THE HAGUE — In an alarming finding that underscores the fragile digital underpinnings of Europe’s green transition, Dutch cybersecurity researchers revealed on Tuesday that thousands of administrative and operational systems governing wind and solar power parks across the continent are directly exposed to the open internet. The discovery lays bare critical vulnerabilities that could allow malicious actors to halt turbine operations, plunge local infrastructure into darkness, and orchestrate widespread sabotage.
The findings, presented at the prestigious ONE Conference in The Hague by Soufian El Yadmani of internet-scanning firm Modat and Bouke van Laethem of the Dutch National Cyber Security Centre (NCSC), reveal a sweeping digital blind spot. Utilizing advanced machine learning techniques to aggregate, sort, and cluster vast swathes of internet data, the researchers identified 8,547 internet-facing systems linked directly to specific solar parks (7,942) and wind farms (605) across 35 European countries.
While the majority of the exposed assets consisted of administrative login pages and operational interfaces displaying real-time telemetry, the researchers warned that a significant subset presented a far more immediate and alarming danger: direct remote control capabilities.
Main Facts: The Anatomy of the Vulnerability
The core of the issue lies in poor cyber-hygiene among renewable energy operators, many of whom have integrated operational technology (OT) systems with corporate networks or directly onto the public internet for ease of remote maintenance. This practice has inadvertently thrown open the doors to external threat actors.
According to the research, the exposed infrastructure encompassed a dangerous mix of administrative portals and operational dashboards. While many were protected by basic login screens—which remain vulnerable to brute-force attacks, credential stuffing, and exploiting default manufacturer passwords—others lacked even basic authentication barriers.
Most critically, El Yadmani told Reuters that researchers found approximately 181 sites where they believed full, active operational control could have been achieved. In one particularly striking example highlighted in the report, a single wind turbine’s public-facing web page displayed live performance metrics alongside functional "Start," "Stop," and "Reset" buttons, accompanied by the exact geographic coordinates of the asset. In other instances, a single compromised interface provided oversight over multiple turbines or an entire sprawling solar farm.
"What we can map in hours, an attacker can map in hours, too," the report explicitly warned, emphasizing the symmetry between security research methodologies and advanced persistent threat (APT) reconnaissance. The researchers issued an urgent, unequivocal plea to operators across the continent: take administrative and operational interfaces off the public internet immediately.
The geographic footprint of the exposure spans 35 nations, with Southern and Central Europe registering the highest concentrations of vulnerable solar and wind assets. Spain and Greece emerged as the most exposed nations for solar energy infrastructure, while Germany and Italy topped the list for wind farm vulnerabilities.
Chronology: From Digital Reconnaissance to the Hague Disclosure
The timeline leading up to the shocking disclosures at the ONE Conference highlights a rapidly escalating awareness—and exploitation—of operational technology (OT) vulnerabilities within Europe’s energy grids.
- December 2025: The digital threat transitioned from theoretical risk to hard reality in Poland. According to sources cited in the Dutch researchers’ report, the Polish cybersecurity incident response team, CERT Polska, analyzed a targeted cyberattack that successfully compromised 30 wind and solar sites across the country. This incident served as a stark harbinger of how adversaries could weaponize exposed renewable assets.
- Early 2026: Researchers Soufian El Yadmani and Bouke van Laethem began leveraging machine learning models to parse massive internet-scanning databases. Their goal was to map the digital perimeter of Europe’s renewable energy sector, correlating IP addresses, domain names, and metadata with physical solar parks and wind farms.
- February 2026: Dutch intelligence agencies, national police, and public prosecutors issued a joint warning highlighting how the rapid advancement and deployment of artificial intelligence by malicious actors was drastically accelerating the threat landscape for critical infrastructure.
- Tuesday, March 2026: El Yadmani and Van Laethem took the stage at the ONE Conference in The Hague. In a heavily attended presentation, they formally unveiled their findings, detailing the 8,547 exposed systems across 35 countries and sounding the alarm on the imminent danger of remote sabotage.
Supporting Data: Mapping the Exposure Across Europe
The quantitative scope of the research provides a sobering look at how deeply interconnected—and exposed—Europe’s green energy grid currently is. Through automated data clustering, the researchers mapped vulnerabilities across two primary domains: photovoltaic (solar) parks and wind energy installations.
The Solar Sector Breakdown
Solar energy infrastructure accounted for the vast majority of the exposed systems, totaling 7,942 individual entries. The distribution heavily favored nations with high installed photovoltaic capacities in Southern and Southeastern Europe:
- Spain: 2,766 exposed solar systems (the highest in Europe).
- Greece: 1,860 exposed solar systems.
- Germany: 672 exposed solar systems, despite holding the continent’s largest total installed solar capacity.
