Researchers from Modat and the Dutch National Cyber Security Centre (NCSC-NL) have identified 8,547 internet-facing systems linked to wind and solar parks across Europe that should not be publicly accessible.
The findings, presented at The ONE Conference in The Hague, cover 35 countries in the European Union, EFTA and candidate states. The exposed systems include administrative interfaces and control panels associated with operating renewable-energy assets.
The researchers mapped wind and solar facilities across 40 European countries. Their results should be considered a lower bound, as only systems that could be confidently linked to a specific energy asset were counted. One exposed system may also control several turbines or an entire wind or solar park.
Key findings
- Solar energy: 7,942 exposed systems were identified in 34 countries. Spain accounted for 2,766 systems, or 35% of the total. Spain, Greece, Italy and Germany together represented 76%.
- Wind energy: 605 exposed systems were identified in 23 countries. Germany and Italy accounted for 212 and 192 systems respectively, together representing 67% of the total.
- The Netherlands: Researchers identified 132 exposed solar systems and nine exposed wind systems.
Examples included a web interface for an individual wind turbine displaying live production data, controls such as Start, Stop and Reset, and the turbine’s map location. Other login pages revealed the name of the wind park, while one even displayed the default username “root”.
Physically robust, digitally exposed
While distributed renewable-energy assets may be difficult to target physically, their digital exposure creates a different risk. The researchers used machine-learning clustering within Modat Magnify to group similar online systems and identify device types at scale without relying on manually written rules. The same speed and automation, they warn, can also be used by attackers.
The research follows a September 2026 statement by Dutch intelligence and security services warning that artificial intelligence is accelerating the cyber-threat landscape. It also comes at a time when renewable sources supplied 54% of electricity in the European Union during the second quarter of 2026, according to Eurostat, with solar accounting for 42% and wind for 28% of renewable generation.
“Physically, wind and sun are the most robust parts of our energy supply. Digitally, they are fragmented, often exposed to the internet and not always monitored. What we can map in hours, an attacker can map in hours too. You can’t defend what you can’t see, and no one can see this whole landscape alone,” said Soufian El Yadmani of Modat.
What operators can do now
- Remove administrative interfaces from the public internet immediately.
- Adopt an “assume breach” approach and monitor environments as though an attacker may already be present.
- Implement secure connectivity based on operational technology security principles.
- Prepare alternative operating modes, including manual OT operation.
- Adapt standard operating procedures to defined threat levels and triggers.
- Maintain clear visibility of assets, architecture, access paths and connections involving suppliers and service providers.
- Exchange intelligence, experience and knowledge at sector, national and European level.
A public-private partnership from The Hague
The project combines Modat’s expertise in mapping internet infrastructure with NCSC-NL’s mission to strengthen digital resilience. The researchers said the partnership made it possible to establish a broad, evidence-based picture of the exposure affecting Europe’s renewable-energy infrastructure.
Responsible publication
Only aggregated country-level figures have been published. No individual parks, operators, IP addresses or precise locations have been disclosed. Affected parties were informed through the relevant national computer emergency response teams.
About Modat
Modat is a European internet-intelligence company that continuously maps, profiles and analyses internet infrastructure to help organisations understand potentially malicious intent before infrastructure is weaponised. It supports governments, national CERTs, critical-infrastructure operators, security companies and enterprises. More information is available at modat.io.
#CyberSecurity #RenewableEnergy #WindEnergy #SolarEnergy #CriticalInfrastructure #EnergySecurity #Modat #NCSCNL


