All news

How Secure Are Britain’s Smart Meters Against Cyber Attacks?

19 July 2026 Peter Flynn
How Secure Are Britain’s Smart Meters Against Cyber Attacks?

Smart meters are now part of Britain’s critical digital infrastructure. They record household energy consumption, send readings to suppliers and support functions that would once have required an engineer to visit the property.

That naturally creates uncomfortable questions.

Can somebody hack a smart meter? Could a criminal alter the readings and increase a household’s bill? Could an attacker disconnect thousands of homes remotely? Does the meter reveal when a family is at home or away?

The honest answer is that no connected system can be described as completely unhackable. Smart meters contain software, cryptographic credentials and communications technology, all of which must be managed throughout the equipment’s life.

However, Britain’s second-generation smart meter system was not designed like an ordinary internet-connected household gadget. It uses a specialised national communications network, tightly controlled permissions, cryptographic authentication and several independent security layers.

For the average householder, the risk of a criminal remotely taking control of a SMETS2 meter is low. Billing disputes, faulty equipment, communications failures, incorrect tariffs and compromised supplier accounts are considerably more realistic concerns than a stranger directly hacking the meter.

The Short Answers Householders Want

Can a British smart meter be hacked?

In theory, yes. Any device containing hardware and software could have vulnerabilities.

In practice, remotely hacking a SMETS2 meter is much harder than compromising an ordinary smart-home device. The meter does not normally connect to the household’s Wi-Fi, does not expose a conventional web page to the public internet and will not accept arbitrary commands from an unknown computer.

Messages reaching the meter must pass through the authorised smart-meter communications system and satisfy cryptographic checks.

Physical tampering with an individual meter is another possibility, although meters have security seals, event logs and tamper-detection features. Interfering with an electricity or gas meter is also dangerous and potentially criminal.

  • 【Muti-measurment Functions】Power Meter Socket power energy meter can measure and display Voltage, Watts, Power Consumpti…
  • 【Overload Alarm Function】The power monitor will automatically alarm to warn the user when any device with a load exceedi…
  • 【Buy with Confidence】safety tested (GS mark) and CE certified; we offer lifetime customer service for every meter.Stream…

Can somebody manipulate the bill?

A cyber attacker could theoretically attempt to interfere with meter readings, tariff information or a supplier’s billing systems. However, directly changing authenticated SMETS2 readings is not a simple matter.

A much more plausible billing problem is an administrative or technical error, such as:

  • The wrong tariff being recorded
  • Estimated readings being used during a communications failure
  • A meter being linked to the wrong account
  • Incorrect opening or closing readings
  • Confusion between the meter display and the in-home display
  • A supplier’s billing platform processing accurate data incorrectly
  • A smart meter temporarily operating in “dumb” mode
  • A household account being accessed through stolen login details

A surprisingly high bill is therefore not, by itself, evidence that the meter has been hacked.

Can the electricity supply be disconnected remotely?

Yes. Smart electricity meters include functions that can support remote disconnection and reconnection. Smart meters can also be switched remotely between credit and prepayment modes.

That does not mean any DCC participant can disconnect any household whenever it chooses. Supply-affecting instructions are treated as critical commands. They require strong cryptographic authentication and must come from an authorised party with the correct permissions.

Energy suppliers must also comply with Ofgem’s consumer-protection rules. Remote switching to prepayment or disconnection over debt is a regulated commercial action, not simply a technical decision.

Could hackers disconnect thousands of meters at once?

This is the most serious theoretical scenario, but it is also one the British system was specifically designed to resist.

The National Cyber Security Centre has explained that creating a mass-disconnection event would require the compromise of several separate parts of the system. An attacker would need far more than access to one household meter or one set of customer-account credentials.

Security controls, separate organisational responsibilities, per-meter authentication, command signing, network capacity constraints and anomaly monitoring are intended to prevent one compromise from becoming a national event.

