Summary
- ENISA and European grid organisations convened the forum on 8 October.
- A demonstration considered possible movement from compromised home equipment to energy devices.
- The demonstration is not evidence that a large-scale grid manipulation attack has occurred.
European energy cybersecurity organisations have warned that growing numbers of connected solar inverters, batteries and other distributed energy devices are creating new routes for attackers to influence electricity systems, as grid operators review lessons from recent attacks on critical infrastructure.
The subject was examined at a Brussels forum on 8 October organised by E.DSO, EE-ISAC, ENCS and the European Union Agency for Cybersecurity. The meeting brought together operators and researchers to discuss the practical security of a power system becoming more distributed and digitally connected.
ENCS researchers presented a scenario in which an attacker who already controls an ordinary household device, such as a router or camera, attempts to communicate with a solar inverter or home battery sharing the local network.
The concern arises where equipment uses protocols that do not authenticate every control command. Under such conditions, an attacker with network access may be able to influence the operation of energy equipment without directly exploiting the inverter’s operating system.
This is a demonstrated or assessed attack route, not confirmation that a criminal or state actor has already manipulated thousands of residential batteries. Individual household effects would also differ from the wider network consequences that might arise if many devices were controlled simultaneously.
The discussion follows coordinated cyberattacks against parts of Poland’s energy sector in December 2025. According to the organisers’ account, communications between some affected sites and distribution operators were lost, although electricity generation continued. That distinction illustrates how an intrusion may impair visibility or control without immediately interrupting physical output.
Ukraine’s transmission system operator Ukrenergo also described operating under sustained attack and using AI-assisted tools to help staff respond, locate gaps and manage reporting. Its experience was presented alongside the need to retain human authority over decisions affecting critical operations.
European energy operators are implementing requirements under NIS2 and the Network Code on Cybersecurity, while the distribution of risk increasingly extends to manufacturers, equipment owners, service providers and consumers. The installation of a connected device can introduce dependencies outside the direct control of a utility.
Independent testing, manufacturer vulnerability management and information sharing are among the measures discussed at the forum. Their effectiveness depends on whether practical controls cover devices at the edges of the network as well as large, centrally managed grid assets.
Distribution networks increasingly interact with equipment outside the traditional utility estate. Residential solar inverters, batteries and smart devices can connect through home networks that were not originally designed as part of critical energy infrastructure. Their manufacturers, installers, household owners and grid operators may consequently hold different parts of the security responsibility.
Poland’s December 2025 energy-sector attacks affected communications between renewable installations and distribution operators, according to the account presented at the Brussels meeting. Electricity generation was not reported to have stopped, although the loss of operational communications showed how digital compromise can affect oversight even without a blackout.
ENCS researchers described an attack route beginning with a compromised domestic device such as a router or camera. In their demonstration, unauthenticated commands on a shared local network could potentially influence compatible solar or battery equipment. The example is a controlled scenario rather than evidence of a live coordinated compromise of thousands of homes.
Ukraine’s electricity transmission operator also described using AI tools to support technical analysis and reporting while retaining human control over decisions affecting grid operations. The practical constraints include maintaining experienced staff and preserving recovery capabilities during sustained attacks.
Ukraine’s transmission operator is also discussing how AI can support threat detection and reporting while keeping consequential decisions under human control. Its operational setting under sustained attack differs from ordinary European utility conditions, but the underlying question of scarce specialist capacity is shared across the sector.




