Center for Infrastructure Security in the Era of AI

Iran-Linked Hackers Blamed for Cyberattack That Shut Down UK Power Plant

Hackers linked to Iran have been blamed for a cyberattack that temporarily shut down a British power plant. The incident affected a small-scale energy generator, which was reportedly offline for four days following the attack. The UK Department for Energy Security and Net Zero said the incident did not pose a risk to the wider energy system and emphasized that the country’s energy infrastructure remained resilient.

The incident occurred amid heightened tensions between Iran and the United Kingdom following the UK’s decision to allow the United States to conduct defensive operations against Iran from British bases. UK officials have previously warned that Iran and other hostile states are increasingly targeting systems supporting essential services, while U.S. cybersecurity agencies have also warned of threats to critical infrastructure from actors linked to Iran’s Islamic Revolutionary Guard Corps.

Why it matters: The incident demonstrates that cyberattacks can produce direct operational effects on energy infrastructure even when disruption remains localized. The reported four-day shutdown highlights the importance of protecting generation assets from cyber threats and maintaining operational resilience as geopolitical tensions increasingly translate into cyber activity targeting critical infrastructure.

Source: The Guardian
Author: Ben Quinn
Published: August 23, 2026

Japan Outlines Measures to Protect Infrastructure From Cyberattacks

Japan has drafted new cybersecurity guidelines outlining approximately 150 measures for businesses operating critical infrastructure. The guidelines cover sectors including finance, railways, electricity, and other essential services and warn operators that even closed networks disconnected from the internet are “not necessarily safe.” Companies are urged to prepare for system failures and strengthen their ability to recover from successful attacks rather than relying solely on preventive defenses.

The draft also addresses emerging and systemic risks, recommending measures to mitigate the financial impact of ransomware attacks while discouraging ransom payments. It calls for defenses to evolve in response to cyberattacks using advanced AI models and recommends preparing for the transition to post-quantum cryptography as quantum-computing capabilities advance. Japan’s National Cybersecurity Office developed the guidelines to support more consistent cybersecurity standards across critical-infrastructure sectors.

Why it matters: Japan’s approach reflects a shift from primarily preventing cyberattacks toward ensuring that critical services can continue and recover when defenses fail. The emphasis on closed-network risks, ransomware resilience, AI-enabled threats, and post-quantum security illustrates how governments are broadening critical-infrastructure cybersecurity requirements to address both current operational risks and emerging technologies.

Source: The Japan Times
Author: Jiji
Published: August 24, 2026

U.S. Agencies Warn of Hackers Actively Attacking Siemens S7 PLCs in Critical Facilities

U.S. cybersecurity and intelligence agencies warned that threat actors are actively targeting Siemens S7 Series programmable logic controllers used across critical infrastructure. According to a joint advisory from the NSA, CISA, the FBI, the Department of Energy, and the Environmental Protection Agency, attackers are using internet-scanning services to identify exposed or poorly segmented PLCs and AI-assisted tools to generate exploitation scripts capable of interacting with the devices.

The activity has primarily involved reconnaissance, capability development, and testing against PLCs rather than confirmed destructive attacks. The agencies said the actors are using open-source industrial automation libraries to obtain read/write access to PLC memory, configurations, and ladder logic. Sectors most affected include critical manufacturing, energy, water and wastewater, chemicals, food and agriculture, and commercial facilities.

Why it matters: AI-assisted development can reduce the expertise and time required to create tools for attacking industrial control systems. Because PLCs directly control physical processes, successful exploitation could lead to operational disruption, safety incidents, equipment damage, or cascading effects across interconnected infrastructure.

Source: Cyber Security News
Author: Guru Baran
Published: August 20, 2026