THE HAGUE — A sweeping new cybersecurity assessment has revealed that thousands of administrative and operational systems powering wind and solar energy parks across Europe are directly exposed to the public internet. The startling finding, unveiled on Tuesday by a team of Dutch researchers, exposes critical vulnerabilities that could allow unauthorized actors to remotely manipulate turbines, halt renewable energy production, and cause widespread disruptions to Europe’s vital energy grids.
The research underscores a mounting anxiety among security officials regarding the resilience of Europe’s critical infrastructure. Amid a landscape of heightened geopolitical tensions, frequent cyberespionage campaigns, and suspected state-sponsored sabotage, experts warn that the digital defense of the continent’s green transition has lagged significantly behind its rapid physical expansion.
Main Facts: The Scope of the Exposure
The comprehensive security audit was conducted by Soufian El Yadmani, a researcher from the Dutch internet-scanning firm Modat, alongside Bouke van Laethem of the Dutch National Cyber Security Centre (NCSC). Utilizing advanced machine learning techniques to aggregate, sort, and cluster vast swathes of internet-facing data, the pair identified 8,547 distinct systems linked to specific renewable energy sites across 35 European countries.
Of the thousands of exposed access points, the vast majority consisted of administrative portals, login screens, and operational interfaces designed to display live performance metrics and operational controls. While many of these sites were shielded behind rudimentary login pages, the researchers warned that a significant subset—an estimated 181 individual sites—exhibited direct vulnerabilities that could have permitted full operational control by malicious actors.
The scale of the threat was visually and technically underscored by specific interfaces discovered during the scanning process. In one instance highlighted by the researchers, a single wind turbine’s publicly accessible web page displayed real-time operational data alongside active "Start," "Stop," and "Reset" buttons, accompanied by the precise geographical coordinates of the asset. Depending on the architecture of the site, a successful compromise of such interfaces could allow an attacker to shut down individual turbines, entire wind arrays, or sprawling solar parks with the click of a button.
"What we can map in hours, an attacker can map in hours, too," the researchers emphasized in their joint report, issuing an urgent plea for energy operators to pull all administrative and operational interfaces off the public internet immediately.
Chronology: From Digital Reconnaissance to the ONE Conference Reveal
The timeline leading up to this week’s alarming disclosure reflects a growing pattern of digital reconnaissance and real-world incidents targeting the renewable energy sector:
- December 2025: A coordinated cyberattack targeted approximately 30 wind and solar installations across Poland. The incident, later analyzed and documented by the Polish cybersecurity response team CERT Polska, served as a stark real-world warning of the vulnerabilities plaguing decentralized renewable energy assets.
- Early 2026: Dutch researchers Soufian El Yadmani and Bouke van Laethem intensified their cross-border digital scanning initiative, employing machine learning to map thousands of internet-exposed operational technology (OT) and industrial control system (ICS) interfaces across Europe’s solar and wind infrastructure.
- February 2026: National security and intelligence agencies across the Netherlands issued broader warnings regarding the accelerating convergence of artificial intelligence and cyber threats, noting that bad actors are increasingly automating the discovery of digital vulnerabilities.
- Tuesday, March (Current): El Yadmani and Van Laethem officially presented their groundbreaking findings at the prestigious ONE Conference in The Hague, detailing the geographic distribution of the exposed assets and calling for immediate defensive remediations across the European Union.
Supporting Data: Geographic Distribution and Vulnerability Metrics
The research highlights a continent-wide security blind spot, heavily concentrated in nations leading Europe’s green energy transition. Out of the 8,547 exposed systems mapped by the researchers, 7,942 were linked to solar parks, while 605 were tied to wind farms operating across 35 countries.
Breakdown by Technology and Nation
While the raw numbers reflect where the researchers were most successful in correlating exposed internet protocols (IPs) with physical assets, the geographic distribution points to systemic oversight issues among localized operators and third-party vendors:
- Solar Power Exposure:
- Spain registered the highest volume of exposed solar systems in Europe, with 2,766 internet-facing interfaces identified.
- Greece followed closely behind, accounting for 1,860 exposed solar installations.
- Germany, despite boasting Europe’s largest total installed solar capacity, recorded 672 exposed solar systems.
- Wind Power Exposure:
- Germany emerged as the most vulnerable nation for wind energy assets, with 212 exposed wind systems connected to the internet.
