{"id":9238,"date":"2026-08-27T08:25:00","date_gmt":"2026-08-27T08:25:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9238"},"modified":"2026-08-27T08:25:00","modified_gmt":"2026-08-27T08:25:00","slug":"critical-infrastructures-long-undefended-tail-exposed-by-uk-energy-attack","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9238","title":{"rendered":"Critical infrastructure\u2019s long, undefended tail exposed by UK energy attack"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">A cyberattack that forced a small British electricity generator offline for four days caused no power outage, threatened no part of the national grid, and may not even have been carried out by the Iran-linked hackers initially blamed.<\/p>\n<p class=\"wp-block-paragraph\">But the incident illustrates a consequential weakness in Western critical infrastructure. Thousands of small generators, water systems, and other industrial sites have aging operational technology<a> \u2014 <\/a>exposed programmable logic controllers, cellular modems, remote management systems \u2014 connected to the internet without the security programs protecting their larger counterparts, leaving easy targets during a period of geopolitical conflict.<\/p>\n<p class=\"wp-block-paragraph\">British newspapers <a href=\"https:\/\/www.telegraph.co.uk\/news\/2026\/08\/22\/iranian-hackers-shut-down-uk-power-plant\/\">reported that Iran-linked hackers attacked<\/a> the unidentified generator in July. The UK government confirmed an incident occurred but has not identified the facility, disclosed what the attackers did, or attributed the attack to Iran.<\/p>\n<p class=\"wp-block-paragraph\">Energy Minister Michael Shanks sought to tamp down some of the more alarming coverage, <a href=\"https:\/\/www.linkedin.com\/posts\/michael-shanks-130373344_the-telegraphs-reporting-today-relates-to-activity-7497258099339161601-RQoZ\/\">saying the generator was \u201ctiny\u201d<\/a> compared with what most people would consider a power plant. The government nevertheless <a href=\"https:\/\/www.reuters.com\/business\/energy\/uk-briefs-energy-chiefs-after-iran-linked-cyber-attack-reports-2026-08-24\/\">briefed energy executives<\/a> and began working with regulators and the National Cyber Security Centre to assess the threat and strengthen protections.<\/p>\n<p class=\"wp-block-paragraph\">The limited public information makes it impossible to determine whether the incident was an Iranian operation, an opportunistic intrusion by another actor, or something else entirely. An online persona calling itself APT Iran <a href=\"https:\/\/infosec.exchange\/@krypt3ia\/117151242333098613\">has denied responsibility<\/a>.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe don\u2019t have any forensic evidence of what actually happened,\u201d <a href=\"https:\/\/www.amazon.com\/dp\/B085RR67H5\">Josh Picolet<\/a>, VP of detection and S2 threat analysis at Team Cymru, tells CSO. \u201cWithout that, you have to assume it was serious enough to take offline.\u201d<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/www.linkedin.com\/in\/philip-tonkin\/\">Phil Tonkin<\/a>, field CTO at Dragos, tells CSO that the available information nevertheless indicates that the incident involved operational equipment and was similar to attacks targeting programmable logic controllers (PLCs) at US water facilities.<\/p>\n<p class=\"wp-block-paragraph\">But Tonkin cautions that the public account grew more dramatic as it passed among news organizations \u2014 evolving from an incident at a small energy facility into reports of an attack on a power plant or gas-fired peaking plant, despite the absence of official information supporting those descriptions.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhat we\u2019ve seen reported so far seems to have been a collection of hypotheses being reported and scaling,\u201d he says.<\/p>\n<h2 class=\"wp-block-heading\">From US water systems to UK generator<\/h2>\n<p class=\"wp-block-paragraph\">Whatever happened in Britain, it fits a pattern documented more concretely in the United States.<\/p>\n<p class=\"wp-block-paragraph\">The FBI and Environmental Protection Agency <a href=\"https:\/\/www.fbi.gov\/investigate\/cyber\/alerts\/2026\/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions\">said on July 30<\/a> that water and wastewater utilities in at least seven states had reported attacks against internet-facing Rockwell Automation MicroLogix 1100 and 1400 PLCs. Attackers changed IP addresses and passwords, causing operators to lose monitoring and control of connected equipment.<\/p>\n<p class=\"wp-block-paragraph\">CISA has since put the campaign\u2019s scale much higher, <a href=\"https:\/\/www.cisa.gov\/resources-tools\/resources\/exposure-reduction\">saying it<\/a> observed malicious activity targeting more than 100 internet-exposed water-sector systems in July. <a href=\"https:\/\/www.linkedin.com\/in\/sean-tufts-36b4909\/\">Sean Tufts<\/a>, field CTO at Claroty, tells CSO the security firm saw indicators of compromise on roughly 40 to 50 clients in the same campaign, a handful of which require formal incident response. \u201cWe\u2019re seeing them hit and have success,\u201d he says.