NEWYou can now listen to Fox News articles!
Iran-linked hackers are suspected of forcing a small British power generator offline for four days last month, the latest sign that Tehran-linked cyber activity may be moving from probing vulnerable systems to causing disruptions U.S. officials have long warned about.
Iran-linked hackers were behind the outage, according to British security officials who spoke with multiple news outlets.
“To be clear: there was no threat to the wider grid and nobody lost power. We have one of the most resilient energy systems in the world,” UK Energy Minister Michael Shanks said in a statement.
He described the generator as “tiny” but said his department had briefed CEOs following the intrusion on “steps they should take to stay secure.”
WATER CYBERATTACK HITS AT LEAST 7 STATES
The British shutdown came weeks after hackers struck more than 30 community water systems in Minnesota, accessing technology used to remotely monitor and control pumps and other equipment. Minnesota officials have not publicly attributed the attacks. Several news outlets, citing U.S. officials and a leaked industry threat-sharing memo, reported that Iran was the likely culprit. President Donald Trump has publicly rejected that assessment, saying he did not believe Iran was to blame.
Together, the incidents are putting civilian infrastructure at the center of another front in the conflict between the U.S. and Iran. As the military confrontation stretches into its sixth month, relatively small and often lightly defended water and energy facilities offer hackers a way to cause physical disruption without penetrating a major power grid or striking a military target.
Those facilities can be especially vulnerable because many rely on internet-connected industrial control systems that allow operators to monitor and manage physical equipment remotely. Once inside, hackers can interrupt operations, lock out operators or manipulate controls for pumps and other machinery.
In a July alert, the FBI and Environmental Protection Agency said malicious actors had targeted water and wastewater utilities in at least seven states by accessing exposed programmable logic controllers and changing their internet addresses and passwords. Some incidents disrupted water operations, causing reported pressure loss and flooding.
Federal agencies have also warned that Iranian-affiliated actors have targeted similar industrial devices across water, energy and government sectors, seeking access to the software used to control them. That activity has already caused operational disruptions and financial losses.
IRAN’S PROXY WAR HAS CROSSED OCEANS AND IS NOW KNOCKING ON AMERICA’S DOOR

Iranian hackers have pursued U.S. infrastructure before.
The threat extends beyond industrial systems. On Aug. 18, the Justice Department charged 17 members of an Iran-based company with carrying out a sweeping cyber theft campaign targeting hundreds of universities, private companies and government agencies. Prosecutors said many of the intrusions were conducted on behalf of the IRGC and other Iranian entities and resulted in the theft of more than 31 terabytes of academic data and intellectual property.
In 2016, the Justice Department charged an Iranian hacker with gaining access to the control system for a dam in Rye, New York. The dam’s sluice gate had been disconnected for maintenance at the time, preventing him from manipulating water levels and flow rates.
More recently, U.S. agencies linked an IRGC-affiliated campaign known as CyberAv3ngers to compromises of Israeli-made industrial controllers at dozens of U.S. facilities in late 2023 and early 2024, including water and wastewater systems, energy companies, food manufacturers and health care organizations. The campaign exploited devices exposed to the public internet that were still using default passwords.
SIGN UP TO GET THE POLITICS NEWSLETTER
The more recent attacks underscore how little access may be required to produce a physical effect. In Minnesota, compromised controllers affected systems used to track water levels, pressure, pump operations and equipment alarms; in some communities, equipment was temporarily taken offline while operators restored systems.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Whether Tehran intends a wider campaign against Western infrastructure remains unclear. But the four-day shutdown in Britain illustrates what hackers can do once they gain access to a small industrial system: disrupt physical operations without breaching a major grid operator or triggering a blackout large enough to invite an immediate military response.
Read the full article here


