Research reveals cybersecurity risks across europe’s energy parks | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Research by The Hague-based internet intelligence company Modat, conducted with Bouke van Laethem, has identified 8,547 internet-facing systems in European solar parks and wind farms that should not be publicly accessible, including exposed administrative interfaces and control panels.

As detailed in the report To See the Wind and the Sun, researchers mapped operating wind farms and solar parks in 40 countries in the EU, the European Free Trade Association (EFTA), and EU candidate states, and found exposed systems in 35 of them.

Soufian El Yadmani (Modat) and Bouke van Laethem (NCSC-NL) presented the research at the Mainstage of The ONE Conference at the World Forum in The Hague. Van Laethem is employed by the Dutch National Cyber Security Centre but contributed to the research outside of this capacity. The NCSC was not formally involved in the project.

According to researchers, the figure is a lower bound. The researchers counted a system only once they could confidently link it to a specific solar park or wind farm. More systems share the same characteristics but have yet to be attributed.

Crucially, the research counts systems, not turbines or panels. According to the research, some of the systems could control several turbines or an entire wind farm.

As a result, the findings have shown 7,942 exposed solar systems in 34 countries, with Spain alone accounting for 2,766 (35%). Together with Greece, Italy, and Germany, the top four countries account for 76% of the total.

Alongside solar, the research has uncovered that there were 605 exposed wind systems in 23 countries, with Germany (212) and Italy (192) accounting for 67%. In the Netherlands, the research uncovered 132 exposed systems in solar and 9 in wind.

The web interface of a single wind turbine showing live production data, Start, Stop, and Reset controls, alongside the turbine’s location on a map and login pages that name the wind park they protect. One of these noted that the default username is “root”.

This is particularly worrying as renewables generated 54% of the EU’s electricity in the second quarter of 2026, according to Eurostat. Solar (42%) and wind (28%) accounted for the largest share of renewable generation.

Physically Robust, Digitally Exposed

Founder and CEO at Modat, Sooufian El Yadmanu, said that physically robust, digitally exposed Wind farms and solar parks are Europe’s most dispersed energy assets and, physically, its hardest targets. However, online, the picture is different.

“Digitally, they are fragmented, often exposed to the internet and not always monitored. What we can map in hours, an attacker can map in hours too. You can’t defend what you can’t see, and no one can see this whole landscape alone,” said Soufian El Yadmani, founder and CEO of Modat.

To identify the systems, the researchers used machine-learning clustering in Modat Magnify, which automatically groups similar systems online and surfaced device types for which no rules had been written. Attackers can use the same speed.

The findings come weeks after the joint statement of September 2026 by the Dutch intelligence and security services, NCSC, National Coordinator for Security and Counterterrorism (NCTV), the Government CIO, the Public Prosecution Service and the police, which warned that AI is accelerating the threat.

What Infrastructure Operators Can Do Now

• Take admin interfaces off the internet immediately.
• Assume breach and plan and monitor as if an attacker is inside.
• Implement secure connectivity, following the principles published for operational technology.
• Consider operating modes, including manual operation of OT.
• Adapt standard operating procedures so they can adapt based on the threat level or trigger events.
• Build and maintain visibility of assets, architecture, and access, including what suppliers and service providers connect.
• Work together and exchange intelligence, experience, or knowledge across the sector nationally, and at European level.

The research has been published using aggregated country-level figures, without identifying individual wind farms, solar parks or their operators. IP addresses and precise locations have also been withheld from public disclosure. According to the researchers, affected parties are being informed through their national computer emergency response teams (CERTs).

Where France’s technology leaders turn strategy into impact.

Join decision-makers, experts and technology leaders for high-value conferences, real-world use cases, and peer exchange across AI, cloud, cybersecurity, DevOps, data, and data centres.



——————————————————-


Click Here For The Original Source.