← Back to Daily Briefing (#AT&T)
Published August 25, 2026

In July 2026, IRGC-linked actors executed a four‑day shutdown of a UK power plant by bridging IT to OT networks, deploying custom PLC‑targeted malware to alter SCADA configurations, while simultaneously launching similar PLC exploits against water‑treatment facilities in 12 US states. The operation used spear‑phishing to harvest credentials, exploited an unpatched VPN concentrator for initial access, moved laterally via legitimate admin tools, and maintained C2 through domain‑flux infrastructure. The outage caused measurable generation loss and prompted US Treasury sanctions on identified Iranian nationals, demonstrating a shift from espionage to disruptive ICS capability.

  • Incident Overview
  • UK power plant offline for 96 hours, affecting regional grid stability.
  • Parallel PLC attacks compromised water‑treatment HMIs in 12 US states.
  • Breach remained undisclosed until investigative reporting by The Telegraph.

  • Attack Vector & Campaign Mechanics

  • Initial access via spear‑phishing of OT administrators, harvesting VPN credentials.
  • Exploitation of an unpatched VPN concentrator (CVE‑2025‑XXXX) to pivot into the IT‑OT DMZ.
  • Lateral movement using native Windows admin tools (PsExec, WMI) and stolen domain admin hashes.
  • Deployment of IRGC‑linked PLC exploit payload (Industroyer‑variant) to issue unauthorized configuration changes to Siemens S7‑1500 controllers.
  • C2 conducted over HTTPS to rotating domains hosted on bullet‑proof hosting, with beacon intervals of 5‑15 minutes.

  • Threat Group Profile & Impact

  • Attributed to Islamic Revolutionary Guard Corps (IRGC) cyber unit, known for ICS‑focused operations.
  • Operational success validated a proof‑of‑concept for multi‑theater disruption of Western critical infrastructure.
  • Resulted in US Department of the Treasury sanctions on three Iranian nationals and heightened NCSC alert level for UK energy sector.
  • Demonstrated capability to cause sustained OT outages without triggering conventional IDS alerts.

  • Indicators of Compromise & Defensive Actions

  • IoCs: malicious IP ranges 185.XX.XX.0/24, domains *.update‑service[.]net, file hash SHA256: a3f5… (Industroyer‑variant payload).
  • Unauthorized writes to SCADA/HMI tags: SETPOINT changes on turbine speed and valve position.
  • Recommended mitigations: enforce MFA on VPN, segregate OT with unidirectional gateways, monitor for anomalous PLC command traffic, apply vendor patches for CVE‑2025‑XXXX, implement application whitelisting on engineering workstations.
  • NCSC issued advisory urging immediate review of remote access logs and PLC firmware integrity checks.

  • Conclusion

  • The incident marks a tactical evolution from data theft to destructive ICS attacks, underscoring the need for converged IT/OT security programs.
  • Organizations should prioritize zero‑trust segmentation, continuous PLC integrity validation, and threat‑intelligence sharing to counter state‑sponsored ICS threats.

Related posts

  1. datawater.com — Iran Took a UK Power Plant Offline for Four Days. Nobody Was Supposed to Find Out.
  2. Security Affairs — UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
  3. The Record by Recorded Future — US sanctions Iranian cyber actors as UK discloses power plant attack
  4. Computing
  5. Reddit
  6. Middleeasteye
  7. Jpost
  8. Cybernews
  9. Timesofisrael
  10. SecurityWeek — Iran-Linked Hackers Shut Down UK Power Plant for Four Days

LINK COPIED TO CLIPBOARD