- Italy followed closely behind Germany in the wind sector, registering 192 exposed systems.
The researchers noted that these rankings do not necessarily imply that Spanish or German firms are inherently more negligent than their European counterparts. Rather, they reflect the data sets available, digital footprints left by specific SCADA (Supervisory Control and Data Acquisition) vendors, and the precision with which public-facing metadata could be mapped to physical infrastructure.
Official Responses and Industry Silence
The revelations presented at The Hague have placed immense pressure on regulatory bodies, cybersecurity agencies, and national governments across Europe. However, the initial response from institutional authorities has been measured or noticeably delayed.
The European Union Agency for Cybersecurity (ENISA) was contacted for comment following the release of the report but was unable to provide an immediate statement. Similarly, government ministries, critical infrastructure regulators, and energy authorities in Germany, Italy, and Spain—the nations most heavily impacted by the exposed systems—did not immediately respond to formal requests for comment from international media.
Security analysts suggest this lag in official response reflects the administrative complexity of managing decentralized renewable energy assets. Unlike traditional, centralized fossil-fuel or nuclear power plants, which are typically guarded by rigorous, state-mandated physical and digital security perimeters, renewable energy grids are often composed of thousands of geographically dispersed, semi-autonomous, and remotely managed sites. Many of these parks rely on third-party maintenance contractors who frequently leave remote-management ports open to the internet to facilitate routine servicing without requiring on-site visits.
Implications: The Shadow of Sabotage and Critical Infrastructure Risk
The implications of the Modat and NCSC findings extend far beyond digital privacy or corporate data leaks; they strike at the heart of European energy security and national defense.
The Geopolitical Context
The timing of this report coincides with an intensely volatile geopolitical climate. Since the escalation of the Russia-Ukraine war in 2022, European critical infrastructure has been subjected to a relentless barrage of suspected sabotage, cyberespionage, and hybrid warfare tactics. Western governments and intelligence agencies have frequently attributed these malicious operations to Russian state-backed actors, though Moscow has consistently denied any involvement in cyber-attacks or infrastructure sabotage across Europe.
Compounding these traditional state-actor threats is the rapid evolution of technology. Just last month, Dutch intelligence agencies, police, and specialized prosecutors issued a joint warning that artificial intelligence is drastically accelerating the sophistication and speed of cyber threats. Automated tools allow threat actors to scan, identify, and exploit vulnerable industrial control systems in a fraction of the time it once took human hackers.
The Cascading Threat to Public Life
During their presentation at the ONE Conference, El Yadmani emphasized the alarming proximity between decentralized renewable assets and essential public services. When wind and solar farms are integrated into regional grids supplying power to densely populated urban centers, critical transit hubs, or international airports, the stakes multiply exponentially.
"If you can turn off the energy within the city or the airport, imagine that at a larger scale," El Yadmani warned delegates. A synchronized, multi-site cyberattack shutting down thousands of megawatts of renewable generation capacity in a matter of seconds could destabilize regional transmission networks, trigger cascading blackouts, overwhelm grid balancing mechanisms, and paralyze emergency services.
The Path Forward: Remediation and Resilience
The findings serve as a wake-up call for the European energy sector. Cybersecurity experts and government bodies agree that mitigating these risks requires immediate, mandatory action from energy operators, equipment manufacturers, and regulatory authorities.
Key recommendations issued by the researchers and cybersecurity professionals include:
- Immediate Disconnection: Taking all administrative, login, and operational management interfaces off the public internet immediately.
- Implementation of Secure Access: Requiring multi-factor authentication (MFA), encrypted Virtual Private Networks (VPNs), and zero-trust network architectures for any necessary remote-maintenance operations.
- Enhanced Asset Discovery: Deploying continuous internal and external threat-hunting tools to map shadow IT and unmanaged IoT devices across distributed green energy parks.
- Regulatory Enforcement: Establishing stricter, EU-wide cybersecurity mandates specifically tailored to decentralized renewable energy infrastructure, ensuring that operators face stringent penalties for leaving industrial control systems exposed.
As Europe accelerates its transition toward a sustainable, green-energy future, the digital fortifying of its power grids must keep pace with physical deployment. Left unaddressed, the digital vulnerabilities exposed in Spain, Germany, Greece, Italy, and beyond threaten to turn Europe’s greatest climate assets into a sprawling, easily accessible target for malicious adversaries.