The risk cannot honestly be described as zero. Nevertheless, the system was designed to make large-scale disruption considerably harder than sensational claims about “one hacker switching off Britain” suggest.

  • APP Remote Control: Effortlessly manage your home appliances anytime, anywhere through the Smart Life APP. No more worry…
  • Voice Control: Our smart plugs are compatible with Alexa and Google Assistant, enabling you to control your home electri…
  • Energy Consumption Monitoring: This feature enables you to closely track your devices’ energy consumption. You can acces…

What Is a SMETS2 Smart Meter?

SMETS stands for Smart Metering Equipment Technical Specifications. SMETS2 is the second major generation of smart-meter equipment installed in Great Britain.

A normal dual-fuel installation may contain:

  • A smart electricity meter
  • A smart gas meter
  • A communications hub
  • An in-home display
  • A Home Area Network connecting the equipment
  • A Wide Area Network connection to the national DCC system

The electricity meter generally acts as the main point around which the communications hub is installed. The gas meter, which may be some distance away and must preserve battery power, exchanges information through the local Home Area Network.

The in-home display receives information over this local network. It allows the householder to view consumption and estimated costs without giving the display direct control over the national system.

SMETS1 and SMETS2 are not the same

First-generation SMETS1 meters were initially deployed using supplier-specific communications arrangements. Some temporarily lost smart functions when customers changed supplier, although large numbers have since been enrolled into the national DCC system.

SMETS2 was designed around interoperability. A customer should be able to change energy supplier without requiring the meter to be replaced or permanently losing its smart functions.

This common national architecture also enables a more consistent security model.

What Does the Data Communications Company Do?

The Data Communications Company, commonly called the DCC, operates the secure communications infrastructure connecting smart-meter equipment with authorised organisations.

DCC users include:

  • Energy suppliers
  • Electricity network operators
  • Gas network operators
  • Approved third-party service providers
  • Other authorised participants performing defined smart-meter functions

The DCC is regulated by Ofgem and operates under the Smart Energy Code and its communications licence.

A useful way to understand the system is to think of the DCC as a protected digital delivery network. It carries authorised messages between organisations and smart-meter equipment, but participation does not automatically give an organisation permission to perform every possible function.

An electricity network operator does not need permission to change a household’s tariff. A price-comparison service does not need permission to disconnect a meter. Permissions are divided according to legitimate operational roles.

The meter does not normally use your broadband

A SMETS2 meter does not usually depend on the householder’s Wi-Fi router or broadband account.

The communications hub uses the DCC’s Wide Area Network. Depending on the location and communications region, this has involved cellular or long-range radio technology. The communications infrastructure is being modernised as older mobile-network technologies are retired.

This separation matters for security.

A criminal who compromises a household Wi-Fi password does not automatically gain access to the smart-meter Wide Area Network. The in-home display may stop updating if its local connection fails, but that is different from an attacker gaining control of the meter.

The DCC is not a general-purpose internet service

Smart-meter communications do not operate like ordinary browsing or email. The system is built around defined services, message formats, device identities and authorised transactions.

A meter is not supposed to accept an unexpected command merely because somebody knows its address. Messages must pass authentication checks, and the sender must have the right identity and permission for the requested action.

Smart Meter Communicating

How Smart-Meter Encryption Works

Encryption is an important part of smart-meter security, but it is not the only protection.

The British system also uses digital signatures, authentication codes, device identities, security certificates and tightly divided permissions.

Sensitive data is encrypted

Information such as consumption readings and debt data may reveal private information about a household. Sensitive communications are therefore encrypted so that only the intended recipient should be able to read them.

The communications network transports the messages, but sensitive content is protected for the authorised recipient.

This limits the damage that could result from the compromise of an intermediate communications component.

Critical commands are digitally authenticated

A command that could affect supply is more sensitive than a request to read a meter.

The NCSC describes supply-affecting transactions as critical. These commands require strong authentication using cryptographic signatures. The receiving meter can therefore check whether the instruction came from an authorised identity and whether it has been altered.

