UK Energy Site Hit by Iran-Linked Cyberattack, Prompting National Alert
The UK's National Cyber Security Centre has alerted energy firms after an IRGC-linked group breached a small power plant, the same threat actor and technique already targeting GCC-adjacent infrastructure.

An industrial power plant facility exterior, representing the UK energy sector cyberattack attributed to an Iran-linked threat actor
Power companies in the UK have been put on alert after hackers linked to Iran's Islamic Revolutionary Guard Corps (IRGC) shut down an energy site, in an incident that follows the same exploitation pattern currently drawing scrutiny from US regulators on the other side of the Atlantic.
The attack took place in July and is suspected to have been carried out by CyberAv3ngers, a group affiliated with the IRGC's electronic warfare arm that specialises in breaching industrial control systems. The UK's Department for Energy Security and Net Zero has said the attack hit a small plant and that at no point was there a risk to the wider energy system, but the National Cyber Security Centre, a branch of signals intelligence agency GCHQ, briefed energy CEOs directly and wrote to companies with advice and next steps.
Michael Shanks, the Minister for Energy, said the government and industry had taken the incident seriously and were working with regulators and the NCSC to assess threats and strengthen protections. Richard Moore, the former head of the MI6 overseas intelligence agency, said the UK faced sustained cyber activity from multiple states, naming China, Russia, Iran and North Korea as consistently focused on attacking UK targets.
This is not CyberAv3ngers' first campaign against Western water and energy infrastructure. The group has previously compromised Unitronics Vision programmable logic controllers, rugged industrial computers used to automate machinery across water, energy, food and beverage, manufacturing and healthcare facilities. CyberAv3ngers isn't the only Iran-linked actor GCC-facing security teams have had to track this year, MCW's profile of Handala covers a separate Iranian-linked group active against regional enterprises, worth keeping on the radar even though it operates independently of the campaign described here.
A recent analysis by cyber security firm Tenable found the group has repeatedly compromised small water utilities, municipal facilities and rural energy operators, describing the pattern as structural rather than coincidental. Many of these organisations rely on remote access tools such as TeamViewer or AnyDesk and expose their programmable logic controllers directly to the public internet, a basic misconfiguration rather than a sophisticated intrusion technique.
That same structural exposure is precisely what MCW's deep dive into OT and ICS security in the GCC has flagged as a regional risk. The Gulf's energy pipelines, desalination plants and power grids run on operational technology built for reliability rather than security, the same profile that made this UK plant, and the water utilities targeted in the US, viable targets in the first place.
Attribution here remains a working assumption rather than a confirmed finding. Neither the NCSC nor the Department for Energy Security and Net Zero has formally named CyberAv3ngers or the Iranian state in an official attribution statement, and the incident is still being assessed. For GCC operators running comparable industrial control systems, the practical takeaway is less about the specific attacker and more about the exposure pattern: default credentials, internet-facing PLCs and unmonitored remote access tools remain the common thread across every incident in this campaign, regardless of which country's infrastructure gets hit next.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.