The intrusion into the UK power plant did not start at the utility. It started at a contractor whose credentials into the plant's operational technology network were compromised, then walked in through that trust relationship. The plant went offline. Treasury's fresh sanctions this week target the Iranian actors behind this and prior critical-infrastructure breaches, part of what the department called an "unprecedented, whole-of-government, economic campaign" against Tehran, unprecedented paired here with a sanctions list, not a headline writer's flourish. Attribution and consequence are two different documents. One names a state; the other freezes assets. Neither one is an access control on the contractor's VPN.
The utility's public statement leans on the words "AI-powered" for the threat it says comes next. The compromised-contractor pathway that actually worked this time is not an AI problem. It is a third-party access review problem, the kind that gets solved by scoping contractor credentials to specific OT segments and expiring them on contract end, not by a model card. Every power operator running contractor remote access into control networks this week should be pulling the access logs for every vendor account with standing OT privileges, not waiting for Treasury's next sanctions list to tell them who already got in.