Thousands of European solar and wind systems exposed online, raising critical infrastructure concerns

Thousands of systems are visible from the public internet

Thousands of digital systems used to manage and operate European solar parks and wind farms are exposed to the public internet, creating a significant cybersecurity concern for renewable-energy infrastructure.

That is the central finding of research published on October 6 by European internet-intelligence company Modat, together with Bouke van Laethem of the Dutch National Cyber Security Centre (NCSC-NL).

The researchers identified 8,547 internet-facing systems that they could confidently attribute to operating solar parks and wind farms across 35 countries. The research covered 40 countries across the European Union, EFTA and EU candidate states.

The number is explicitly described as a lower bound, because researchers only counted systems when they could confidently link them to a specific renewable-energy site.


Some systems exposed operational controls

The research covered EU countries, EFTA members and EU candidate states.
The systems involved sit within the broader world of Operational Technology (OT) and Industrial Control Systems (ICS).

The issue goes beyond ordinary websites or informational dashboards.

The research found exposed administrative interfaces, login pages and operational interfaces.

In one example, a wind-turbine web interface displayed live production information together with Start, Stop and Reset controls. Some systems could manage multiple turbines or an entire wind farm.

Researchers assessed that approximately 181 locations could potentially have been fully controlled.

That does not mean those sites were hacked.

It means the researchers found enough exposure to assess that full operational control might have been possible.

The distinction matters:

Exposure is not the same as compromise.


Why OT security matters

The systems involved sit within the broader world of Operational Technology (OT) and Industrial Control Systems (ICS).

These technologies connect the digital layer of an energy facility to physical processes.

For renewable-energy operators, that can include:

  • turbines;
  • inverters;
  • monitoring systems;
  • protection equipment;
  • plant controllers;
  • remote-management systems.

If an administrative or operational interface is unnecessarily reachable from the public internet, the potential impact extends beyond stolen information.

A successful intrusion could potentially affect availability or physical operation.


AI can accelerate attack-surface mapping

Modat used machine-learning clustering through its Magnify platform to identify and group exposed systems across the internet.

The researchers say the approach helped surface device types for which specific detection rules had not previously been written.

That creates an important cybersecurity challenge.

The same automation that allows defenders to map infrastructure faster can also make it easier for attackers to discover large numbers of exposed systems.

The research therefore highlights not just a configuration problem, but a broader shift in the speed at which internet-facing infrastructure can be discovered.

KEY TAKEAWAYS

🔐 Researchers identified 8,547 internet-exposed systems linked to wind farms and solar parks across 35 European countries.

⚠️ Around 181 locations were assessed as potentially allowing full operational control.

🌐 Exposure does not mean that the systems were hacked.

🤖 Machine-learning techniques helped researchers identify and classify exposed infrastructure.

🛡️ The primary recommendation is to remove administrative and operational control interfaces from the public internet.


Renewable energy is becoming critical infrastructure

The research covered EU countries, EFTA members and EU candidate states.

The finding comes at a time when renewable generation represents an increasingly important share of Europe’s electricity system.

According to figures cited by Modat, renewables accounted for 54% of EU electricity generation in the second quarter of 2026, with solar and wind making up the largest portions of renewable generation.

That changes the cybersecurity equation.

A vulnerable renewable-energy system is no longer simply an isolated industrial asset.

At scale, renewable infrastructure contributes to:

  • grid stability;
  • electricity availability;
  • production balancing;
  • energy security;
  • resilience against physical and cyber disruption.

An attack on a single facility might have limited consequences. A coordinated attack against many distributed systems could be considerably more serious.


What about Albania?

The research covered EU countries, EFTA members and EU candidate states. Albania falls within that broader geographic category.

However, the researchers did not publish a specific number for Albania in the material reviewed for this article.

It would therefore be inaccurate to claim that the research proves Albanian renewable-energy facilities are exposed.

The finding is nevertheless relevant to Albania as the country expands solar and potentially wind generation and increasingly relies on digitally managed energy infrastructure.

The lesson is broader than the specific countries identified:

Renewable-energy expansion also requires cybersecurity expansion.


What operators should do

The researchers’ central recommendation is straightforward: administrative and operational control interfaces should not be directly exposed to the public internet.

That means operators should consider:

  1. Removing control interfaces from the public internet.
  2. Using secure VPN access for remote management.
  3. Strong authentication and, where possible, multi-factor authentication.
  4. Segmentation between IT and OT networks.
  5. Eliminating default credentials.
  6. Continuous external attack-surface monitoring.
  7. Maintaining an accurate inventory of internet-connected assets.
  8. Coordinating with national CERT/CSIRT organizations when exposure is discovered.

Modat says it did not publish park names, operators, IP addresses or precise locations and that affected organizations were notified through national CERTs.


What happens next?

The immediate task is remediation: identifying the owners of exposed systems and closing unnecessary internet access.

But the researchers stress that the 8,547 figure should not be treated as the complete universe of exposed infrastructure.

It represents systems that could be confidently attributed to specific solar parks and wind farms. Other systems with similar characteristics may remain unattributed.

That leaves Europe with a larger strategic question:

How much of its increasingly digital energy infrastructure can an attacker map before an attack even begins?

The answer will depend not only on vulnerability management, but also on how operators design remote access, segmentation and continuous exposure monitoring.

Europe is building a greener, more distributed and increasingly digital electricity system.

But physical decentralization does not automatically create digital resilience.

The discovery of 8,547 exposed systems shows that thousands of renewable-energy assets can be visible from the public internet. In a smaller subset of cases, researchers assessed that operational control could potentially have been possible.

There is no evidence from this research of a mass compromise of those systems.

That distinction is important.

But the warning is equally clear: critical energy infrastructure should not wait for a successful attack before fixing an exposed control interface.

Researchers found 8,547 internet-exposed systems linked to European solar parks and wind farms, raising new cybersecurity concerns for critical energy infrastructure.

Share.
Leave A Reply

Exit mobile version