Dutch researchers say anyone with a web browser could reach thousands of control systems at Europe's solar parks and wind farms. At one wind turbine, the open page showed live output, a map pin and buttons labeled Start, Stop and Reset.
The count is 8,547 systems across 35 countries. Modat, an internet intelligence company in The Hague, did the work with the Netherlands' National Cyber Security Centre (NCSC-NL) and presented it on October 6. Solar accounts for 7,942 of those systems and wind for 605. Spain alone has 2,766 exposed solar systems, about 35% of the solar total, and Greece is second.
Most are login pages, but some are worse
Most of what the team found were admin login screens. Some of those pages gave away the default username, which was simply "root". Others went further and controlled single turbines, groups of turbines or an entire farm. The researchers say 8,547 is a floor, because they only counted a system when they could tie it to a specific site.
They stress that these are exposures, not confirmed break-ins. Still, El Yadmani told Reuters the team believed full control would have been possible at around 181 sites, and he worried most about sites tied to public infrastructure. "If you can turn off the energy within the city or the airport, imagine that at a larger scale," he said. The report's own warning is blunter: "what we can map in hours, an attacker can map in hours too".
This has already happened elsewhere. pv magazine notes that attacks on Poland's energy sector in December 2025 hit more than 30 wind and solar farms through firewalls that had no multi-factor login and through default passwords. Officials have been slower to speak. Reuters reported that the EU's cybersecurity agency, ENISA, could not immediately comment, and that authorities in Germany, Italy and Spain did not immediately respond.
What this means for your rooftop
The report covers utility-scale parks and farms, and it says nothing about residential systems. Home gear has its own exposure problem, though. pv magazine points to a 2025 Forescout study that found roughly 35,000 solar devices reachable online, 76% of them in Europe.
The researchers' advice to operators also works for homeowners: keep admin pages off the open internet, lock down remote access and replace default credentials. If you have an inverter or battery app, change the factory password, turn on two-factor login if it's offered, and install updates.
Modat says it has warned the affected operators through national cyber emergency teams. The next thing to watch is whether Modat or the NCSC publishes a follow-up count showing how many of these 8,547 systems have since come off the open internet.
Sources
- 1.Thousands of European solar park systems exposed online, say researchers · pv magazine
- 2.To See the Wind and the Sun: Thousands of Exposed Systems in Europe's Wind Farms and Solar Parks · Modat
- 4.How solar and wind farms can be turned on and off by anyone · The Hague Newsroom
- 5.Modat And The Dutch National Cyber Security Centre Identify Over 8,500 Exposed Online Systems In European Wind And Solar Parks · Ocean News & Technology
- 6.Thousands of European Wind, Solar Power Systems Exposed Online: Dutch Researchers · Insurance Journal (Reuters)
Reported by the WattsUpNext desk from the sources linked below. Spot an error? Tell us at corrections@wattsupnext.com.
The WattsUpNext Brief
Get stories like this in your inbox.
One email each weekday, only the topics you choose. Real news, sourced, no fluff. Unsubscribe in one click.




