# Cyberattack Causes UK Power Plant Outage and Car Systems Infection

*Published August 26, 2026*
*Source: [https://www.sans.org/newsletters/newsbites/xxviii-63](https://www.sans.org/newsletters/newsbites/xxviii-63)*

## Executive Summary

A cyberattack caused a UK power plant to go offline for four days, showcasing the challenge between individual asset risk and systemic resilience. Additionally, car systems were infected with proxy malware, and security flaws in N-able Passportal and Keycloak were patched.

## Article

A recent cyberattack led to the temporary shutdown of a UK power plant, demonstrating the delicate balance between asset risk and systemic resilience. While the engineered system managed to absorb the failure without service disruption, the attack highlights the potential vulnerability of critical infrastructure. This incident involved a relatively small generator, which remained offline for four days due to the cyber intrusion. The implications of similar attacks on larger facilities or multiple smaller ones simultaneously could be far more significant.

In a separate event, car systems were found to be infected with proxy malware, effectively turning them into part of a botnet. This infection underscores the growing risk of cyber threats extending beyond traditional IT environments into the realm of connected vehicles. Such malware can manipulate car systems to perform various unwanted actions and potentially compromise driver safety.

Additionally, vulnerabilities in N-able Passportal and Keycloak were identified and have since been addressed with security patches. These flaws could have been exploited by attackers to gain unauthorized access to sensitive information. Organizations using these platforms are advised to apply the latest updates promptly to mitigate any potential risks. Ensuring that software vulnerabilities are regularly patched is a vital component of maintaining a secure IT environment.