<\/p>\n<p class=\"wp-block-paragraph\">Some attacks caused loss of water pressure and flooding, according to the agencies. At least one victim found altered PLC project files and discrepancies in the ladder logic controlling equipment. The operational consequences varied depending on what the controller managed and whether the facility could switch to manual operation.<\/p>\n<p class=\"wp-block-paragraph\">The government has not formally attributed all of those incidents publicly to Iran. But an earlier multi-agency advisory <a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa26-097a\">described Iranian-affiliated actors exploiting exposed PLCs<\/a> and using configuration software to make malicious changes.<\/p>\n<p class=\"wp-block-paragraph\">The reported number of affected states has also become disputed. APT Iran has acknowledged attacks in fewer states than some media accounts have reported while denying the UK intrusion \u2014 a curious combination of claiming some operations and disavowing others.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWhen we see groups like APT Iran or CyberAv3ngers self-attributing attacks, that doesn\u2019t mean it is the Iranian government,\u201d Tonkin says. \u201cIt doesn\u2019t really matter in terms of the defender. The defender needs to know what is vulnerable and how to defend those assets, because anybody can copy these methods.\u201d<\/p>\n<p class=\"wp-block-paragraph\">The ambiguity may itself benefit Iran. Relatively unsophisticated attacks can create headlines, uncertainty, and political pressure without producing the forensic clarity that might prompt a forceful government response.<\/p>\n<p class=\"wp-block-paragraph\">For attackers unable to match the conventional military power of the United States and its allies, cyber operations also offer a comparatively inexpensive way to bring a conflict into an adversary\u2019s home territory.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you pull it off in a meaningful way, it could be devastating,\u201d Picolet says. The intent, he speculates, could be \u201cto cause harm to your adversaries or maybe break your will\u201d by bringing the fight domestically, even if it remains in cyberspace.<\/p>\n<p class=\"wp-block-paragraph\">For now, the operations have been more disruptive than destructive. Their immediate value may lie in creating anxiety and earning publicity by displaying screenshots of compromised industrial systems.<\/p>\n<h2 class=\"wp-block-heading\">Critical infrastructure\u2019s long tail<\/h2>\n<p class=\"wp-block-paragraph\">The more significant commonality between the UK and US incidents is not necessarily the attacker. It\u2019s the target.<\/p>\n<p class=\"wp-block-paragraph\">In both countries, large electric utilities, oil and gas companies, and major manufacturers generally operate under regulations, formal risk-management programs, and security architectures designed to prevent industrial equipment from being placed directly on the public internet.<\/p>\n<p class=\"wp-block-paragraph\">Small municipal water systems, rural cooperatives, and community-owned facilities often have none of those advantages.<\/p>\n<p class=\"wp-block-paragraph\">Their digitization has produced real benefits. An engineer no longer needs to drive to a remote pumping station or generator to inspect its status. A cellular modem and remote-management interface allow equipment to be monitored and adjusted from miles away.<\/p>\n<p class=\"wp-block-paragraph\">The same connection can expose equipment designed decades ago, when its manufacturers never contemplated that it would face internet-based attackers.<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe thing that brought the efficiency has made those assets exposed,\u201d Tonkin says. \u201cIn smaller organizations, there is no governance to stop an engineer from doing it. Thousands and thousands of very vulnerable devices are connected straight to the internet.\u201d<\/p>\n<p class=\"wp-block-paragraph\">These smaller systems may individually be inconsequential to a national grid or water supply. Collectively, however, they create opportunities for widespread disruption, particularly if an attacker coordinates operations across numerous sites or exploits dependencies among power, water, manufacturing, transportation, and communications providers.<\/p>\n<p class=\"wp-block-paragraph\">Tufts points to <a href=\"https:\/\/www.csoonline.com\/article\/570705\/colonial-pipeline-shutdown-highlights-need-for-better-ot-cybersecurity-practices.html\">Colonial Pipeline<\/a> as a preview of that dynamic, wherein a ransomware attack on a single company operating one pipeline rippled into fuel shortages well beyond its own customers. \u201cIt was interrupting the super majors,\u201d he says.