8,547 European wind and solar systems exposed online, researchers find
Joint research from Modat and the Dutch National Cyber Security Centre identified 8,547 internet-facing systems linked to European solar parks and wind farms. Most were administrative or login pages, but researchers believe about 181 sites may have exposed operational control.
What happened?
Confirmed research findings: on October 6, 2026, Modat published joint research by Soufian El Yadmani of Modat and Bouke van Laethem of the Dutch National Cyber Security Centre. Using internet-wide scan data and machine-learning-assisted clustering, the researchers attributed 8,547 exposed systems to solar parks and wind farms across 35 European countries: 7,942 solar-related systems and 605 wind-related systems. Reuters independently reported on the findings after their presentation at the ONE Conference in The Hague. Most identified systems were administrative pages or login interfaces, which does not by itself prove that an unauthenticated attacker could control equipment. The researchers told Reuters they believed about 181 sites may have allowed full operational control; some interfaces displayed live data or controls for individual turbines, groups of turbines, or entire farms. Responsible-disclosure limits: the public report provides aggregated country figures and withholds operator names, IP addresses, and exact locations. Affected parties were notified through national computer-emergency-response teams. Unknowns: the published material does not establish that all 8,547 systems were vulnerable to the same technique, that every interface lacked authentication, or that attackers exploited these particular exposures. Authorities in several countries and the EU cybersecurity agency had not provided detailed responses in the initial Reuters report.
How the technology works
At a safe defensive level, renewable-energy sites use web interfaces for monitoring, maintenance, vendor support, and operational control. A system becomes internet-facing when its service can be reached directly from the public internet, sometimes through a router, remote-management appliance, cloud gateway, or misconfigured firewall. Exposure is not identical to compromise: a properly authenticated page may still be reachable, while a weakly protected or misconfigured interface can create a path to sensitive data or control functions. Internet-scanning platforms can identify visible services at scale, and clustering can connect device fingerprints, certificates, page content, and location clues to a specific type of facility. The defensive lesson is to remove operational and administrative interfaces from direct public access, route necessary remote work through strongly authenticated gateways, and separate business networks from control systems. This article does not publish searchable identifiers or instructions for locating the exposed sites.
Who is affected?
Wind and solar operators, equipment vendors, maintenance providers, grid coordinators, and communities that depend on these facilities are affected by the risk. Spain had the largest number of attributed solar exposures in the research, followed by Greece; Germany had the most attributed wind-system exposures. Those rankings partly reflect what researchers could confidently connect to known sites and should not be treated as a complete national risk score. A disruption at one small installation may have limited grid impact, but compromised access across many sites or at facilities supporting cities, airports, or other critical services could create a larger operational problem. There is no public evidence that customers' personal information was exposed in this research, and no confirmed outage has been attributed to the 8,547 identified systems.
What should you do?
Operators should immediately inventory every internet-facing asset, remove direct public access to administrative and operational interfaces, and confirm ownership with vendors and service providers. Where remote access is necessary, use a hardened gateway or VPN with phishing-resistant multifactor authentication, device certificates, least privilege, short-lived access, and complete session logging. Change default credentials, disable unused accounts and services, patch supported systems, restrict management traffic to approved sources, and segment operational technology from office and vendor networks. Monitor for unusual logins, configuration changes, start-stop commands, and connections from unfamiliar infrastructure. Validate backups and manual recovery procedures without disrupting production. Procurement contracts should require secure-by-default remote access, supported patch lifecycles, asset inventories, incident notification, and coordinated vulnerability disclosure. National CERTs and regulators should help smaller operators identify exposed assets without publishing details that would increase risk.
My analysis
My Analysis — opinion and inference: renewable energy is physically distributed, but public internet exposure can erase much of that resilience by putting many separate sites within reach of the same scanning and attack workflow. My privacy-first position is that visibility should work for defenders without becoming a public target list. The researchers were right to publish aggregated findings, withhold operator and location details, and coordinate notification through national CERTs. My inference is that a significant share of the problem will trace to forgotten vendor access, inherited default configurations, and unclear responsibility between operators, installers, and equipment manufacturers; that is a risk assessment, not a finding about every identified system. The research should not be used to claim that 8,547 power plants were hacked or remotely controllable. It should be used to demand a measurable reduction in exposed interfaces, stronger authentication, independent verification, and clear ownership of every connection that can affect physical operations.
Why this matters
Cyber incidents often sound distant or overly technical. The important question is whether the same weakness, behavior, surveillance power, or exposure exists in systems you use. Facts and opinion are separated here so you can judge both clearly.
Facts, claims, and unknowns are separated above. Details may change as investigations and official statements develop.
Modat and NCSC-NL: To See the Wind and the Sun research Reuters: thousands of European wind and solar systems exposed online CERT Polska: December 2025 energy-sector incident report CERT Polska: follow-up report and defensive findings