News Room
16
Share
Iran-Linked Actors and Qilin Ransomware Escalate Strikes on UK Energy and Defense Supply Chains
criticalCritical Infrastructure

Iran-Linked Actors and Qilin Ransomware Escalate Strikes on UK Energy and Defense Supply Chains

Recent attacks on a UK power plant and aerospace manufacturers signal a coordinated escalation against critical national infrastructure by nation-state and criminal actors.

29 August 2026Last updated 29 August 20264 min readMandiant
E
Encrygma AI Cyber Weapons Advisory Services :We provide AI Cyber Warfare Technologies Reports, including full technical blueprints, tech source codes, entire know how. Consult with us. Click Here

Executive Takeaway — TL;DR

Category:
Critical Infrastructure
Severity:
Critical
Actor Type:
Nation-State
Geography:
United Kingdom
Confidence:
High Confidence
Source:
Mandiant
Read Time:
4 min

Executive Summary

Over the past 48 hours, the United Kingdom’s critical national infrastructure (CNI) has faced a significant surge in malicious cyber activity. Following the confirmed shutdown of a regional power plant attributed to Iran-linked actors, new reports from August 27, 2026, indicate that the Qilin ransomware group has successfully breached two major UK manufacturers: Metal Conversions and Air International Thermal Systems. The latter is a critical supplier to aerospace and defense programs, raising immediate concerns regarding the integrity of the military supply chain. These incidents, occurring alongside ongoing threats to water systems in the US and UK, represent a shift toward high-impact operational disruption.

Threat Analysis

The current threat landscape is characterized by a convergence of geopolitical retaliation and opportunistic extortion. The attack on the UK power plant is widely viewed as a retaliatory measure by Tehran following the UK's support of US military operations. Simultaneously, the Qilin ransomware group—a Russia-linked entity—is targeting the 'long tail' of the supply chain. By hitting mid-tier manufacturers like Air International Thermal Systems, attackers can bypass the hardened perimeters of primary defense contractors while still achieving significant strategic leverage. This 'dual-threat' environment forces CNI operators to defend against both state-sponsored sabotage and financially motivated disruption.

Technical Details

Intelligence suggests that the recent energy sector disruptions utilized vulnerabilities in internet-exposed Programmable Logic Controllers (PLCs), specifically targeting Siemens and Unitronics devices. Attackers exploited default credentials and unpatched remote access interfaces to gain direct control over industrial processes. In the case of the Qilin ransomware attacks, the group utilized advanced 'living-off-the-land' (LotL) techniques, leveraging legitimate administrative tools to move laterally from IT environments into OT (Operational Technology) segments. The deployment of the Qilin locker was preceded by the exfiltration of sensitive technical blueprints, suggesting a secondary espionage motive beyond the initial ransom demand.

Attribution Assessment

With high confidence, the power plant incident is attributed to 'Cyber Av3ngers,' a group with known ties to the Iranian Islamic Revolutionary Guard Corps (IRGC). Their tactics align with previous campaigns targeting water and energy sectors globally. The manufacturing breaches are attributed to the Qilin (also known as Agenda) ransomware collective. While Qilin operates as a Ransomware-as-a-Service (RaaS) model, their targeting of defense-linked suppliers often aligns with broader Russian strategic interests, particularly in disrupting Western military readiness.

Implications

The successful targeting of a defense supplier like Air International Thermal Systems has profound implications for the aerospace sector. The potential compromise of proprietary thermal management designs could lead to long-term technological theft. Furthermore, the energy sector attack demonstrates that even small-scale generators are now viable targets for state actors looking to test 'proof-of-concept' sabotage techniques before scaling to larger grid components.

Recommendations

Encrygma recommends that all CNI and defense-industrial base (DIB) organizations immediately audit their OT environments for internet-exposed PLCs. Organizations should implement strict network segmentation between IT and OT assets, ensuring that no industrial controller is accessible via the public internet. Additionally, the use of multi-factor authentication (MFA) must be mandated for all remote access points, and supply chain partners should be required to provide a Software Bill of Materials (SBOM) to identify latent vulnerabilities in their digital ecosystems.

Professional Spy Phones — ZERO-CLICK Spyware: Samsung Galaxy and iPhone hardware-modified with a dedicated implant for remote surveillance, lawful interception, and corporate compliance monitoring.
ENCRYGMA

Need Zero Click Spyware for Android and iOS?

Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.

Request a demo