<\/p>\n<h2 class=\"wp-block-heading\">Get PLCs off the public internet \u2014 and prepare for manual operation<\/h2>\n<p class=\"wp-block-paragraph\">The most urgent protective measures are neither novel nor technically complicated.<\/p>\n<p class=\"wp-block-paragraph\">The <a href=\"https:\/\/www.fbi.gov\/investigate\/cyber\/alerts\/2026\/malicious-cyber-actors-targeting-water-and-wastewater-sector-internet--facing-programmable-logic-controllers-causing-operational-disruptions\">FBI and EPA<\/a> recommend removing PLCs from direct internet exposure and placing remote access behind a monitored gateway. Operators should secure cellular modems, replace default or weak passwords, restrict communications through firewalls or access-control lists, and place physical or software key switches in the run position to prevent unauthorized changes.<\/p>\n<p class=\"wp-block-paragraph\">Facilities should also preserve known-good copies of PLC programs, inspect running logic for alterations, and test their ability to operate equipment manually.<\/p>\n<p class=\"wp-block-paragraph\">Equipment that does not need to be exposed to the internet should be disconnected or placed behind a controlled management interface, Picolet says. Where equipment cannot be disconnected, operators need a tested alternative, he adds.<\/p>\n<p class=\"wp-block-paragraph\">\u201cIf you say you can\u2019t turn it off, then you better have a plan to go to manual mode or disable it if an event happens,\u201d Picolet says. Operators should identify exposed systems before an attacker does and make sure employees have practiced switching them into a safe manual state.<\/p>\n<p class=\"wp-block-paragraph\">That can be difficult for small utilities with few employees, limited technical expertise, and budgets funded by local ratepayers. Unlike major power companies, community-owned facilities may lack both a formal risk-management process and the economies of scale needed to build a conventional OT security program.<\/p>\n<p class=\"wp-block-paragraph\">The White House <a href=\"https:\/\/www.politico.com\/news\/2026\/08\/26\/white-house-program-private-companies-water-hacks-01050315\">is now preparing<\/a> a program that would enlist private cybersecurity companies to help water utilities identify and remediate exposed equipment.<\/p>\n<p class=\"wp-block-paragraph\">Larger infrastructure operators have a role as well. Although their CISOs do not directly control the security of a rural water plant or independently owned generator, their organizations may depend on those facilities \u2014 or be connected to them physically or digitally.<\/p>\n<p class=\"wp-block-paragraph\">\u201cCISOs and larger organizations can do a lot to think about who they are actually dependent on in their energy supply chain, and how they can bring those partners along,\u201d Tonkin says.<\/p>\n<p class=\"wp-block-paragraph\">He compared the needed approach with the mutual-aid agreements electric utilities use after major storms. Line crews from across the country help restore service in affected areas rather than leaving each utility to cope on its own.<\/p>\n<p class=\"wp-block-paragraph\">\u201cI think there\u2019s a big need for us to do more as a community in cyberspace to address some of these problems, because these smaller entities are very, very difficult to support,\u201d Tonkin says. \u201cThey haven\u2019t got the budgets, and they haven\u2019t got the resources.\u201d<\/p>\n<p class=\"wp-block-paragraph\">At the same time, those operators must protect themselves from risks they cannot directly manage, regardless of who the threat actor is.<\/p>\n<p class=\"wp-block-paragraph\">\u201cFrom a cyber defender standpoint, we don\u2019t care; it could be Martians, it could be Iranians, it could be Americans,\u201d Tufts says. \u201cWe need to be better, and if someone\u2019s proving they have these capabilities, then we need to take that warning.\u201d<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>A cyberattack that forced a small British electricity generator offline for four days caused no power outage, threatened no part of the national grid, and may not even have been carried out by the Iran-linked hackers initially blamed. But the incident illustrates a consequential weakness in Western critical infrastructure. Thousands of small generators, water systems, [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9239,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9238","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9238"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9238"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9238\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9239"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9238"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9238"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9238"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}