A forged command without the required credentials should be rejected.

Each device has its own identity

SMETS2 devices are provided with cryptographic identities. The system uses a Smart Metering Key Infrastructure to manage trust between meters, suppliers, network operators and the DCC.

When a customer changes supplier, a secure process allows the new supplier to assume the appropriate relationship with the meter. The meter can then recognise the new supplier’s authorised identity.

Importantly, the compromise of one meter is not intended to reveal a master key capable of opening every other meter.

The NCSC has explained that the authentication information associated with a meter is unique. Reverse-engineering or physically compromising one device should not provide everything needed to attack the rest of Britain’s meter population.

Messages are specific to the meter

Authentication codes differ between messages and devices.

Copying a valid message sent to one meter and replaying it against another should not work. Repeating an old command should also encounter security controls intended to prevent unauthorised replay.

This is an important distinction between a properly designed infrastructure system and a cheap consumer device that uses one shared password across an entire product range.

What Remote Commands Can Smart Meters Receive?

Smart meters support more than automatic readings. Depending on the device, fuel type, supplier permissions and regulatory circumstances, authorised commands can include:

  • Requesting consumption information
  • Updating tariff information
  • Changing payment mode
  • Adding prepayment credit
  • Updating device configuration
  • Installing approved firmware
  • Supporting change of supplier
  • Disconnecting or reconnecting supply
  • Retrieving meter status and event information

This functionality is useful. It allows faster supplier switching, more accurate billing and remote support for prepayment customers.

It also creates risk because a compromised command system could affect physical energy services. That is why the security design distinguishes ordinary, sensitive and critical transactions.

Remote capability is not the same as unrestricted access

The fact that a function exists does not mean it is available to every organisation connected to the DCC.

Each participant has a defined role. Commands must be authorised, correctly formed, cryptographically protected and delivered through the approved communications system.

This principle is sometimes described as least privilege: an organisation receives only the access needed to perform its legitimate role.

Smart Meter in The Kitchen

Can a Criminal Hack the Meter Through the Home Area Network?

The Home Area Network, or HAN, allows equipment inside the property to communicate. This may include the electricity meter, gas meter, communications hub and in-home display.

It commonly uses a secured form of Zigbee wireless communication rather than ordinary Wi-Fi.

Being physically nearby is not enough

A person standing near the house should not be able to join the meter network simply by detecting its wireless signal.

Devices must be authorised and securely joined to the HAN. Smart-meter equipment stores security credentials and uses protected connections between recognised devices.

As with every wireless technology, researchers may still investigate implementation errors, weak firmware or flaws in individual device models. However, discovering a wireless signal does not give an attacker automatic control.

The in-home display is not the meter

Many households call the portable screen in the kitchen “the smart meter”. It is actually an in-home display.

If the display freezes, loses its connection or shows an incorrect estimated cost, that does not necessarily mean the electricity or gas meter is faulty. The display translates consumption and tariff information into a form the householder can understand.

A discrepancy can occur if the display has outdated tariff information even while the meter continues recording energy consumption correctly.

Consumer access devices need careful security

Some households connect approved consumer access devices to obtain detailed energy information for apps, automation platforms or home-energy systems.

These devices can provide useful near-real-time information, but they extend the household’s digital energy environment. The app account, cloud platform, phone and associated home network must therefore be protected.

This is where Can Solar Panels Be Hacked? and Can EV Chargers Be Hacked? become particularly relevant. The DCC-connected meter may be well protected, while a separate inverter portal, EV charger, energy app or household Wi-Fi account has weaker security.

Can Smart-Meter Readings Be Changed to Inflate a Bill?

There are several different places where a billing problem could arise:

  • The physical measurement of consumption
  • Information stored by the meter
  • Transmission of the reading
  • The tariff associated with the account
  • Processing within the supplier’s billing platform
  • Presentation on the bill or app
  • Payment and direct-debit calculations

Only some of these involve the meter itself.

