Summary
- Researchers identified 8,547 internet-facing systems associated with wind and solar installations across 35 European countries.
- Some interfaces provided operational functions, with 181 systems reported as potentially allowing extensive control.
- The research documents exposure rather than evidence that attackers compromised the identified systems.
Researchers have identified 8,547 internet-facing systems associated with European wind and solar installations, including interfaces connected to operational equipment.
Modat carried out the research with the Netherlands’ National Cyber Security Centre, using internet scan data to identify systems that could be associated with renewable energy sites across 35 European countries.
The systems included administrative interfaces and equipment controls. Reuters reported that some exposed interfaces could be used to start, stop or reset turbines, while 181 systems appeared to provide particularly extensive levels of control.
Spain and Greece had the largest numbers of exposed solar systems identified in the research. Germany and Italy recorded the largest numbers associated with wind installations.
None of those findings establishes that the systems were compromised. An internet-facing service is exposed to discovery and connection attempts, but successful access still depends on its configuration, authentication and other controls around it.
Operational access raises the potential impact
The consequences change when an exposed interface reaches beyond monitoring and into operational control. A system that reports generation data presents a different risk from one that can issue commands to equipment because unauthorised access to the latter can affect availability and physical processes.
Renewable generation also creates a distributed technology estate. Wind farms and solar parks can contain large numbers of geographically dispersed assets supported by remote management services, communications links and supplier platforms. Those systems help operators manage equipment at scale, but every external connection becomes part of the environment that has to be secured.
The research provides a measurement of that exposure. More than 8,500 systems were sufficiently visible to be identified and associated with European renewable energy infrastructure, while a smaller group appeared to expose functions with more substantial operational consequences.
The effect of compromising one installation would vary according to the equipment, its generating capacity, network design, protective controls and the operator’s ability to detect and recover from interference. The research does not show that access to one interface would automatically produce a wider grid event.
It does demonstrate that some technology used around electricity generation remains directly reachable from networks that any remote attacker can scan. Operational technology is often discussed as though its security boundary begins inside the plant, but remote administration and connected services can extend that boundary considerably further.
European authorities are already examining cyber risk across distributed energy systems as solar and wind capacity becomes a larger part of electricity supply. Previous Cyber Insider coverage of connected solar focused on European Commission recommendations for reducing cyber risk in photovoltaic equipment. The Modat research adds a different type of evidence by measuring what is already visible online.
Modat also points to attacks against energy infrastructure as evidence of the environment in which these systems operate. Its latest work does not attribute hostile activity to any of the installations it identified and does not claim that the exposed interfaces were used in an attack.
The finding is narrower and more concrete. Thousands of systems associated with European renewable generation were reachable from the public internet when the research was conducted, some exposed operational functions, and 181 appeared to provide particularly extensive control.





