See all

Thousands of European solar park systems exposed online, say researchers

Dutch firm Modat and the Netherlands’ cybersecurity agency have identified 8,547 exposed systems at solar and wind sites in 35 European countries, with Spain accounting for more than one-third of the solar total.
Image: Modat

Researchers from Modat, an internet intelligence company based in The Hague, and the National Cyber Security Centre (NCSC-NL) of the Netherlands have found 8,547 internet-facing systems at European solar projects and wind farms that should not be reachable from the internet, including exposed admin interfaces and control panels.

The researchers mapped operating solar parks and wind farms in 40 countries across the European Union, the European Free Trade Association and EU candidate states, excluding rooftop installations, and found exposed systems in 35 of them. They presented the findings this week at the ONE Conference in The Hague.

Solar accounted for 7,942 of the systems, across 34 countries. Spain had 2,766, or 35% of the total, followed by Greece with 1,860, Italy with 753 and Germany with 672, according to Modat and the NCSC-NL. Those four countries account for 76% of exposed solar systems. Hungary had 514 and Turkey 454.

Wind accounted for 605 exposed systems in 23 countries, led by Germany with 212 and Italy with 192. Spain, which led the solar count, had only 11.

The researchers said the figures are likely an undercount, because systems were counted only once they could be confidently tied to specific sites. The count covers systems, not solar panels or wind turbines, and some of the systems found control several turbines or entire wind farms.

Start and stop

One example in the report is the web interface of a single wind turbine, reachable from the internet, showing live production data alongside start, stop and reset controls. Another page opens the web server of the Siemens programmable logic controller that runs the turbine, and a map page shows the turbine’s location. Other exposed login pages named the wind park they protected, and one noted that its default username was “root.”

Modat said it identified the systems with machine-learning clustering on its Magnify platform, which groups similar systems automatically and surfaced device types the researchers had not written search rules for. The researchers said attackers can map the same systems just as quickly. AI tools have already been used to find remote shutdown weaknesses in microinverters.

“What we can map in hours, an attacker can map in hours too. You can’t defend what you can’t see, and no one can see this whole landscape alone,” said Soufian El Yadmani, Modat’s founder and chief executive, who co-authored the report with NCSC-NL’s Bouke van Laethem.

The researchers published only aggregated country figures and did not name specific projects, operators or IP addresses. The affected parties are being informed through national computer emergency response teams. The report urges operators to take admin interfaces off the internet immediately, assume attackers are already inside their networks, and build visibility over the equipment that suppliers and service providers connect.

Thomas Plank, chief executive of Austrian industrial cybersecurity company Tributech, told pv magazine that taking the interfaces offline would not be enough, because unmanned, widely distributed sites must stay connected for grid operators, traders and maintenance contractors. “Today many can’t independently verify whether the data their control systems rely on is genuine or has been tampered with along the way,” said Plank.

Poland precedent

The report cites the December 2025 attacks on Poland’s energy sector, which hit at least 30 wind and solar farms. Poland’s national computer emergency response team, CERT Polska, found that attackers entered through internet-exposed firewall devices, many without multi-factor authentication, then used default credentials to disable remote terminal units, protection relays, operator workstations and communications equipment at grid connection substations.

The sites lost communication with distribution grid operators, though generation continued. CERT Polska attributed the attacks to a group associated with Russia’s Federal Security Service. The incident has since exposed gaps in cyber insurance for battery storage.

In 2025, cybersecurity company Forescout found about 35,000 solar devices with internet-exposed management interfaces, 76% of them in Europe. The European Union is also weighing restrictions on inverters from high-risk suppliers.

Renewables generated 54% of EU electricity in the second quarter of 2026, according to Eurostat, with solar providing 42% of that renewable output and wind 28%.

Italy, which ranked third in the Modat study’s solar-system count, has meanwhile introduced rules requiring solar and wind plants above 100 kW to install central controllers that allow remote power control, with deadlines running through 2028.

This content is protected by copyright and may not be reused. If you want to cooperate with us and would like to reuse some of our content, please contact: [email protected].

More about
Written by

Comments