Thousands of renewable control panels left vulnerable to cyber attacks

Staff
By Staff
2 Min Read

Could Europe’s solar parks and windfarms be easily hacked? A new report reveals significant vulnerabilities.

Research by Modat and the Dutch National Cyber Security centre has identified 8,547 internet-facing systems in European solar parks and wind farms that should not be reachable from the internet, including exposed admin interfaces and control panels.

Digitally, they’re openly accessible to attackers and include live production data, ‘start’, ‘stop’ and ‘reset’ controls, the turbine’s location on a map and login pages that name the wind park they protect.

Soufian El Yadmani, founder and CEO of Modat said “Physically, wind and sun are the most robust parts of our energy supply. Digitally, they are fragmented, often exposed to the internet and not always monitored. What we can map in hours, an attacker can map in hours too. You can’t defend what you can’t see, and no one can see this whole landscape alone.”

The companies are urging operators to take admin interfaces off the internet with immediate effect, assume systems are under attack and implement secure connectivity.

Fergal Concannon, Manager at Druid Software, said: “Operators need to know what devices are connected, how they authenticated, what they are permitted to communicate with and what happened during an incident. Resilience also means ensuring critical local operations do not simply become blind if central connectivity is disrupted. Regulation is driving the right conversation, but ultimately utilities need security controls they can prove are working in practice.”

Some exposed systems control several turbines or an entire wind farm, putting large amounts of power generation at risk, especially considering the breadth of control available online.

Copyright © 2026 Energy Live News LtdELN

Share This Article
Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *