Cybersecurity · Wednesday, 26 August 2026
01 · Briefing · what happened
A British power plant went off for four days. The break-ins that did nothing are the bigger story.
Iran-linked hackers stopped a small UK generator for four days in July. The same week, five US agencies said the same kind of intruder is sitting inside American plants, causing no damage at all.
4 days
the British plant stayed off
a small generator, no wider grid impact
3 weeks
before the public heard
no regulated operator reported an outage
6
Iranians sanctioned by the US
named as working for the intelligence ministry
274
Zimbra servers found broken into
the fix had been available since 20 July
At a glance
-
Iran-linked hackers shut a small British power plant down for four days in July; nobody lost power
[1] [3] [4] . -
It stayed secret for three weeks; the NCSC had no reported outage from any regulated operator
[4] . -
Smaller plants can sit below mandatory reporting, so the true count of attacks is unknown
[5] . -
The US then sanctioned six men it says hack for Iran's intelligence ministry
[2] . -
Five US agencies named an active threat to Siemens S7 controllers, which run pumps and turbines
[6] [7] . -
The agencies found no damage - only patient looking around, ahead of attacks later
[8] . -
Attackers are using AI to write the break-in scripts, cutting the skill needed
[6] [8] . -
CISA twice gave federal agencies just three days to patch flaws already under attack
[9] [11] . -
274 Zimbra email servers were found compromised, with about 8,200 still unpatched
[10] . -
A US health records firm's breach grew from about 350,000 people to 3.76 million
[12] . -
Interpol arrested 58 people and named 263 suspects across three continents
[13] [14] . -
QR-code scam reports are up 700% in four years; RingGo puts no codes on parking signs
[16] [17] .
Forces in play
one UK plant off four days; US water systems hit in a dozen states
five agencies found looking around, not damage, inside industrial controllers
CISA cut its deadline to three days twice in one week
a four-day outage took three weeks and a newspaper to surface
How it unfolded
-
July
a small British power plant is shut down for four days
[3] -
Late July
Iran-linked intruders disrupt more than 30 water sites in Minnesota
[1] -
19 Aug
five US agencies warn of an active threat to Siemens S7 controllers
[6] -
22 Aug
the Telegraph reveals the British outage
[3] -
24 Aug
the US sanctions six alleged Iranian intelligence hackers
[2]
Where this points
Watch whether Britain widens who has to report an outage - the next test is whether a small operator's four-day stop reaches the NCSC without a newspaper
Full briefing
Four days, and nobody was told
Hackers linked to Iran shut down a small British power plant for four days in July
The three-week delay is itself a finding. The National Cyber Security Centre is understood to have received no reported outage from any regulated power operator
Then the trail arrived
Two days after the story, the US Treasury sanctioned six men it says work inside Iran’s Ministry of Intelligence and Security
Five US agencies then published something sharper. The NSA, FBI, CISA, the environment agency and the Department of Energy named an “active threat” to Siemens S7 controllers, the small computers that run pumps, valves and turbines
The detail that matters is what the agencies did not find. No damage. They describe “persistent reconnaissance” — patient looking around, in preparation for attacks later
The clock on a fix keeps shrinking
CISA gave federal agencies three days to patch a Zimbra email flaw already under attack, after Poland’s emergency response team flagged it
Elsewhere: CareCloud’s health-records breach grew from roughly 350,000 people to 3,756,469 as the US health department’s tracker updated
Closer to home
QR-code scam reports are up 700% in four years
Kaspersky found the first malware written specifically for car dashboard systems, delivered through a hijacked update channel and used to rent out the car’s connection
02 · Lesson · why it matters
The way in is worth more unused
Breaking in buys a position, not a result. Cash it and you get one visible event - and everyone else learns exactly what to look for.
How it works
- Break in quietly and cause no damage
- You now hold a position, not a result
- Using it produces one visible event
- The event names you and your method
- Everyone else patches; your other ways in close
- So the position was worth more unused
The twist
Breaking in is not the attack - it is buying the right to one. Cash it and you get a single outage, plus an advisory that closes every other door you were holding.
