8,547 open control systems at European renewable plants
Researchers from Modat and NCSC found thousands of administrative and control systems at solar and wind facilities across 35 countries openly accessible on the internet — at around 181 sites, they believe full remote control would have been possible. No sites have been publicly identified, and there is no evidence that any of them were attacked.
Dutch security research has mapped how much of Europe's green power production is actually reachable from the internet. The result: 8,547 systems at solar and wind parks that, according to the researchers, should never have been exposed at all.
The findings were presented at the ONE Conference in The Hague on October 6, 2026 by Soufian El Yadmani of internet-scanning firm Modat and Bouke van Laethem of the Dutch national cyber security centre NCSC-NL, according to Reuters and Channel NewsAsia via UA.News.
What the exposure meant in practice
The majority of the findings concerned solar parks: 7,942 exposed systems versus 605 at wind parks, spread across 35 European countries. One example from the research shows how far the access could reach: a turbine's web page displayed live data, buttons for "Start, Stop and Reset" and the turbine's position. Some systems controlled several turbines or an entire park, according to Reuters' account of the presentation.
At around 181 sites, the researchers believed full control would have been possible, El Yadmani told Reuters. He particularly highlighted facilities closely tied to critical societal infrastructure: "If you can switch off the energy in the city or at the airport, imagine that on a larger scale," he said, according to Reuters.
How the research was done
The method is itself an example of machine learning applied in practical security work. The researchers used ML clustering in Modat's tool Magnify, which automatically groups similar systems on the internet — and thereby found device types for which no rules had been written, according to a write-up of the research in OceanNews/ON&T.
One exposed login page named the wind park it "protected," and stated that the default username was "root."
The figure of 8,547 is a lower bound. The researchers only counted a system once they could confidently link it to a specific solar park or wind farm, so the real number may be higher.
Where were the systems found?
- Solar: Spain tops the list with 2,766 exposed systems, Greece follows with 1,860. The Netherlands has 132.
- Wind: Germany has the most with 212, Italy just behind with 192. The Netherlands has nine.
The scan covered, according to OceanNews, operating parks in 40 EU, EFTA and EU-candidate countries, with exposed findings in 35 of them. The relationship between the countries in the per-country figures (solar found in 34 countries, wind in 23) is not fully explained in the sources.
The context is power plants producing an ever-larger share of electricity: according to Eurostat, renewables supplied 54 percent of the EU's electricity in the second quarter of 2026.
The threat picture — and what is not confirmed
The report cites CERT Polska's analysis of a December 2025 attack on 30 wind and solar installations in Poland as an example of the potential threat. But it is important to distinguish context from documentation: no sources link the exposed systems the researchers found to any attack, and it is not known whether any of the roughly 181 sites with assumed full control were actually compromised.
The findings come at a time when European critical infrastructure has been subject to suspected sabotage and cyberattacks, often attributed to Russia by Western governments since Russia's full-scale invasion of Ukraine in 2022 — something Russia denies any involvement in. No sources link the exposed renewable installations to any state actor.
The presentation took place weeks after a joint statement in September 2026 in which the Dutch intelligence and security services, NCSC, NCTV, the Government CIO, the prosecution service and the police warned that AI is accelerating the cyber threat to critical infrastructure — a general warning, not a description of how these systems became exposed.
What happens now?
The researchers are publishing only aggregated figures per country. Names of parks, operators, IP addresses and locations have not been made public. Affected parties are being notified via their national CERTs — a responsible-disclosure practice that gives operators a path to fix the systems without public embarrassment.
The European cyber security agency ENISA could not immediately comment, and authorities in Germany, Italy and Spain did not respond to inquiries, according to Reuters. The question that remains is practical: administration interfaces for power production on open internet connections are a well-known misconfiguration — and with more than half of the EU's electricity now coming from renewable sources, the stakes are markedly higher than when these systems were built.

