8,500 European Renewable Energy Control Systems Reachable from the Open Internet

Green Energy News
08.10.2026

Researchers have found 8,547 industrial control systems managing solar and wind installations across Europe exposed and accessible on the public internet — where they have no business being. The joint investigation by security firm Modat and the Netherlands National Cybersecurity Centre identified the affected interfaces, many protected by nothing more than a basic login page.

Solar installations account for the vast majority of the exposure: 7,942 of the 8,547 systems. Spain tops the geographic breakdown with 2,766 objects — 35 percent of the European total — followed by Greece at 1,860, Italy at 753, and Germany at 672.

The danger is not hypothetical. In December 2025, at least 30 Polish wind and solar farms were attacked through open firewalls that lacked multi-factor authentication; CERT Polska attributed those incidents to a group linked to Russia’s FSB.

Researchers grouped the critical risks into three categories: exposed controller web servers that could allow attackers to remotely halt or reset equipment; control panels reachable through default credentials — including at least one documented case of a default “root” login — and AI-assisted tools capable of automatically scanning microinverters for vulnerabilities, enabling attacks to scale fast.

Experts stress that adversaries can map vulnerable networks just as quickly as the researchers themselves did. Operators are urged to isolate administrative panels from the public internet without delay.

Source: PV Magazine

Partners material

Become a member of 100 RE UA

Switching to 100% renewable energy in Ukraine is possible!