Researchers from Modat and the Dutch government’s cybersecurity center NCSC-NL identified 8,547 internet-facing systems at wind farms and solar parks across 35 countries in and around the EU. The exposed systems range from login screens to a turbine control page offering Start, Stop and Reset buttons to anyone with a browser. Solar accounts for 7,942 systems, with Spain alone holding 2,766; wind accounts for 605, led by Germany with 212 and Italy with 192. The real number is likely higher, since systems were counted only when they could be linked to a specific renewable site.

Physical decentralization gives Europe’s renewables a defensive advantage against physical attacks, but the researchers note that in cyberspace “there is no there there.” One exposed wind turbine dashboard showed live power and wind data, a Siemens ET 200SP PLC web server, and a map revealing the site’s location. Some exposed systems control several turbines or an entire farm, and two wind park login pages named their sites outright—one noting that the default username is root in all newer releases.

Lithuania already bars entities from certain national-security-risk countries from remotely controlling large renewable assets, but Tributech CEO Thomas Plank argues that restriction only addresses who connects, not what happens after. He advises operators to inventory every remote connection, require individual accounts with strong authentication, separate command rights from monitoring rights, and keep independent logs of commands and configuration changes. Under NIS2, management bodies are liable for cybersecurity oversight, including 24-hour early warning of incidents. The researchers’ first step is simpler: take admin interfaces off the internet immediately and operate as if an attacker is already inside.