Wind and solar parks: 8,547 systems exposed across Europe

Wind and solar parks: 8,547 systems exposed across Europe

Researchers at Modat and NCSC-NL, the Dutch government's cybersecurity center, have counted 8,547 systems at wind farms and solar parks that can be reached from the internet even though they should not be. The systems are spread across 35 countries in and around the EU. They range from simple login pages to a turbine control panel with a Stop button that anyone with a browser can press.

Most of the confirmed systems belong to operators in Spain, Greece, Italy and Germany. The researchers say the real figure is higher, because a system only made the list once it could be tied to a specific solar or wind site.

Hard to hit physically, easy to reach online

The report points out that scattered renewable generation has one security benefit. Thousands of solar parks and wind farms across the continent are a poor target for bombs, drones or saboteurs, and the International Energy Agency has linked Ukraine's shift toward decentralized power to energy security. That advantage does not carry over to the network. "Physically, decentralised renewable energy is a very hard target. But in cyberspace, there is no there there," the authors wrote.

One dashboard, one turbine

Modat found the devices with machine-learning clustering, which automatically groups systems that look alike. New device types surface without anyone first writing a detection rule, and some of the equipment it found was not on the team's list.

One wind turbine shows what this looks like in practice. Its web dashboard displays live power output, wind speed and rotor data, and its control panel offers Start, Stop and Reset. One menu item further is the web server of the Siemens ET 200SP PLC, the industrial controller that runs the turbine. A map page reveals the turbine's location, and aerial imagery of the spot shows the neighboring turbine, service buildings and the access road.

That page runs a single machine. Other systems in the data set control several turbines or an entire farm, so one exposed entry can represent far more capacity. Two wind park login pages named their sites outright, and one noted that the default username in all newer releases is root.

Spain leads on solar, Germany on wind

Solar accounts for 7,942 systems in 34 countries. Spain has 2,766 of them, or 35 percent. Together with Greece (1,860), Italy (753) and Germany (672), these four countries hold 76 percent of the solar total.

Wind accounts for 605 systems in 23 countries, with Germany (212) and Italy (192) making up 67 percent. Spain has only 11. The smaller wind number is not much comfort: the farms in scope range from 10 megawatts to more than 4,500, and some exposed systems control multiple turbines.

Who connects, and what they can do

Lithuania bars entities from countries it considers national security threats, including China, from remotely controlling solar parks, wind farms and storage above 100 kW. Thomas Plank, CEO of Tributech, told Help Net Security that this is reasonable but "addresses who connects, not what happens once they do." Most of the exposed systems are reachable regardless of the vendor's home country, he said, and a stolen maintenance account at a European vendor gives an attacker the same access.

Plank said parks now depend on dozens of remote links to outside parties, some of which will be compromised. Every command to a turbine or inverter should be checked for who sent it, whether that sender is authorized for that asset and action, and whether it arrived unchanged.

NIS2, the EU's cybersecurity directive, makes management bodies of essential and important entities approve, oversee and answer for security measures, even when operations are outsourced. Plank's advice to CIOs starts with a full list of remote connections. From there he recommends individual vendor accounts with strong authentication, access limited to specific assets and actions, monitoring rights separated from command rights, the operator's own log of every change, and incident notice in time for NIS2's 24-hour early warning.

The authors' first step is shorter: take admin interfaces off the internet now, plan as if an attacker is already inside, and keep the option of running sites by hand.

Our Take

The striking part of this research is not a clever exploit but how basic the exposure is. A Stop button on a public web page and a default root account suggest that many operators have not yet done the simple work of taking control interfaces offline. That fits a wider pattern in operational technology, where legacy equipment still limits visibility into what is connected.

Plank's point about vendor access also deserves attention. Rules based on a vendor's origin, like Lithuania's, may help, but they do nothing about stolen credentials. In the US, there are similar calls for a binding OT security directive. It is worth watching whether European regulators use NIS2 liability to push operators to act on reports like this one.