报告称与伊朗有关的黑客首次致使英国发电厂瘫痪


2026-08-24T13:30:00-0400 / 哥伦比亚广播公司新闻(CBS News)

作者:拉米·因诺森西奥(Ramy Inocencio)

拉米·因诺森西奥是驻扎伦敦的哥伦比亚广播公司新闻驻外记者,负责报道欧洲和中东地区事务。他于2019年加入该媒体,担任哥伦比亚广播公司新闻驻亚洲记者,总部位于北京,在亚太地区开展报道,拥有在亚洲和美国之间工作、出行的二十年从业经验。

伦敦讯——据英国多家媒体报道,与伊朗有关联的黑客成功致使英国一家发电厂临时瘫痪。

《每日电讯报》和《金融时报》报道了此次攻击事件,他们称事件发生在7月,直到现在才被公开报道。据信,这是与伊朗有关联的黑客首次成功瘫痪英国境内此类设施。

更令人担忧的是,此次网络入侵发生的同一个月,据称与伊朗有关联的黑客还针对包括新泽西州、明尼苏达州、佐治亚州和南达科他州在内的十余个州的供水系统发动攻击,导致运营人员无法进入系统,并造成水压下降和水淹事故。

哥伦比亚广播公司新闻联系了英国国家网络安全中心(NCSC),但该机构既未确认也未否认发生过任何黑客攻击事件。

据美国官员和英国知情人士透露,在这两起攻击事件中,黑客的目标都是被称为“可编程逻辑控制器”(PLC)的计算机设备。这类设备也被称为PLC,是全球各地自动化工业系统的核心,广泛应用于能源、供水和制造业。但它们也被普遍用于医院,以在停电时保障电力供应;用于化工厂,以控制温度和压力避免爆炸;还用于电梯和火车,以控制运行速度。可编程逻辑控制器还被用于管控监狱安全门、调节交通信号灯系统以及启动消防系统。

市场研究公司的数据显示,全球在用的可编程逻辑控制器数量的行业估算差异巨大,从约1200万台到7000多万台不等。首款可编程逻辑控制器于20世纪60年代末投产,如今仍在使用的许多老旧设备在设计之初并未考虑到21世纪的网络安全挑战。

不过,安全研究人员表示,黑客入侵可编程逻辑控制器所使用的手段并不复杂。

美国网络安全与基础设施安全局(CISA)报告称,与伊朗有关联的网络攻击者使用的是简单手段,包括扫描暴露在外的设备、利用未修改的默认密码,而非利用企业可能尚未发现的漏洞进行复杂攻击。这种策略更像是寻找未上锁的门,而非高科技黑客行为。

美国网络安全与基础设施安全局还表示,保障这类设备安全的责任主要落在了各工厂运营商身上——这些运营商往往是小型公用事业公司,几乎没有专门的网络安全人员,而这类设备从一开始就未将安全性作为优先设计目标。2024年的一项网络安全研究人员扫描结果显示,有成千上万台可编程逻辑控制器暴露在公开互联网上,可被搜索到。

报道称,在针对英国发电厂的攻击中,该系统瘫痪了四天,员工们努力恢复控制权限。英国官员和工业企业高管并未披露遭攻击的发电厂具体是哪一家,但据了解,此次攻击针对的是一家小型设施,并未影响英国整体电力供应。目前没有任何组织宣称对此负责,但安全专家表示,这类攻击可能是概念验证尝试——测试如何绕过更易受攻击目标的系统,以便未来尝试攻击更敏感、高价值的目标。

多年来,英国一直就与伊朗有关联的网络活动发出警告。2022年,官员们谴责伊朗发动网络攻击,致使阿尔巴尼亚政府服务陷入瘫痪。但今年年初,随着美伊战争以及伊朗最高领袖阿亚图拉·阿里·哈梅内伊遇袭身亡事件的发生,相关警告大幅升级。

今年6月,英国国家网络安全中心负责人理查德·霍恩博士透露,在过去一年中,该中心已“处置”了200多起针对英国关键基础设施的网络攻击,其中约75%的攻击与俄罗斯、中国和伊朗等敌对国家有关。

Iran-linked hackers blamed for taking down U.K. power plant for first time, reports say

2026-08-24T13:30:00-0400 / CBS News

By Ramy Inocencio

Ramy Inocencio is a CBS News foreign correspondent based in London, covering Europe and the Middle East. He joined the Network in 2019 as CBS News’ Asia correspondent, based in Beijing and reporting across the Asia-Pacific, bringing two decades of experience working and traveling between Asia and the United States.

London — Iranian-affiliated hackers successfully but temporarily took a power plant offline in the United Kingdom, according to multiple British media outlets.

The Telegraph and Financial Times reported the attack, which they say happened in July but is only now being reported, is believed to be the first time Iranian-linked hackers managed to shut down such a facility in the country.

Of further concern, the breach also happened the same month Iranian-linked hackers are believed to have targeted the water systems of a dozen states including New Jersey, Minnesota, Georgia and South Dakota, locking out operators and causing pressure loss and flooding.

CBS News reached out to the U.K.’s cybersecurity agency, the National Cyber Security Centre, but it neither confirmed nor denied any hacking had occurred.

In both attacks, computers called “programmable logic controllers” were targeted, according to U.S. officials and people familiar with the matter in the U.K. Also known as PLCs, these are the brains of automated industrial systems found around the world that in large part span energy, water and manufacturing. But they are also used ubiquitously in hospitals to help supply power in blackouts, in chemical plants to control temperature and pressure to avoid explosions and in elevators and trains to control speed. PLCs are also employed to control prison security gates, in the timing of traffic light systems and in the activation of fire suppression systems.

Industry estimates on how many PLCs are in use worldwide vary widely, from roughly 12 million to more than 70 million, according to market research firms. The first model was manufactured in the late 1960s — and many older units still in use today were never designed with 21st century cybersecurity challenges in mind.

Yet, security researchers say the methods hackers use to breach PLCs are not sophisticated.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has reported Iranian-linked actors are using simple techniques that include scanning for exposed devices and exploiting default credentials — default passwords that have not been changed — rather than deploying sophisticated exploits of holes that companies may not know exist. The strategy is more akin to looking for unlocked doors versus high-tech hacking.

CISA has also said the responsibility for securing this equipment has largely fallen on individual plant operators – often small utilities with few to no dedicated cybersecurity staff – for devices that were never built with security as a priority in the first place. One 2024 scan by cybersecurity researchers found thousands of PLCs sitting exposed and searchable on the open internet.

In the attack on the British power plant, that system was offline for four days as employees worked to restore control, reports said. British officials and industrial executives have not disclosed which plant was hit, but it is understood the attack targeted a small-scale facility and did not impact the U.K.’s overall power supply. No organization has claimed responsibility, but security experts say it is possible these attacks may be proof-of-concept attempts — testing how to navigate the systems of more vulnerable targets before attempting to reach more sensitive, high-value ones in the future.

For years, the U.K. has warned of Iranian-linked cyber activity. In 2022, officials condemned Iran for a cyberattack that crippled Albania’s government services. But the warnings sharply intensified early this year, triggered by the U.S.-Israel war against Iran and the killing of Supreme Leader Ayatollah Ali Khamenei.

In June, the head of the U.K.’s National Cyber Security Centre, Dr. Richard Horne, disclosed it had “managed” more than 200 cyberattacks against UK critical infrastructure in the past year, with roughly 75% of the attacks linked to hostile states including Russia, China and Iran.

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

湘ICP备2026001899号-2