Dutch cybersecurity investigators have cautioned that internet-exposed systems at thousands of solar parks and wind farms throughout Europe could leave vital energy networks vulnerable to digital assaults.
An investigation conducted jointly by internet-scanning firm Modat and the Dutch National Cyber Security Center (NCSC-NL) uncovered 8,547 devices distributed across 35 nations in Europe that lacked proper isolation from the public internet. These results were made public on Tuesday, October 6, 2026, during the ONE Conference held in The Hague.
Among the vulnerable infrastructure are administrative portals, sign-in screens, and operational dashboards capable of showing power generation metrics or managing renewable energy hardware. According to the study’s authors, this vulnerability underscores escalating cybersecurity worries as photovoltaic and wind facilities assume a larger role in powering Europe.
Thousands of Renewable Energy Systems Exposed
Out of the total 8,547 discovered systems, solar installations accounted for 7,942 while wind farms comprised 605. Spain recorded the highest count of exposed photovoltaic assets at 2,766, with Greece trailing at 1,860. On the wind energy side, Germany led with 212 vulnerable units, closely followed by Italy at 192.
The investigators emphasized that this total represents a conservative estimate, as they only counted equipment they could verify as belonging to distinct renewable energy sites. Furthermore, certain interfaces possessed the capability to regulate entire wind facilities or multiple individual turbines.
Around 181 Sites Could Face Remote Control Risk
Although most exposed systems consisted primarily of login screens and administrative dashboards, the study estimated that approximately 181 locations might be susceptible to full remote manipulation. One documented instance displayed real-time turbine statistics accompanied by location data alongside “Start,” “Stop,” and “Reset” buttons.
This exposure does not imply that the installations have suffered breaches or are currently manipulated by hostile actors. Rather, the experts caution that leaving operational controls reachable via the web introduces an unnecessary pathway for prospective intrusions.
Also Read: Why AI Agents Need Cybersecurity Memory to Protect Enterprise Data
Cybersecurity Risks Grow with Renewable Expansion
These revelations emerge as European authorities grow increasingly anxious regarding security threats directed at essential infrastructure. To illustrate the real-world danger, researchers referenced a December 2025 cyber incident that impacted 30 wind and solar locations in Poland.
The Dutch team advised facility operators to disconnect management interfaces from the public web and strengthen protection around operational technology. They also cautioned that malicious actors can rapidly identify vulnerable assets utilizing comparable network scanning tools. Given that green energy currently makes up a substantial share of Europe’s electricity supply, the problem carries wide-ranging consequences as digital connectivity within power generation continues to expand.




