European Renewable Energy Sites Found with Thousands of Internet-Exposed Systems

Modat and the Dutch cybersecurity center NCSC-NL identified 8,547 internet-facing systems at wind farms and solar parks in 35 countries in and around the EU. The exposed devices include login pages and turbine controls with Start, Stop, and Reset functions, and some link to industrial controllers and site locations. Spain, Greece, Italy, and Germany account for most confirmed systems, while the actual total is likely higher because only devices tied to specific sites were counted.
Modat and NCSC-NL counted 8,547 reachable systems tied to wind and solar sites across 35 countries in or near the EU. Solar accounted for 7,942 entries in 34 countries; wind for 605 in 23. Spain, Greece, Italy, and Germany held most confirmed systems, and the true total may be higher because only site-linked devices were included.
Machine-learning clustering grouped similar devices and revealed types the team had not previously sought. One exposed turbine page displayed operating data, offered start, stop, and reset controls, linked to a Siemens ET 200SP PLC, and exposed its location. Lithuania restricts remote control by vendors from certain countries; an expert said such rules address access, not command validation after entry.
The exposure could affect grid operators, maintenance staff, and communities relying on renewable power if unauthorized users reach turbine or solar controls. Attackers might disrupt generation, gather site details, or misuse valid credentials, potentially straining reliability and response efforts. The findings may push operators toward stronger authentication, monitoring, and vendor oversight, though the actual societal impact depends on how quickly exposed systems are secured.