By Stephanie van den Berg and Toby Sterling
THE HAGUE, Oct 6 (Reuters) – Thousands of administrative systems at wind and solar power parks in Europe are exposed to the internet, potentially giving attackers access to interfaces that can stop turbines and raising the risk of sabotage, Dutch researchers warned on Tuesday.
The exposed systems included administrative and login interfaces as well as operational interfaces showing data and controls.
However, one of the researchers, Soufian El Yadmani, from internet-scanning company Modat, told Reuters that researchers believed full control would have been possible in the case of around 181 sites.
One turbine’s web page showed live data, “Start, Stop and Reset” buttons and the turbine’s location, the research said. Some systems controlled several turbines or a whole farm.
“What we can map in hours, an attacker can map in hours too,” the report said. The researchers urged operators to take admin interfaces off the internet immediately.
SPANISH SOLAR, GERMAN WIND MOST EXPOSED
The findings come amid concerns about Europe’s critical infrastructure, which has faced suspected sabotage and cyberattacks frequently attributed by Western governments to Russia since its invasion of Ukraine in 2022. Russia denies any involvement.
Last month, Dutch intelligence agencies, police and prosecutors warned that artificial intelligence was accelerating the threat.
El Yadmani and Bouke van Laethem of the Dutch National Cyber Security Centre presented their findings on Tuesday at the ONE Conference in The Hague.
Turbines or arrays closely linked to public infrastructure were a special concern, El Yadmani said. “If you can turn off the energy within the city or the airport, imagine that at a larger scale.”
Using machine learning to sort and cluster data, the pair said they identified 8,547 internet-facing systems they could link to at specific solar parks (7,942) and wind farms (605) in 35 European countries, which should not have been exposed to the internet.
Most of the systems found were admin pages with login screens.
Spain had the most exposed solar systems, with 2,766, followed by Greece with 1,860, they said.
Germany has Europe’s most installed solar capacity, and 672 exposed solar systems. However it had the most exposed wind systems with 212, with Italy close behind at 192. The researchers said the rankings partly reflected where they had been able to link systems to specific sites.
The European Union Agency for Cybersecurity could not immediately comment. Authorities in Germany, Italy and Spain did not immediately respond to requests for comment.
The report listed among its sources the Polish cybersecurity team CERT Polska’s analysis of a December 2025 attack on 30 wind and solar sites in Poland, an example of the potential threat.
(Reporting by Stephanie van der Berg and Toby Sterling; Editing by Xevi Fontdegloria)








Comments