The figure is a lower bound. The researchers counted a system only once they could confidently link it to a specific solar park or wind farm. Many more systems share the same characteristics but have not yet been attributed. The research counts systems, not turbines or panels: some of the systems found control several turbines or an entire wind farm.
Key findings:
- Solar: 7,942 exposed systems in 34 countries. Spain alone accounts for 2,766 (35%). Together with Greece, Italy, and Germany, the top four countries account for 76% of the total.
- Wind: 605 exposed systems in 23 countries. Germany (212) and Italy (192) together account for 67%.
- The Netherlands: 132 exposed systems in solar and nine in wind.
- What exposure looks like: the web interface of a single wind turbine showing live production data, Start, Stop, and Reset controls, and the turbine’s location on a map; and login pages that name the wind park they protect, one of them noting that the default username is “root.”
Wind farms and solar parks are Europe’s most dispersed energy assets and, physically, its hardest targets. Online, the picture is different. To identify the systems, the researchers used machine-learning clustering in Modat Magnify, which automatically groups similar systems online and surfaced device types for which no rules had been written. Attackers can use the same speed. The findings come weeks after the joint statement of September 2026 by the Dutch intelligence and security services, NCSC, NCTV, the Government CIO, the Public Prosecution Service, and the police, which warned that AI is accelerating the threat.
Renewables generated 54% of the EU’s electricity in the second quarter of 2026, according to Eurostat. Solar (42%) and wind (28%) accounted for the largest share of renewable generation.
“Physically, wind and sun are the most robust parts of our energy supply. Digitally, they are fragmented, often exposed to the internet and not always monitored. What we can map in hours, an attacker can map in hours too. You can’t defend what you can’t see, and no one can see this whole landscape alone,” said Soufian El Yadmani, founder and CEO of Modat.
What operators can do now:
- Take admin interfaces off the internet, immediately.
- Assume breach and plan and monitor as if an attacker is already inside.
- Implement secure connectivity, following the principles published for operational technology.
- Consider your operating modes, including manual operation of OT.
- Adapt standard operating procedures so they can change based on the threat level or specific trigger events.
- Build and maintain visibility of assets, architecture, and access, including everything that suppliers and service providers connect.
- Work together and exchange information across the sector, nationally and at European level, whether that is intelligence, experience, or knowledge.
The research is a collaboration between experts from two organizations based in The Hague: Modat, which continuously maps internet infrastructure, and NCSC-NL, which helps sectors and government strengthen their digital resilience. The research publishes aggregated figures per country only. Names of parks, operators, IP addresses, and locations are not made public. Affected parties are being informed through their national CERTs.