decrypted · 23 august 2026 · vulnerabilities and patching · uk policy and law · ai and llm security
The Iran-linked attack that kept a UK power plant dark for four days
Hackers linked to Iran kept a small British power generation site offline for four days last month: the first confirmed instance of Iran-affiliated attackers taking a UK electricity-generating facility out of action, according to reporting this week that the government has since confirmed in substance. The Department for Energy Security and Net Zero says the site was small-scale and the wider grid was never at risk, and it has written to power companies warning them of the threat. Almost everything else about the incident is still unconfirmed: which site, how the attackers got in, and whether the operator was ever obliged to tell anyone at all.
What's confirmed, and what isn't
DESNZ has acknowledged the outage, describing the site as small-scale and saying the UK's overall energy supply was never at risk. The National Cyber Security Centre, which leads on attacks against critical infrastructure, declined to name the site or describe how the attackers got in. Officials believe the operation was a proof of concept, a demonstration that hackers linked to Iran's Revolutionary Guard Corps can disable Western energy infrastructure rather than an attempt to cause blackouts. It landed around the same time as a wave of attacks on US water utilities in a dozen states, and after the UK let the US fly defensive operations against Iran from British bases, bases the IRGC had already called fair game.
None of that gives a UK director anything to act on directly. No CVE, no named vendor, no confirmed entry point. What matters more than the attribution is a detail buried in the coverage: the NCSC reportedly received no outage report from any regulated power station operator over this incident. Read plainly, that means the site that went dark for four days sat outside the category of operator required to tell the NCSC anything at all.
The edge a Secure by Design regime forgot
Segmentation between IT and operational technology is the usual Secure by Design answer to an intrusion at a generation site, and it is still the right one in general. But the sharper lesson here is legislative, not technical: Britain's cyber reporting duty for critical infrastructure has a size threshold, and this incident appears to have sat just below it. The Cyber Security and Resilience Bill, working through Parliament now, exists to pull operators like this one inside the regulatory net. Until it does, a small-scale generation site can go dark for four days with no formal channel back to the people whose job is to spot the pattern across sites. The fix here is not a technical control, it is a reporting duty set by consequence to the grid, not by the size of the individual site.
Also this week
Grok's agentic browser has an unpatched hole that a webpage can walk straight through. Researchers at Adversa AI found that hidden, encrypted instructions on a page can survive Grok's content filters, which cannot read ciphertext, then get decrypted inside the model's own code sandbox and treated as trusted output rather than untrusted input. In roughly 40% of around 20 attempts since June, the trick got Grok to smuggle a user's name, rough location, subscription tier and live conversation history to an attacker's server via a crafted URL. Adversa reported it to xAI on 3 June; follow-ups on 4 and 10 August went unanswered, and the flaw was still reproducible on 19 August. The lesson generalises beyond Grok: anything an agent decrypts or executes on a user's behalf is still someone else's input, however trusted the sandbox looks from the inside.
CISA's deadline to patch two actively exploited TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, fell today for the first of the pair. The first is an unauthenticated remote code execution bug reachable over TCP port 4307 via an undocumented function; the second lets an attacker break out of that sandbox to run OS-level commands. Kaspersky has tied both to the Head Mare hacktivist group, which used the chain to replace legitimate TrueConf client installers with trojanised copies and infect meeting participants directly. Any UK organisation running TrueConf, including public bodies that favour self-hosted platforms for data residency, should treat CISA's federal deadline as their own.
The Cyber Security and Resilience Bill reaches Committee Stage in the House of Lords on 1 September, having cleared the Commons in June. It extends the 2018 NIS Regulations to data centres above 1 megawatt of IT load, medium and large managed service providers, large-scale energy load controllers, and critical suppliers designated by regulators, with a tight incident reporting clock: an initial notification within 24 hours, a full report within 72. It will not apply retrospectively to the power plant above, but it is the mechanism built to stop the next one falling through the same gap.
Sources
- Iran-linked hackers accused of cyberattack that shut down British power plant
- UK Power Plant Disabled for Four Days by Iran-Linked Hackers, Concurrent with US Water Attacks
- UK Power Plant Cyber Attack: Energy Security Concerns
- Grok chat history leak: Cryptographic Context Injection
- CISA orders feds to patch actively exploited TrueConf Server flaws
- The Cyber Security and Resilience Bill: understanding the UK's legislative response to digital threats
Working through what a critical infrastructure or AI security incident would mean for your own organisation? Get in touch.
More like this
- A crafted email is all it takes to root Cisco's mail gateway 15 september 2026
- The AI test that broke into a real company because it couldn't stop 11 september 2026
- A default password was the only thing standing between the internet and 220 million passports 9 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.