Thousands of European Renewable Energy Systems Exposed Online, Posing Critical Infrastructure Risk
Researchers have discovered over 8,500 internet-accessible systems controlling wind and solar parks across Europe, many with critical functions like turbine stop buttons, creating significant cybersecurity vulnerabilities.

A recent investigation by Modat and NCSC-NL, the Dutch government's cybersecurity center, has uncovered a startling number of internet-facing systems within European wind and solar parks that should not be accessible from the public internet. The study identified 8,547 such systems spread across 35 countries in and around the European Union. These exposed assets range from simple login screens to sophisticated control pages that include critical functions, such as a "Stop" button for wind turbines, accessible to anyone with a web browser.
The geographical distribution of these exposed systems highlights particular concentrations in Spain, Greece, Italy, and Germany, which together account for the majority of the identified assets. Researchers emphasized that the true number is likely higher, as a system was only included in the count if it could be definitively linked to a specific solar or wind energy site. This widespread exposure presents a significant cybersecurity risk to Europe's critical energy infrastructure, despite the physical decentralization of these assets offering some resilience against traditional sabotage.
One of the key findings involves the technical details of the exposure. Researchers utilized machine-learning clustering to identify devices, enabling the discovery of previously unknown system types. For instance, one identified wind turbine's web dashboard not only displayed real-time operational data like power output and wind speed but also provided direct control over the turbine's "Start," "Stop," and "Reset" functions. Furthermore, the system's web server, running on a Siemens ET 200SP PLC, was directly accessible, and a map feature revealed the turbine's precise location, even showing neighboring infrastructure.
The scale of the exposure varies, with some systems controlling individual turbines while others manage entire wind or solar farms. This means a single compromised system could potentially impact a much larger generating capacity. In some cases, exposed login pages explicitly stated default credentials, such as "root," for newer releases, further lowering the barrier to entry for attackers. The report also noted that the smaller number of exposed wind systems compared to solar systems is less comforting than it appears, as some of these wind farm systems control multiple turbines and significant power generation capacity.
Experts like Thomas Plank, CEO of Tributech, commented on the findings, suggesting that while restricting remote access from high-risk vendors is a sensible step, it doesn't address the core issue of exposed systems. He noted that most of these systems are vulnerable regardless of vendor origin, and a compromised account from a European vendor poses the same risk as one from elsewhere. Plank highlighted the reliance on numerous remote links to third parties, many of which are potential compromise points. "Once an attacker is inside, the network can’t tell a legitimate stop command from a malicious one," he stated, underscoring the need for robust command verification.
In light of the EU's NIS2 directive, which holds management bodies liable for cybersecurity measures, CIOs are urged to take proactive steps. Plank advises obtaining a comprehensive inventory of all remote connections, including who connects, from where, to which assets, and their access privileges (read-only vs. operational control). He recommends implementing individual vendor accounts with strong authentication, limiting access to specific assets and actions, and separating command rights from monitoring capabilities. Operators should also maintain their own logs of commands and configurations, independently verify data, and ensure timely incident notification.
The immediate recommendations for operators are straightforward yet critical: remove administrative interfaces from the internet without delay. Furthermore, organizations should adopt a security posture that assumes an attacker is already present, implementing continuous monitoring and planning for manual operation of sites as a fallback. These measures are essential to protect the integrity and availability of Europe's increasingly vital renewable energy infrastructure from cyber threats.