On October 6, 2026, internet intelligence researchers from The Hague-based company Modat and the Dutch National Cyber Security Centre (NCSC-NL) revealed that 8,547 internet-facing systems at European solar parks and wind farms are directly accessible from the public internet, exposing critical administrative interfaces and operational controls to potential saboteurs.
The Scale of Exposure Across 35 European Countries
The research, presented at the ONE Conference in The Hague by Modat’s Soufian El Yadmani and Bouke van Laethem of NCSC-NL, mapped operating wind farms and solar parks across 40 countries, including the European Union, European Free Trade Association (EFTA), and candidate states. They discovered vulnerable infrastructure in 35 of those nations. Out of the total 8,547 exposed systems, 7,942 were linked to solar sites spread across 34 countries, while 605 involved wind farms in 23 countries.
Spain emerged with the highest total of exposed solar assets, accounting for 2,766 systems or roughly 35% of the global count. Greece followed with 1,860 exposed solar systems. Wind farm vulnerabilities leaned heavily toward Germany, which recorded 212 exposed systems, closely followed by Italy with 192. Together, Germany and Italy represented 67% of the total exposed wind assets. In the Netherlands, researchers identified 132 exposed solar systems and nine at wind installations.
According to reuters.com reporting, Spain, Greece, Italy, and Germany combined accounted for 76% of all exposed solar systems. While Germany holds Europe’s most installed solar capacity and recorded 672 exposed solar systems, it simultaneously led the continent in vulnerable wind infrastructure.
Machine-Learning Clustering and Operational Risks
The discovery was made possible using advanced machine-learning clustering capabilities inside Modat Magnify. The software automatically groups similar systems found online, successfully identifying device types that lacked any previously developed detection rules. “What we can map in hours, an attacker can map in hours too,” the research report warned, as noted by reuters.com.
The exposed architecture extends far beyond passive diagnostic pages. Researchers encountered operational web interfaces for wind turbines showing live production data alongside active “Start, Stop and Reset” buttons, complete with precise geographic locations displayed on a map. Other login pages explicitly identified the specific wind park they protected, with one interface even noting that the default administrative username was set to “root”.
While the majority of the discovered assets were administrative login pages, El Yadmani stated to reuters.com that researchers believe full, direct control would have been technically possible at approximately 181 sites. Some individual interfaces controlled multiple turbines or entire power generation farms.
Context of Critical Infrastructure Vulnerability
The findings arrive amid heightened anxieties surrounding European critical infrastructure security. Western governments have frequently attributed suspected sabotage and cyberattacks against European utilities to Russia since its 2022 invasion of Ukraine—though Russia consistently denies any involvement. Just last month, Dutch intelligence agencies, police, and prosecutors issued public warnings that artificial intelligence is actively accelerating cyber threats.

Highlighting the severity of these exposures, the Modat and NCSC-NL report explicitly cited prior incidents, including an analysis by Polish cybersecurity team CERT Polska regarding a December 2025 attack that targeted 30 wind and solar sites in Poland.
Turbines and arrays closely tied to public infrastructure draw particular alarm from security analysts. “If you can turn off the energy within the city or the airport, imagine that at a larger scale,” El Yadmani cautioned during his presentation at the ONE Conference, as reported by reuters.com.
Mitigation Steps and Remediation Actions
The researchers have urged operators to immediately disconnect all administrative interfaces from the public internet. Network administrators are advised to operate under the assumption that an adversarial actor may have already gained unauthorized access.
Recommended countermeasures include transitioning to secure connectivity models grounded in established operational technology (OT) principles, evaluating manual operating modes, and establishing flexible operating procedures capable of adapting to varying threat levels. Operators are also tasked with maintaining a comprehensive inventory of physical assets, underlying network architectures, and access privileges—including third-party connections provided by suppliers and service providers.
To prevent future systemic failures, researchers emphasize the necessity of cross-sector information sharing between operators, national authorities, and European-level organizations. While aggregated figures have been published by country, the researchers have withheld specific park names, operator identities, IP addresses, and exact geographic coordinates. Affected parties are currently being notified through their respective national computer emergency response teams (CERTs).