Thousands of wind farms and solar parks across Europe have internet-facing systems that could expose critical energy infrastructure to cyberattacks, Dutch cybersecurity researchers have warned.
A study by internet-scanning company Modat and the Dutch National Cyber Security Center (NCSC-NL) identified 8,547 systems across 35 European countries that should not have been accessible from the public internet. The researchers presented the findings on Tuesday (October 6, 2026) at the ONE Conference in The Hague.
The exposed systems include administrative pages, login interfaces and operational panels that can display energy-production information or provide controls for renewable-energy equipment. Researchers said the discovery highlights a growing cybersecurity concern as wind and solar installations become increasingly important to Europe's electricity supply.
Of the 8,547 systems identified, 7,942 were linked to solar parks and 605 to wind farms. Spain had the most exposed solar systems, with 2,766, followed by Greece with 1,860. Germany had the most exposed wind systems, with 212, while Italy followed with 192.
The researchers stressed that the figure is a lower bound since they counted only systems they could confidently connect to specific renewable-energy facilities. Some of the systems could also control multiple turbines or an entire wind farm.
While most exposed systems were administrative or login pages, researchers estimated that around 181 sites could potentially have been fully controlled remotely. One example showed live turbine data alongside “Start,” “Stop,” and “Reset” controls, along with the turbine's location.
That does not mean the facilities have been hacked or that attackers currently control them. Instead, researchers are warning that leaving operational interfaces accessible online creates an avoidable route for potential attacks.
Also Read: Why AI Agents Need Cybersecurity Memory to Protect Enterprise Data
The findings come as European governments face increasing concerns over attacks on critical infrastructure. Researchers pointed to a December 2025 cyberattack involving 30 wind and solar sites in Poland as an example of the potential threat.
The Dutch researchers urged operators to remove administrative interfaces from the public internet and strengthen protection around operational technology. They also warned that attackers can map exposed systems quickly using similar scanning techniques. The issue has broader implications since renewable energy now forms a significant part of Europe's power mix. As more electricity generation becomes digitally connected.