A joint investigation has found 8,547 internet-facing systems at wind farms and solar parks scattered across 35 countries in and around the EU, every one of them reachable when it should not be. The study came from Modat and NCSC-NL, the cybersecurity center of the Dutch government.
Exposure runs the whole scale: some systems show nothing but a login screen, while others expose a turbine’s control interface with a Stop button available to any visitor in a browser. Most of the confirmed systems belong to operators in Spain, Greece, Italy and Germany.
A single turbine shows what that exposure means. A control panel offering Start, Stop and Reset sits beside a dashboard that streams live power, wind speed and rotor readings. A menu item reaches the Siemens ET 200SP PLC running the machine, and a map page exposes the site, with aerial photos revealing the turbine next to it, the service buildings and the access road.
Some of the others sit one level up and command several turbines or an entire farm, which means a single reachable console can account for far more generating capacity than one machine. A pair of wind park login pages identified their facilities by name, and one disclosed that newer releases ship with the default username root.
Solar makes up 7,942 of the systems across 34 countries, with Spain alone holding 2,766, or 35 percent. Wind contributes a further 605 systems in 23 countries, a total dominated by Germany and Italy.
The researchers used machine-learning clustering, which surfaced device types they had not known to look for. Their advice is blunt: pull admin interfaces off the internet, keep the option of running sites by hand, and plan as if an attacker is already inside.
