Iran-nexus actors

3 items · Policy 1 · Attacks 2 · all entities

UK government tables amendments letting ministers bar high-risk technology suppliers from critical sectors

Amendments tabled on August 24 to the Cyber Security and Resilience Bill, now HL Bill 32 in the House of Lords after clearing the Commons, would give ministers power to block critical-sector organisations from using technology suppliers judged high risk. SecurityWeek links the timing to an Iran-linked attack that took a small UK energy facility offline for four days on August 22; that connection is the outlet's characterisation rather than a stated government rationale.

Reported by pressSecurityWeek ↗ ·

Iran-linked hackers blamed for a four-day shutdown of a small UK power plant

A cyberattack shut down a small UK power generator for four days in July 2026, which the UK government acknowledged after The Telegraph disclosed it in late August; officials did not name the operator and said there was no risk to the wider energy system, and the energy minister briefed power-company chiefs afterward. Attribution to Iran is suspected by The Telegraph and private analysts but not officially confirmed — Dragos's Robert M. Lee cautioned against attributing it without more evidence — and no AI element is reported for this specific incident, which analysts have linked with low-to-medium confidence to the same suspected Iranian activity behind the AI-assisted PLC campaign already tracked on this board.

Reported by pressAxios (Sam Sabin) ↗ ·

US advisory: Iran-linked actors manipulating Rockwell, Siemens and Schneider PLCs

A US government advisory (CISA/FBI/NSA/EPA), updated July 22, warns Iran-linked actors are using vendors' own engineering software to alter project files on Rockwell, Siemens (S7-1200) and Schneider (Modicon M340) PLCs — disabling shutdown and alarm logic at US water, energy and government facilities, with at least one confirmed US victim. No direct AI angle, but a strategically significant critical-infrastructure escalation.

Confirmed by orgSecurityWeek ↗ ·