The Wind Sector Breakdown
Wind energy parks, which often feature heavier, more centralized mechanical infrastructure connected to high-voltage transmission lines, yielded 605 exposed systems. The highest concentrations were found in economic powerhouses:
- Germany: 212 exposed wind systems (the highest in Europe).
- Italy: 192 exposed wind systems.
The researchers noted that these rankings are partially reflective of their methodology—specifically, the geographic regions where data enrichment allowed them to definitively link an exposed IP address or administrative portal to a precise, physical power generation site. Consequently, the true number of exposed systems across the entirety of Europe could be significantly higher.
Official Responses: Silence and Scrutiny
As the implications of the report reverberate through diplomatic and regulatory channels, the response from official bodies and national governments has been measured, marked in many cases by an initial silence as agencies scramble to verify the claims.
The European Union Agency for Cybersecurity (ENISA), the bloc’s premier cybersecurity watchdog, was unable to provide immediate comments when approached by journalists following the disclosure. ENISA has historically struggled with enforcing uniform cybersecurity mandates across member states, relying heavily on advisory guidelines such as the revised Network and Information Security (NIS2) Directive.
National authorities in the countries most heavily impacted by the findings—specifically Germany, Italy, and Spain—did not immediately respond to requests for comment from international news agencies. The lack of immediate public statements from national ministries of energy and cybersecurity agencies has fueled concerns regarding bureaucratic delays in addressing industrial control system (ICS) vulnerabilities.
However, the warnings delivered by the Dutch National Cyber Security Centre (NCSC) alongside Modat carry immense institutional weight. By having an active government cybersecurity researcher co-presenting the findings, the Netherlands has effectively forced the issue onto the European agenda, compelling national regulators to initiate emergency sweeps of their respective critical infrastructure assets.
Implications: The Looming Specter of Infrastructure Sabotage
The timing of the Dutch researchers’ warning could not be more critical. The findings arrive against a tense geopolitical backdrop characterized by acute anxiety over the security of Europe’s critical national infrastructure (CNI).
Since the escalation of the Russia-Ukraine war in February 2022, Western governments and intelligence services have frequently attributed a surge in suspected sabotage attempts, reconnaissance operations, and sophisticated cyberattacks against European utilities, transport networks, and communication lines to Russian state-sponsored actors. Moscow has consistently denied any involvement in these incidents, characterizing such accusations as politically motivated rhetoric.
Nevertheless, the shift toward decentralized energy generation—while crucial for meeting European climate targets and phasing out fossil fuels—has vastly expanded the "attack surface" of the power grid. Traditional energy grids relied on a small number of heavily guarded, centralized coal, gas, or nuclear power plants. Today, the European grid comprises hundreds of thousands of distributed renewable assets, many of which are managed by third-party vendors, local contractors, or automated software platforms with substandard cybersecurity protocols.
El Yadmani emphasized the catastrophic potential of cascading failures during his presentation at the ONE Conference. "If you can turn off the energy within the city or the airport, imagine that at a larger scale," he warned.
The ramifications of a coordinated, multi-site cyberattack against thousands of wind turbines and solar parks are profound:
- Grid Instability and Blackouts: Modern electrical grids require a delicate, real-time balance between power generation and electricity consumption. If a malicious actor were to simultaneously shut down thousands of megawatts of wind and solar generation across multiple European nations, it could trigger sudden frequency drops, overloading remaining transmission lines and risking widespread, cascading blackouts.
- Physical Destruction: Unauthorized manipulation of wind turbine operational parameters—such as disabling braking systems during high wind speeds or overriding pitch-control mechanisms—can cause catastrophic mechanical failure, structural collapse, and irreversible physical damage worth millions of euros per turbine.
- Economic Disruption: Industrial operations, transportation hubs, hospitals, and financial institutions rely uninterruptedly on stable power supplies. A prolonged, cyber-induced energy shortage would paralyze economic output and severely test public trust in the resilience of green infrastructure.
The Path Forward
The revelations in The Hague serve as a wake-up call for energy ministries, utility providers, and regulatory bodies across the European Union. The traditional cybersecurity paradigm—which treated operational technology (OT) as inherently secure simply because it was isolated from the office environment—is obsolete.
As the NIS2 Directive and other European cybersecurity frameworks begin to take stricter effect, operators of wind and solar parks will face mounting legal and financial pressures to secure their digital perimeters. Immediate remediation measures must include:
- Immediate Disconnection: Removing all administrative, diagnostic, and operational interfaces from the public internet.
- Implementation of Zero-Trust Architecture: Mandating secure, encrypted Virtual Private Networks (VPNs) and multi-factor authentication (MFA) for any necessary remote engineering access.
- Continuous External Scanning: Conducting rigorous, automated vulnerability assessments to catch misconfigured assets before malicious threat actors can map them.
Until these measures are universally adopted, Europe’s green energy transition remains precariously balanced between a sustainable future and an exposed, digitized vulnerability waiting to be exploited.
