers linked to Iran’s Islamic Revolutionary Guard Corps: a test of whether they could reach and disable Western energy infrastructure, not just probe it. Infosecurity Magazine ran the same facts through a different lens, leading with a “wake-up call” framing and pulling in outside experts to assess what the incident says about UK preparedness. CNBC’s write-up of the Telegraph story added a detail the security trade press did not lead with: the UK’s Department for Energy Security and Net Zero has already briefed energy-sector chief executives, issued written guidance on strengthening defenses, and is now updating cybersecurity regulation for the sector.
Where the coverage splits
That is the point where the accounts diverge, and the divergence is itself informative. Security Affairs and Infosecurity Magazine both frame this as evidence of a widening capability gap. Infosecurity Magazine quoted Graeme Stewart of Check Point asking “what happens if the next target is bigger, more critical or more deeply connected,” and Muhammad Yahya Patel of Huntress warning that smaller critical national infrastructure (CNI) operators, the kind that ran the disabled plant, often sit below the reporting thresholds that would otherwise flag their exposure. James Griffiths of UtopianKnight went further, calling the breach “unfortunately inevitable” given years of underinvestment in UK CNI protection.
CNBC’s account, by contrast, reads as a story about a government already in motion: officials briefing industry, guidance already issued, regulation already being rewritten. Put the two framings side by side and the disagreement is not about the facts, it is about whether the response is ahead of the threat or behind it. Both cannot be fully true at once, and neither outlet resolves the tension.
Security Affairs’ framing leaned on numbers the NCSC itself had already put on the record. Two months before the plant incident, NCSC chief executive Dr Richard Horne told the Royal United Services Institute’s Annual Security Lecture that the agency had managed more than 200 incidents affecting UK critical national infrastructure in the year to May 2026, with roughly three-quarters linked to hostile states including Russia, China and Iran. Horne argued that treating cyber risk as a bounded problem misreads the fight: “this contest is not confined to a compact space. It is not like a wrestling match in a closely defined territory as some have suggested. It is far more akin to a football or basketball game, played across a large field of play, where success depends on how you operate across the entire pitch.” A single small power plant going dark for four days is, on that framing, one result inside a contest NCSC had already said was running at more than 200 incidents a year.
The same equipment, the same advisory, four months earlier
What none of the three accounts connects is the advisory that already covers the exact equipment class both incidents targeted. The Cybersecurity and Infrastructure Security Agency (CISA) has been warning since April about Iranian-affiliated actors, tracked as CyberAv3ngers and linked to the IRGC’s Cyber-Electronic Command, exploiting internet-exposed programmable logic controllers (PLCs) across US water, energy and government infrastructure. That advisory was updated on July 22, days before the UK plant reportedly went dark, to add Siemens and Schneider Electric devices alongside the Rockwell Automation controllers it originally covered, and to document for the first time that the attackers were exfiltrating engineering project files, not just flipping switches.
The advisory’s tactics section matches what showed up on the ground on the US side. Water utilities in states including Minnesota, Michigan, Georgia, South Dakota, New Jersey and Alabama reported pressure swings and, in several cases, boil-water notices after operators found unauthorized access to their control systems. The advisory describes attackers reaching PLCs over exposed Dropbear SSH services, pulling engineering project files off the devices, and manipulating human-machine interface (HMI) and SCADA logic to disable shutdown and alarm functions, exactly the kind of access that turns a routine pressure fluctuation into a facility that cannot automatically protect itself. None of the three trade-press accounts of the UK incident mention this advisory by name, even though it is the clearest public documentation of the access pattern both incidents share.
CyberTech reported in August on a related escalation: researchers found AI tools being used to generate exploit code against the same Siemens S7 controller family named in that advisory. The UK power plant incident and the 12-state US water campaign are not a new front opening up. They are the advisory’s threat model playing out on schedule, against operators who had four months of public warning and specific mitigation guidance, including removing PLCs from direct internet exposure, before either incident was reported.
What it means for the security leader
The through-line the individual stories miss is this: guidance issuance is not the same as guidance adoption, and the gap between the two is where both incidents happened. CISA published detection and mitigation steps for this exact PLC exposure pattern in April and widened them in July. The UK plant and the US utilities that got hit afterward were not victims of a novel technique. They were victims of the enforcement gap that Huntress’s Patel flagged: smaller CNI operators without mandatory reporting obligations, without dedicated OT security staff, and without the budget to segment internet-facing PLCs from the control network in the timeframe a government advisory assumes.
For a security leader running any OT or ICS environment, the actionable read is not “patch faster.” It is: treat a government advisory naming your equipment class as an assumed-breach timeline, not a recommendation. If a controller family named in AA26-097A sits on your network, verify today whether it has a routable path to the internet, whether its project files have ever been validated against a known-good baseline, and whether your organization would even meet the reporting thresholds that trigger outside help if it happened tomorrow. The lesson of this week’s coverage, taken together rather than one story at a time, is that the advance warning already existed. What did not exist was a mechanism to make operators act on it before the four-month clock ran out.
The staffing question compounds this. CyberTech reported last week that lawmakers have asked the Government Accountability Office to examine the effects of CISA staffing cuts. An agency stretched thinner is an agency less able to follow an advisory with the kind of direct operator outreach that might have closed this gap before July.
Source: National Cyber Security Centre

