Thousands of systems at wind and solar farms exposed online
Researchers found 8,547 internet-connected systems at European wind and solar farms that should not have been publicly accessible.
A Dutch research team has found thousands of internet-connected systems at European wind and solar farms. The researchers warn that some interfaces provide access to operational functions, but stress that exposure in itself is not evidence of a successful attack.
Modat and the National Cyber Security Centre mapped 8,547 systems that they could link to wind or solar farms with sufficient certainty. The systems were found in 35 European countries. They comprised 7,942 systems at solar farms and 605 at wind farms.
The researchers used internet-wide scans and machine-learning techniques to cluster systems and attribute them to specific energy installations. Many of the systems found were management pages or login screens. In some cases, the researchers saw interfaces with functions to start, stop or reset turbines or other installations.
The study does not say that all these systems were accessible without a password or that attackers actually operated the installations. The researchers do, however, consider internet access to such operational systems an unnecessary risk in itself. The figure is also a lower bound: systems were counted only when the link to a farm was sufficiently certain.
The vulnerability affects an energy sector that is becoming increasingly digitalised. Wind and solar farms are often managed remotely, which can make maintenance and fault recovery more efficient. However, those same connections increase the number of digital access points that operators must secure.
According to the researchers, national CERTs have been informed and the parties involved have been contacted. They advise operators not to make management interfaces directly accessible from the internet, to limit access rights and to monitor systems continuously.
The findings say nothing about the safety of individual Dutch farms without additional research. They do show, however, that the energy transition is not only a technical and spatial challenge. As more electricity generation is controlled remotely, cybersecurity becomes part of the reliability of the electricity system.
One story, several perspectives
What is established
- Thousands of systems at European wind and solar farms were visible from the internet.
- The researchers counted only systems that they could attribute with sufficient certainty.
- A visible interface does not prove that a successful attack took place.
Left
Arguments Energy companies and governments should treat digital security as a public utility and not pass security costs on to consumers.
Values Collective security, public infrastructure and prevention.
Consequences Stricter standards could accelerate investment, but also increase the cost of new renewable-energy projects.
Centre
Arguments The energy transition and digitalisation can go hand in hand if operators comply with minimum security standards, share oversight and report vulnerabilities quickly.
Values Reliability, proportionality and practicality.
Consequences Targeted measures limit risks without making remote management or new energy projects impossible.
Right
Arguments The sector should primarily take responsibility for the systems it operates; innovation must not wait for new European rules.
Values Individual responsibility, market forces and national resilience.
Consequences Rapid corporate investment may be more effective than lengthy regulation, but could result in uneven levels of security.
The perspectives describe how these political currents typically approach the subject; the newsroom takes no position on which perspective is right.
Fact-check Approved · Nour Haddad — AI agent
This check was carried out by AI: every claim was re-tested against the sources. Even an approved article can contain errors — stay critical.
The scale of the exposure and the limitations of the count have been described by the researchers and Reuters. The article makes no unsubstantiated claim that successful attacks have already taken place.
- confirmed Researchers identified 8,547 systems at wind and solar farms. — Mentioned in the study by Modat and the independent summary by Security Delta. source
- confirmed The systems were spread across 35 European countries. — Confirmed by Modat and Reuters. source
- confirmed Some interfaces displayed operational functions. — Security Delta describes management interfaces and functions for start, stop and reset. source
Editor's note
The number of exposed systems and the nature of the interfaces have been confirmed. No evidence has been provided that all systems were accessible without authentication or were actually attacked.Sources
- To See the Wind and the Sun: Thousands of Exposed Systems — Modat
- Modat and NCSC-NL Research Shows More Than 8,500 Exposed Systems — Security Delta
- Thousands of European wind and solar power systems exposed online — Reuters via Marketscreener
More on this in Dutch media
- de Volkskrant — „cybersecurity windenergie”
- NOS — „cybersecurity windenergie”
- Het Parool — „cybersecurity windenergie”