Where you've seen this
A spare key an ex still has
worth nothing once used, because then you change the locks
A journalist's confidential source
one story burns the access that could have carried ten
A country's secret listening post
acting on what you heard tells the other side you were listening
The catch
It only holds where using the access reveals it. A thief who can take money quietly keeps taking it, and holding back buys them nothing.
Full lesson
A small plant, and a very loud silence
A British generator stopped for four days in July. No lights went out. No regulated operator filed a report. Nobody outside a small circle knew until a newspaper printed it on 22 August.
Then, within days, the whole shape of it was public. Six men named and sanctioned. Five American agencies publishing the make and model of the equipment under attack. Every operator in two countries handed a checklist: find your controllers, take them off the internet, go looking for someone already inside.
That sequence is the lesson. It ran in that order for a reason.
What breaking in actually buys
We talk about a break-in as if it were the harm. Usually it is not. Getting inside the computers that run a pump or a turbine does no damage on its own. It gives you the ability to do damage, at a moment you choose.
That is a position, not a result. It sits there. It costs almost nothing to keep. And its whole value is that nobody knows it exists.
Compare it to a spare key. A key you hold is worth something every day you hold it, because every door it opens is still available to you. The moment you use it to walk into someone’s house while they are home, you have swapped all of that for one entrance - and they change the locks.
Using it is how you lose it
Look at what the four days cost the people who caused them.
Before: a quiet capability inside a plant, unknown, reusable, and shared with nothing. After: a newspaper story, a sanctions list with six names on it, an indictment. Then a joint advisory from five agencies, naming the exact family of controllers and the exact style of tooling.
The outage was real. It was also, from the attacker’s side, a conversion - a durable secret turned into one temporary event plus a great deal of information handed to the other side. Any other plant they were sitting inside just became harder to sit inside, because every operator now has a list and a reason to use it.
This is not a mistake by the attacker. It is the price of the thing. Some capabilities can only be spent, never used.
Which is why the alarming part is the quiet part
The same week, the American agencies said something easy to skim past. They had found no high-impact attacks through the route they were describing. What they had found was persistent reconnaissance - patient looking around, in preparation for later.
Read through the lesson above, that stops being reassuring. An absence of damage is exactly what a held position looks like from the outside. It is also what an empty building looks like. From the damage alone, you cannot tell those apart.
So “nothing has happened to us” is not one piece of evidence. It is two very different worlds wearing the same face, and the only way to tell them apart is to stop watching for events and start looking for presence.
You are inside this too
Nothing here needs a government to work.
A password of yours that leaked two years ago and has never been used against you may mean it was worthless. It may mean it is being kept. The old cloud account with your files in it, still logged in on a device you gave away, is a position somebody may be holding without ever having touched it. Every account of yours that has been quiet is quiet for one of two reasons, and your inbox cannot tell you which.
The practical move is small and unglamorous. Sign out old sessions. Remove devices you no longer own. Turn on the alerts that fire when someone logs in, not just when money leaves. Those look for presence, not damage.
The line somebody drew
One more thing sits underneath the British story, and it is not a technical failure.
The plant was small. Small enough, apparently, to fall outside the rules that oblige an operator to tell the national cyber agency when something goes wrong. That threshold is not a fact about the world. It is a line somebody chose, and it was probably chosen sensibly - you cannot ask every operator of every generator to file a report about everything.
But the line decides what the country can count. And what a country cannot count, it will tend to believe is not happening. The agency’s own view of how often the grid is attacked is shaped by a definition written years earlier for reasons that had nothing to do with Iran.
Nobody in this story can see all of it. The operator saw four days of their own plant. The agencies saw controllers with strangers in them and no idea which ones would ever matter. The attacker, holding whatever else they hold, does not know which of those positions will still be there next year, or which one a routine inventory will quietly take away. Everyone is working from their own small window, and confident conclusions are what you get when you mistake a window for a view.
03 · Lab · your turn
The Held Position
Rehearse holding a quiet way in and deciding when, if ever, to spend it - and feel what spending it costs everywhere else.
04 · Hope · carry this
The advisory that came out of this went to everyone, not only the operators large enough to be asked. Knowing what to look for used to be a privilege of the well-connected; more and more it is simply published.
More from Cybersecurity