Skip to content
Modat Try Magnify
← Back to Blog
News 6 Oct 2026

Modat Research Shows More Than 8,500 Exposed Systems in Europe’s Wind and Solar Parks

Researchers mapped internet-facing control and management systems and found exposed systems across 35 countries in the EU, EFTA, and EU candidate states. Today, they presented their findings at The ONE Conference in The Hague.

Modat Research Shows More Than 8,500 Exposed Systems in Europe’s Wind and Solar Parks

THE HAGUE, 6 October 2026. Research by The Hague-based Internet Intelligence company Modat has identified 8,547 internet-facing systems in European solar parks and wind farms that should not be reachable from the internet, including exposed admin interfaces and control panels. The researchers mapped operating wind farms and solar parks in 40 countries in the EU, EFTA and EU candidate states, and found exposed systems in 35 of them. Soufian El Yadmani (Modat) and Bouke van Laethem presented the research today on the Mainstage of The ONE Conference at the World Forum in The Hague.

The figure is a lower bound. The researchers counted a system only once they could confidently link it to a specific solar park or wind farm. Many more systems share the same characteristics but have not yet been attributed. The research counts systems, not turbines or panels: some of the systems found control several turbines or an entire wind farm.

Key Findings

  • Solar: 7,942 exposed systems in 34 countries. Spain alone accounts for 2,766 (35%). Together with Greece, Italy and Germany, the top four countries account for 76% of the total.
  • Wind: 605 exposed systems in 23 countries. Germany (212) and Italy (192) together account for 67%.
  • The Netherlands: 132 exposed systems in solar and 9 in wind.
  • What exposure looks like: the web interface of a single wind turbine showing live production data, Start, Stop and Reset controls, and the turbine’s location on a map; and login pages that name the wind park they protect, one of them noting that the default username is “root”.

Physically Robust, Digitally Exposed

Wind farms and solar parks are Europe’s most dispersed energy assets and, physically, its hardest targets. Online, the picture is different. To identify the systems, the researchers used machine-learning clustering in Modat Magnify, which automatically groups similar systems online and surfaced device types for which no rules had been written. Attackers can use the same speed. The findings come weeks after the joint statement of September 2026 by the Dutch intelligence and security services, NCSC, NCTV, the Government CIO, the Public Prosecution Service and the police, which warned that AI is accelerating the threat.

Renewables generated 54% of the EU’s electricity in the second quarter of 2026, according to Eurostat. Solar (42%) and wind (28%) accounted for the largest share of renewable generation.

“Physically, wind and sun are the most robust parts of our energy supply. Digitally, they are fragmented, often exposed to the internet and not always monitored. What we can map in hours, an attacker can map in hours too. You can’t defend what you can’t see, and no one can see this whole landscape alone,” said Soufian El Yadmani, founder and CEO of Modat.

What Operators Can Do Now

  • Take admin interfaces off the internet, immediately.
  • Assume breach and plan and monitor as if an attacker is already inside.
  • Implement secure connectivity, following the principles published for operational technology.
  • Consider your operating modes, including manual operation of OT.
  • Adapt standard operating procedures so they can change based on the threat level or specific trigger events.
  • Build and maintain visibility of assets, architecture and access, including everything that suppliers and service providers connect.
  • Work together and exchange information across the sector, nationally and at European level, whether that is intelligence, experience or knowledge.

Responsible Publication

The research publishes aggregated figures per country only. Names of parks, operators, IP addresses and locations are not made public. Affected parties are being informed through their national CERTs.

The blog post and the full report are at To See the Wind and the Sun.

Intent leaves a trace.

Talk to us about your needs

Request a demo

See it on your own estate

Tell us who you are and we will come back to you personally, usually within two working days.

Loading the form…

Message received

Thank you

We have your message and someone will come back to you personally, usually within two working days.