Yaamlabs
Resilience

8,547 European wind and solar systems reachable online

Modat and NCSC-NL found 8,547 admin pages and control panels at European solar and wind sites open to the internet. How to find and close yours.

By Yaali. October 11, 2026, 6 min read, Resilience, Threat intel.

Cover illustration of a solar park and wind turbines at dusk with network lines rising from a control cabinet, with the Yaamlabs logo and the text: Europe's wind and solar parks left reachable online, 181, sites where full control looked possible

Modat, an internet intelligence company in The Hague, and the Dutch National Cyber Security Centre (NCSC-NL) found 8,547 internet-facing systems at European solar parks and wind farms that should not be reachable from the internet. Soufian El Yadmani of Modat and Bouke van Laethem of NCSC-NL presented the work on October 6 at the ONE Conference in The Hague. They mapped operating utility-scale sites in 40 countries across the EU, EFTA and EU candidate states, rooftop solar excluded, and found exposed systems in 35 of them.

Many of the exposed systems are login pages for admin interfaces, but not all. The researchers estimated that full, direct control was technically possible at about 181 sites; some outlets round this to 180. If you own, operate, maintain or integrate a solar park or wind farm in Europe, assume some of these systems could be yours: names, operators and IP addresses were not published, and affected parties are being told through their national computer emergency response team (CERT), which may not have reached you yet.

Exposure counts from the Modat and NCSC-NL study: 8,547 systems in 35 of 40 countries, 7,942 at solar parks and 605 at wind farms, with Spain, Greece, Italy and Germany leading solar and Germany and Italy leading wind

What was found

Solar accounts for 7,942 of the systems, across 34 countries. Spain alone has 2,766, which is 35% of the solar total, followed by Greece with 1,860, Italy with 753 and Germany with 672. Those four countries hold 76% of exposed solar systems. Wind accounts for 605 systems in 23 countries, and Germany (212) and Italy (192) make up 67% of that. The Netherlands, home to both research teams, has 132 solar and 9 wind systems on the list.

The figures count systems, not panels or turbines. One exposed system may be a single turbine's web interface; another may control several turbines or a whole farm from one screen. The researchers only counted systems they could confidently tie to a specific park, so they describe 8,547 as a lower bound. Reporting differs on the headline: PV Tech wrote "almost 8,000", which is the solar figure on its own, while other outlets round the total to "more than 8,500". The exact combined count in Modat's report is 8,547.

How the exposure works

Utility-scale solar and wind sites are unmanned. Grid operators, energy traders, the operations and maintenance contractor and the equipment vendor all need to reach them remotely, so turbine controllers, inverter portals and monitoring systems often end up with a web interface on a public address. Once that page answers on the internet, scanners index its title, banner and content like any other website.

The examples in the report show what that means in practice. One wind turbine page showed live production data, the turbine's position on a map and Start, Stop and Reset buttons. Several login pages named the wind park they protected, and one displayed the default username, "root". PV Tech reports that many devices were misconfigured or left on default settings, which turns a login page into an easy target for anyone trying vendor default passwords.

Modat found many of these systems with machine-learning clustering in its Magnify platform, which groups internet-facing systems that look alike. That surfaced device types nobody had written a detection rule for. The researchers make the obvious point that attackers can do the same: "What we can map in hours, an attacker can map in hours too."

What attackers are doing

The study reports exposure, not intrusions. No source says any of these 8,547 systems has been abused, and no park was switched off as part of the research.

A recent attack in Poland shows what this kind of access can lead to. In late December 2025, attackers hit about 30 energy sites in Poland, wind and solar farms among them. CERT Polska found they came in through internet-facing Fortinet FortiGate firewalls without multi-factor authentication (MFA), then used default credentials on operational technology (OT) equipment such as remote terminal units, protection relays and serial device servers. They went after the systems that monitor the sites and connect them to the grid rather than generation itself, disabling operator workstations and damaging some devices beyond repair. There was no power outage. Polish officials blamed Russia.

Steven Swift of Suzu Labs warned that an attacker with control could do more than stop generation, for example changing working settings to force an overload that damages equipment.

What to do

Five steps for wind and solar operators: find your exposure from the outside, take admin interfaces off the internet, put remote access behind a VPN with MFA, replace default credentials, and assume breach with logging and manual operation plans

1. Find what you expose

List every public IP address at each site: the site router, cellular modems, and anything the vendor or the maintenance contractor installed for their own access. Then look at those addresses the way an attacker would. In Shodan, search net: followed by each range (for example net:203.0.113.0/28); in Censys, search ip: 203.0.113.0/28. Search both for your park names too, because some exposed login pages carried them. Finish with an external port scan of the same ranges, since search engines miss services. Modat says operators, vendors and service providers can ask it what of their assets is visible.

2. Take admin interfaces off the internet

Modat and NCSC-NL put this first. Remove port forwards and public addresses that point at turbine controllers, inverter portals, data loggers or monitoring servers. If a contractor set up the access, get it removed in writing and confirm with a fresh scan.

3. Rebuild remote access properly

Grid operators and contractors still need a way in. Route it through a VPN or a remote access gateway with MFA, limited to named accounts and to the systems each party needs. Treat that gateway as critical: the Polish attacks went through firewalls with VPN access and no MFA. Keep it patched and remove contractor accounts when contracts end.

4. Replace default credentials

Change every default password on controllers, relays, remote terminal units, serial servers and HMIs (the human-machine interface screens operators use), and disable default service accounts you do not use. Use unique credentials per site, so one leaked password does not open every park.

5. Assume someone was already in

For any system you find exposed, pull its web server and event logs and look for logins from unknown addresses, configuration changes and start or stop commands nobody ordered. Check firewall logs for inbound connections to the device. The researchers also recommend practising manual operation and having procedures that change with the threat level.

Ownership is the gap

Exposure at renewable sites usually sits between organisations. The asset owner holds the contract, the contractor runs the remote access, and the vendor installs its own modem. Modat recommends keeping a current inventory of assets, architecture and access, including connections that suppliers bring in, and a recurring external scan is the quickest way to see whether that inventory is right.

Our attack surface management service keeps that external view of your sites up to date, and our network penetration testing checks what a remote access path actually lets someone reach. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.


Sources: Modat research announcement, Modat report page, pv magazine, PV Tech, Windtech International, Mercom India, Security Magazine, The Hague newsroom, Archyde, SecurityWeek on the Poland attacks.

Read next

Back to the blog, or tell us about your system in the chat. Yaali, our AI agent, answers first and brings in an engineer.