A drone view shows solar panels in Torija. Spain, April 30, 2025. REUTERS/Guillermo Martinez

Thousands of European wind and solar power systems exposed online, Dutch researchers say

· CNA · Join

Read a summary of this article on FAST.
Get bite-sized news via a new
cards interface. Give it a try.
Click here to return to FAST Tap here to return to FAST
FAST

THE HAGUE, Oct 6 : Thousands of administrative systems at wind and solar power parks in Europe are exposed to the internet, potentially giving attackers access to interfaces that can stop turbines and raising the risk of sabotage, Dutch researchers warned on Tuesday.

The exposed systems included administrative and login interfaces as well as operational interfaces showing data and controls.

However, one of the researchers, Soufian El Yadmani, from internet-scanning company Modat, told Reuters that researchers believed full control would have been possible in the case of around 181 sites.

One turbine's web page showed live data, "Start, Stop and Reset" buttons and the turbine's location, the research said. Some systems controlled several turbines or a whole farm.

CNA Games

Guess Word
Crack the word, one row at a time

Buzzword
Create words using the given letters

Mini Sudoku
Tiny puzzle, mighty brain teaser

Mini Crossword
Small grid, big challenge

Word Search
Spot as many words as you can
Show More
Show Less

"What we can map in hours, an attacker can map in hours too," the report said. The researchers urged operators to take admin interfaces off the internet immediately.

SPANISH SOLAR, GERMAN WIND MOST EXPOSED

The findings come amid concerns about Europe's critical infrastructure, which has faced suspected sabotage and cyberattacks frequently attributed by Western governments to Russia since its invasion of Ukraine in 2022. Russia denies any involvement. 

Last month, Dutch intelligence agencies, police and prosecutors warned that artificial intelligence was accelerating the threat.

El Yadmani and Bouke van Laethem of the Dutch National Cyber Security Centre presented their findings on Tuesday at the ONE Conference in The Hague.

Turbines or arrays closely linked to public infrastructure were a special concern, El Yadmani said. "If you can turn off the energy within the city or the airport, imagine that at a larger scale."

Using machine learning to sort and cluster data, the pair said they identified 8,547 internet-facing systems they could link to at specific solar parks (7,942) and wind farms (605) in 35 European countries, which should not have been exposed to the internet.

Most of the systems found were admin pages with login screens. 

Spain had the most exposed solar systems, with 2,766, followed by Greece with 1,860, they said. 

Germany has Europe's most installed solar capacity, and 672 exposed solar systems. However it had the most exposed wind systems with 212, with Italy close behind at 192. The researchers said the rankings partly reflected where they had been able to link systems to specific sites. 

The European Union Agency for Cybersecurity could not immediately comment. Authorities in Germany, Italy and Spain did not immediately respond to requests for comment.

The report listed among its sources the Polish cybersecurity team CERT Polska's analysis of a December 2025 attack on 30 wind and solar sites in Poland, an example of the potential threat.

Source: Reuters

Newsletter

Week in Review

Subscribe to our Chief Editor’s Week in Review

Our chief editor shares analysis and picks of the week's biggest news every Saturday.

Sign up for our newsletters

Get our pick of top stories and thought-provoking articles in your inbox

Subscribe here

Get the CNA app

Stay updated with notifications for breaking news and our best stories

Download here

Get WhatsApp alerts

Join our channel for the top reads for the day on your preferred chat app

Join here