Dutch researchers found 8,547 internet-exposed systems linked to European wind and solar farms, with around 181 potentially allowing attackers full operational control.

Thousands of European Wind and Solar Systems Exposed Online, Raising Sabotage Fears

The420 Web Correspondent
10 Min Read

Thousands of digital systems used to manage wind and solar power facilities across Europe are directly exposed to the public internet, creating a potential route for hackers to interfere with critical energy infrastructure.

Dutch researchers identified 8,547 exposed systems across 35 countries, including administrative portals, login pages and operational control interfaces connected to active renewable-energy sites.

In around 181 cases, researchers believe an attacker could potentially have gained full control of the system.

The findings were presented on October 6 at the ONE Conference in The Hague by researchers from Dutch internet-intelligence company Modat and the Netherlands’ National Cyber Security Centre.

FCRF Launches CP-FRM to Build India’s Next Generation of Fraud Risk Professionals

Some Interfaces Could Control Entire Wind Farms

The exposed systems were not limited to harmless monitoring dashboards.

Researchers found operational interfaces capable of showing live information and, in some cases, providing direct controls over renewable-energy equipment.

One wind-turbine interface displayed its location and live operational data alongside buttons marked “Start”, “Stop” and “Reset”.

Some systems controlled more than one turbine.

Others were connected to an entire wind or solar farm, meaning the number of physical energy assets potentially affected could be much larger than the number of exposed systems counted.

8,547 Is a Minimum Estimate

The researchers stressed that the figure should be treated as a lower bound.

They counted a system only when they could confidently connect it to a particular wind or solar facility.

Many other internet-facing systems showed similar technical characteristics but could not be definitively tied to a renewable-energy site and were therefore excluded.

The research initially examined operating sites across 40 countries in the European Union, European Free Trade Association and EU candidate states.

Exposed systems were confirmed in 35 of them.

Spain and Greece Had Most Exposed Solar Systems

The geographical distribution differed depending on the type of renewable infrastructure.

Spain and Greece had the highest numbers of exposed solar systems, while Germany and Italy had the largest concentrations of exposed wind-related systems, Reuters reported.

That does not necessarily mean those countries have weaker cybersecurity overall.

Countries with larger renewable-energy sectors naturally operate more digital infrastructure, which can increase the number of systems visible during large-scale internet scans.

The core security problem is that management interfaces capable of controlling critical physical equipment should generally not be directly reachable from the open internet.

Researchers Say Attackers Can Find the Same Systems

Modat used internet-wide scanning and clustering techniques to map the exposed equipment.

The researchers warned that the same methods are available to criminals and state-backed attackers.

“What we can map in hours, an attacker can map in hours too,” the report said.

That makes obscurity a poor security strategy.

An operator may believe an obscure login panel will remain unnoticed because its address is not publicly advertised.

Automated scanning tools can still discover such systems by examining millions of internet addresses and identifying software signatures associated with energy infrastructure.

Public Internet Access Creates a Critical Weakness

Industrial control systems were traditionally designed for isolated operational networks.

Renewable-energy facilities have increasingly become connected to the internet so operators can monitor output, diagnose faults and remotely manage equipment spread across large geographical areas.

That connectivity brings major operational advantages.

It also creates new attack surfaces.

If a management interface is exposed without strong authentication, network isolation or access controls, an attacker may be able to reach equipment that controls physical processes.

For wind or solar sites, that could potentially include changing settings, interrupting production or shutting equipment down.

Full Control Was Possible in a Smaller Number of Cases

The presence of an exposed interface does not automatically mean hackers could immediately take control.

Many systems still had passwords or other protections.

The researchers therefore separated general internet exposure from systems where they believed complete control could have been possible.

They estimated that around 181 exposed systems potentially fell into the latter category.

That distinction matters.

The larger 8,547 number represents systems that should not have been publicly reachable.

It does not mean all 8,547 wind and solar sites could have been remotely switched off by anyone on the internet.

Renewable Energy Creates a Different Cybersecurity Problem

Traditional power generation is relatively concentrated.

A large nuclear or coal plant might operate from a limited number of heavily secured industrial sites.

Renewable power is much more distributed.

Europe now has thousands of wind turbines, solar farms and remote energy installations spread across multiple countries.

That makes physical attacks harder to coordinate at scale.

Digitally, however, the distributed infrastructure can still become connected through common technologies, remote-management platforms and exposed internet services.

The researchers described that contrast as a major weakness: renewable infrastructure is physically dispersed but can remain unexpectedly visible online.

Energy Systems Have Already Become Cyber Targets

The warning comes amid increasing concern about cyberattacks against European energy infrastructure.

Since Russia’s invasion of Ukraine in 2022, governments across Europe have increased security around power grids, pipelines, communications networks and other critical infrastructure.

Cyberattacks have also moved beyond information theft into attempts to disrupt physical operations.

Reuters pointed to a 2025 cyberattack affecting Polish energy sites as an example of the growing threat to industrial systems.

Researchers did not say the systems identified in the latest study had already been compromised.

The finding is about exposure and potential attack paths, not proof of an active mass intrusion.

Why Stopping a Turbine Matters

Interrupting a single turbine would generally have limited impact on a national electricity grid.

The concern becomes more serious if attackers gain access to systems controlling multiple turbines or several renewable facilities at once.

Electricity grids must constantly balance supply and demand.

A coordinated and unexpected loss of generation can force grid operators to rapidly bring other power sources online or import electricity.

The risk would be greater during periods when power systems are already under stress.

That is why cybersecurity authorities increasingly treat energy-sector software and remote-management interfaces as part of critical infrastructure.

Researchers Urge Operators to Remove Public Access

The primary recommendation is straightforward: sensitive control interfaces should not be directly exposed to the public internet.

Operators can instead use secure private networks, virtual private networks, strong authentication and strict access controls to limit who can reach operational systems.

Systems that no longer require remote access should have unnecessary services disabled entirely.

Researchers also urged operators to continuously scan their own infrastructure to identify services that may have been accidentally exposed.

The challenge is particularly important for smaller energy operators, which may not have large dedicated cybersecurity teams.

Internet Exposure Does Not Require Sophisticated Hacking

One lesson from the research is that attackers do not always need a previously unknown software vulnerability.

If an industrial system is already reachable from the internet, basic reconnaissance may provide an attacker with information about the software, location and function of the equipment.

Weak or default passwords can make the situation worse.

This means some critical-infrastructure risks can be reduced through relatively basic cybersecurity practices before expensive defensive technology is required.

European Energy Security Now Includes Cybersecurity

Europe’s energy transition is adding large amounts of renewable generation while also making electricity infrastructure increasingly software-dependent.

Wind farms, solar installations, batteries and grid-control systems now rely heavily on remote monitoring and automated management.

That means cybersecurity is no longer separate from energy security.

A poorly configured web interface can become a physical infrastructure risk.

The Dutch research shows that the problem is not hypothetical: thousands of energy-related systems are already visible from the public internet.

What this means for you

The immediate risk is not that thousands of European wind turbines can suddenly be switched off at once. The bigger warning is that critical energy equipment is being connected to the internet faster than some operators are securing it, giving attackers avoidable paths into systems that control physical infrastructure.

Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics

Stay Connected