Modat warns 8,547 wind and solar systems are now exposed online in Europe

Modat has released a report with the Dutch National Cyber Security Centre (NCSC-NL) that identifies 8,547 internet-facing systems left exposed at wind farms and solar parks across 35 countries in and around the European Union.

Nmap Download

The researchers say those systems shouldn’t be publicly reachable, and even that number is probably on the low side. They counted only the systems they could confidently tie to specific sites. Some of the exposed interfaces were more than simple status pages: login portals, turbine dashboards, live “Start,” “Stop” and “Reset” controls, and even a Siemens ET 200SP PLC web server. At about 181 sites, full control may have been possible.

Most of the exposure came from solar parks, with 7,942 systems across 34 countries. Spain accounted for 2,766, Greece 1,860, Italy 753 and Germany 672, which adds up to 76% of the total. Wind sites made up the other 605 exposures in 23 countries, led by Germany at 212 and Italy at 192. The affected sites ranged from 10 MW to more than 4,500 MW.

The bigger takeaway is straightforward: once a system is online, physical distance doesn’t mean much. Modat says it used machine-learning clustering to sort known and unknown device types quickly. The same remote-access problems and weak OT security keep showing up, some traffic is still unencrypted, and a December 2025 attack hit more than 30 Polish sites. EU regulatory pressure is climbing too, and Lithuania has already started restricting some remote control. If you work in energy or OT security, this report should be on your list. You can get it from Modat and NCSC-NL.

Wireshark Download