Iranian-affiliated hackers successfully disabled a power plant in the United Kingdom this past July, marking what British officials believe to be the first time such a facility has been forcibly taken offline by Tehran-linked cyber operatives.

The incident, which kept the power plant offline for four days while employees worked to restore control, remained unreported until this week. The facility’s identity has not been disclosed, though it is understood to be a small-scale operation that did not impact the broader national grid.

The British cyberattack occurred during the same month that Iranian-linked hackers targeted water systems across twelve American states, including New Jersey, Minnesota, Georgia, and South Dakota. Those intrusions locked out operators and caused pressure loss and flooding in multiple facilities.

The National Cyber Security Centre, Britain’s primary cybersecurity agency, declined to confirm or deny the reported breach when contacted for comment.

In both the British and American attacks, the hackers targeted programmable logic controllers, commonly known as PLCs. These specialized computers serve as the operational brains of automated industrial systems worldwide, controlling critical functions across energy, water, and manufacturing sectors. Their use extends far beyond these industries. Hospitals rely on PLCs to maintain power during blackouts. Chemical plants use them to regulate temperature and pressure, preventing potentially catastrophic explosions. They control elevator and train speeds, prison security gates, traffic light timing, and fire suppression systems.

Industry estimates place the number of PLCs in use worldwide anywhere from twelve million to over seventy million units. The first model was manufactured in the late 1960s, and many older units still operating today were designed decades before modern cybersecurity threats emerged.

What concerns security experts most is not the sophistication of these attacks, but rather their simplicity. The U.S. Cybersecurity and Infrastructure Security Agency has reported that Iranian-linked actors employ basic techniques, including scanning for exposed devices and exploiting default credentials—factory-set passwords that operators never changed. This approach resembles checking for unlocked doors rather than executing complex technological breaches.

The vulnerability is compounded by a fundamental security gap. Responsibility for protecting this equipment has largely fallen to individual plant operators, often small utilities with minimal or nonexistent dedicated cybersecurity staff. They are tasked with securing devices that were never built with security as a design priority.

A 2024 scan by cybersecurity researchers discovered thousands of PLCs sitting exposed and searchable on the open internet, readily accessible to anyone with basic technical knowledge and malicious intent.

The coordinated nature of these attacks, targeting critical infrastructure across two allied nations during the same month, suggests a deliberate campaign by Iranian cyber operatives. Whether these intrusions represent testing of capabilities, reconnaissance for future operations, or retaliatory measures remains unclear.

What is evident is that the industrial systems undergirding modern civilization remain dangerously vulnerable to actors who need not possess sophisticated capabilities to inflict significant disruption. The challenge facing Western nations is not merely identifying threats, but addressing fundamental security deficiencies in infrastructure designed for an era when such threats did not exist.

Related: Navy Sailor’s Father Detained by ICE During Middle East Deployment