Dutch researchers said on 6 October 2026 that they found 8,547 internet-facing control and administrative systems at solar parks and wind farms across 35 European countries, systems that should not have been reachable from the public internet.
The research comes from The Hague-based internet intelligence company Modat, working with the Netherlands’ National Cyber Security Centre (NCSC-NL). Using machine learning to sort and cluster data, the pair said they identified 8,547 internet-facing systems they could link to specific solar parks (7,942) and wind farms (605) in 35 European countries, which should not have been exposed to the internet. Researchers Soufian El Yadmani of Modat and Bouke van Laethem of NCSC-NL presented the findings at the ONE Conference in The Hague.
The count is heavily weighted toward solar. Solar accounted for 7,942 exposed systems in 34 countries, with Spain alone responsible for 2,766, or 35% of the total. Together with Greece, Italy and Germany, the top four countries accounted for 76% of the total. Spain had the most exposed solar systems, with 2,766, followed by Greece with 1,860. Germany has Europe’s most installed solar capacity, and 672 exposed solar systems.
What makes the finding more than a tally of open ports is what some of the interfaces allow. Soufian El Yadmani told Reuters that researchers believed full control would have been possible in the case of around 181 sites. One turbine’s web page showed live data, “Start, Stop and Reset” buttons and the turbine’s location; some systems controlled several turbines or a whole farm. The researchers also described login pages naming the specific site they protected, including one that stated that the default username was “root”.
The researchers stressed that their figure is a floor, not a ceiling. The figure is a lower bound: the researchers counted a system only once they could confidently link it to a specific solar park or wind farm, and many more systems share the same characteristics but have not yet been attributed. They also noted the scanning techniques they used are not exclusive to defenders. Most of the systems found were admin pages with login screens. “What we can map in hours, an attacker can map in hours too,” the report said, and the researchers urged operators to take admin interfaces off the internet immediately.
El Yadmani pointed to the grid implications of sites tied to public infrastructure. Turbines or arrays closely linked to public infrastructure were a special concern, he said: “If you can turn off the energy within the city or the airport, imagine that at a larger scale.”
At a glance
| What | Who | Scope | Scale | Date |
|---|---|---|---|---|
| Exposed admin/control systems | Modat and NCSC-NL | 35 European countries | 8,547 systems (7,942 solar, 605 wind) | Presented 6 Oct 2026 |
| Full attacker control estimated | Modat researchers | Across surveyed sites | ~181 sites | 6 Oct 2026 |
| Top exposed country, solar | Spain | National total | 2,766 systems (35%) | As of 6 Oct 2026 |
What to watch
The researchers urged operators to pull admin interfaces off the public internet immediately; whether national regulators or grid operators now mandate such fixes, rather than leaving it voluntary, will determine how fast the exposure shrinks.
Sources
- Source: To See the Wind and the Sun (Modat)
- Source: Thousands of European solar park systems exposed online, say researchers (pv magazine)
- Source: Thousands of European wind and solar power systems exposed online, Dutch researchers say (Reuters)
- Source: Internet-facing systems exposed at European wind and solar sites (Windtech International)