Direct meter manipulation is difficult but not impossible in principle

An attacker attempting to alter readings inside the meter would need to overcome physical protections, device security controls or authenticated communications.

Meter manufacturers and the wider smart-meter programme use testing and assurance processes intended to reduce this risk.

Criminal tampering has historically been associated more with attempts to reduce recorded usage than to inflate another household’s bill. Such interference is dangerous, can cause fires or electric shock and may lead to prosecution.

Supplier systems may be a more attractive target

A national energy supplier holds large quantities of customer, payment and billing information. Its web accounts, staff identities, call centres, software platforms and contractors may offer attackers more conventional opportunities than trying to break the cryptography of a household meter.

An attacker who gains access to a customer account might change contact details, intercept communications or use stolen personal information for fraud. That does not necessarily give the attacker the ability to send critical DCC commands.

This separation is important. Compromising the customer-facing website should not automatically provide access to the operational smart-meter command environment.

Billing errors are not automatically cyber attacks

If a bill appears wrong, the householder should:

  • Compare the meter serial number with the number on the bill
  • Read the consumption figure directly from the meter
  • Check whether the bill uses actual or estimated readings
  • Confirm the unit rate and standing charge
  • Check the billing period
  • Compare the opening reading with the previous closing reading
  • Photograph the meter reading and serial number
  • Ask the supplier for the readings used to calculate the bill
  • Request a meter accuracy investigation if the evidence remains inconsistent

Can a Supplier Disconnect a Smart Meter Remotely?

Remote disconnection is technically possible, particularly for electricity meters. Remote switching from credit to prepayment can also result in a household losing supply if it cannot maintain credit.

This has produced understandable concern because the physical effect on the household may feel the same whether the meter is formally disconnected or the customer self-disconnects after being placed on prepayment.

Ofgem rules still apply

A supplier’s technical capability does not remove its legal and regulatory obligations.

Ofgem says that remotely switching a smart meter to prepayment should be a last resort after reasonable efforts have been made to agree a way for the customer to pay.

Suppliers must consider whether prepayment is safe and reasonably practicable. They must assess vulnerability and follow strengthened protections introduced after the serious controversy surrounding involuntary prepayment-meter practices.

Ofgem’s June 2026 compliance review found that suppliers generally complied with the strengthened requirements, but it also identified a small number of cases where procedures were not sufficiently rigorous and vulnerable customers could have been placed at risk.

This illustrates an important point: the most immediate danger may not be a technically sophisticated hacker. It may be an authorised function used incorrectly, without sufficient human checks or with inaccurate information about the customer.

Vulnerable households have additional protections

People who may be endangered by interruption of supply should ensure that their supplier knows about their circumstances and should consider joining the Priority Services Register.

Relevant circumstances can include:

  • Dependence on electrically powered medical equipment
  • Disability or serious illness
  • Advanced age
  • Pregnancy
  • Very young children in the household
  • Communication difficulties
  • Temporary vulnerability following a major life event

Registration does not mean supply can never be interrupted, but it helps suppliers and network operators identify customers who may require additional support.

What Consumer Data Does a Smart Meter Collect?

A smart meter records how much energy is consumed and when it is consumed.

Depending on the configuration and authorised use, electricity information may be recorded at intervals such as half-hourly, daily or monthly. More detailed consumption data can reveal more than the total on a traditional meter.

It may indicate:

  • When energy demand rises in the morning
  • Regular cooking or heating patterns
  • Periods when the property appears unoccupied
  • Overnight EV charging
  • Solar export behaviour
  • Changes in household routine
  • Possible use of high-consumption equipment

It does not directly record which television programme somebody watched or the contents of a conversation. Nevertheless, detailed consumption patterns can support inferences about household behaviour.

For a wider examination of this issue, link here to What Personal Data Do Smart Energy Devices Collect?

Who can obtain the data?

Access depends on the organisation, the purpose, the level of detail and the applicable data rules.

Suppliers require enough information to bill customers and perform regulated functions. Network operators may use appropriately controlled data to plan and manage electricity infrastructure. Authorised third parties can provide services such as tariff analysis, but access must follow the relevant consent and governance requirements.

Government’s Data Access and Privacy Framework defines the rules governing access by suppliers, network operators and third parties.

Consumer choices around half-hourly data have also evolved alongside market-wide half-hourly settlement. Householders should check their supplier’s current privacy notice and smart-meter data settings rather than assuming that every organisation sees the same information.

Smart-meter data remains personal data

Where consumption information relates to an identifiable household, UK data-protection requirements apply.

Organisations must have a lawful basis for processing it, use it for defined purposes, protect it appropriately and avoid retaining it unnecessarily.

Consumers can ask suppliers:

  • What interval of consumption data is being collected
  • Why it is required
  • Who receives it
  • How long it is retained
  • Whether optional uses can be changed
  • Whether it is used for marketing
  • How to exercise data-protection rights

Could a Smart-Meter Cyber Attack Cause a Power Cut?

An attack on a single meter would have a limited effect. A coordinated attack against large numbers of meters is a national-security question because remotely controllable electrical loads could potentially affect demand across the grid.

Britain’s security architecture was designed with this systemic risk in mind.

One compromised meter should not unlock the rest

Per-device keys and identities are intended to contain an individual compromise. Information extracted from one device should not provide a universal credential for other meters.

This is one reason the system is more resilient than an internet product range in which every device ships with the same administrative password.

Mass disruption would require multiple failures

According to the NCSC’s explanation of the system, an attacker seeking to disconnect more than a small number of meters would have to overcome separate controls involving the authorised supplier, the DCC and the communications infrastructure.

The system also includes limits arising from communications capacity and monitoring for unusual behaviour.

That does not make a large-scale event impossible. It makes it a complex, multi-stage attack requiring access to several protected environments rather than a trick that can be performed from outside one house.

Readers can explore the wider national context through What Are the Emerging Cyber Threats Facing UK Energy Infrastructure? and How Prepared Is the UK for Cyber Attacks on Critical Infrastructure?

What Would a Realistic Smart-Meter Attack Look Like?

The most credible attacks are not necessarily the dramatic scenarios seen in headlines.

Compromising a supplier or contractor

An attacker might target:

  • Supplier staff accounts
  • Remote support systems
  • Meter-management platforms
  • Software developers
  • Managed service providers
  • Communications contractors
  • Customer-service processes

This is a supply-chain and identity-security problem. The attacker attempts to obtain legitimate access or exploit trusted software rather than attacking the meter’s cryptography directly.

Stealing a customer’s online account

Criminals might use phishing, reused passwords or information from previous data breaches to access a supplier account.

They could obtain bills and personal information useful for identity fraud. They might also change account details or submit false meter information through consumer-facing channels.

Customers should use a unique password and enable multi-factor authentication where the supplier offers it.

Exploiting an individual device vulnerability

Security researchers may discover a weakness in a specific meter, communications hub, display or consumer access device.

The seriousness would depend on whether the weakness can be reached remotely, whether authentication must first be bypassed and whether compromise remains limited to that device model or household.

Firmware updates, certificate management, monitoring and replacement programmes are therefore important throughout the equipment’s operational life.

Abusing an authorised process

A criminal could impersonate a customer or supplier employee and persuade someone to perform a legitimate action.

This type of social engineering can bypass strong technical security if staff do not verify identities properly. It is one reason critical operational commands need procedural controls as well as cryptography.

  • Installs in circuit panel of most small businesses with clamp-on sensors. Supports single phase, single-split phase, and…
£109.99

What Smart-Meter Security Does Not Protect

The national smart-meter security architecture cannot protect every connected device in the house.

It does not automatically secure:

  • The household Wi-Fi router
  • Supplier account passwords
  • Email accounts
  • Mobile phones
  • Solar inverter portals
  • Battery applications
  • EV charger accounts
  • Smart thermostats
  • Third-party energy-management platforms

A household could therefore have a secure SMETS2 meter but a poorly protected energy app using a reused password.

Security must cover the entire connected-energy chain.

What Householders Can Do

Householders cannot manage the DCC’s cryptographic systems, but they can reduce the most realistic risks.

Protect the energy account

Use a strong password that is not used on another website. Enable multi-factor authentication if available and secure the associated email account equally well.

Treat unexpected energy messages cautiously

Do not provide passwords, one-time codes or bank details to an unexpected caller.

If somebody claims to represent the supplier, end the call and contact the company using the number on a genuine bill or its official website.

Do not tamper with the meter

Never remove seals, open the meter housing or interfere with the wiring. Report damage, heat, burning smells, exposed cables or suspected tampering immediately.

Check bills rather than ignoring them

Compare occasional bills with the reading visible on the physical meter. This can identify account-linking errors, incorrect estimates and tariff problems before they grow.

Secure connected energy devices separately

Change default passwords on solar, battery, heating and EV-charging platforms. Apply firmware updates and remove old installer access that is no longer required.

Report unexplained loss of supply

If electricity goes off unexpectedly, check whether neighbouring properties are affected and contact the distribution network operator by calling 105.

If only the property is affected, contact the energy supplier. Do not assume it is a cyber attack without evidence.

Are Britain’s Smart Meters Secure Enough?

Britain’s SMETS2 infrastructure has one of the more carefully engineered security models found in consumer energy technology.

Its strengths include:

  • A dedicated national communications architecture
  • Devices with individual cryptographic identities
  • Authentication of messages before processing
  • Encryption of sensitive information
  • Digital signatures for critical commands
  • Separation of organisational permissions
  • Restrictions on who can perform particular transactions
  • Security assurance and monitoring
  • Design intended to contain individual compromises

Its weaknesses are the same long-term challenges faced by other large digital infrastructure systems:

  • Equipment may remain installed for many years
  • Previously unknown software vulnerabilities can emerge
  • Cryptographic credentials require careful lifecycle management
  • Suppliers and contractors can be attacked
  • Human procedures can fail
  • Consumer data becomes increasingly valuable
  • Communications technology must be upgraded
  • More household energy devices are becoming interconnected

The most balanced conclusion is therefore not that smart meters are either completely safe or dangerously insecure.

A SMETS2 meter can theoretically be attacked, but the British system makes remote and large-scale exploitation deliberately difficult. For an ordinary household, account fraud, supplier error, privacy misunderstandings and insecure third-party energy devices are more credible concerns than a criminal directly taking control of the meter.

The larger strategic issue is whether Britain can maintain those protections as millions of meters, EV chargers, solar inverters, batteries and flexible-energy systems become more closely connected. That longer-term challenge belongs naturally alongside UK Cyber Energy Security 2026–2035.

Final Verdict

Britain’s smart meters are not unhackable, but they are significantly more secure than many ordinary connected-home devices.

A meter cannot normally be controlled through the household’s Wi-Fi. Sensitive data is encrypted, important commands are authenticated and individual devices have their own cryptographic identities. Remote disconnection is technically possible, but it requires authorised commands and remains subject to Ofgem’s consumer-protection rules.

Bills could theoretically be affected by a cyber incident, particularly if supplier systems were compromised. In everyday life, however, incorrect tariffs, estimated readings, account errors and billing-platform problems are more likely explanations.

The sensible position is vigilance without alarm.

Householders should protect their supplier accounts, check unexpected bills, understand their data choices and report unexplained meter behaviour. Energy companies, meanwhile, must continue treating the smart-meter network as critical national infrastructure rather than merely a convenient billing system.

Reference Material and Research