On October 6, at The ONE Conference in The Hague — the Dutch national cybersecurity conference — researchers from Modat, a Hague-based internet intelligence company, presented a map of Europe's renewable energy management plane. The finding: 8,547 systems in wind farms and solar parks that are reachable from the public internet and should not be. Admin interfaces. Control panels. Not telemetry scraped from a marketing site — the interfaces operators use to run the plant.
Soufian El Yadmani and Bouke van Laethem mapped operating wind and solar infrastructure across 40 countries in the EU, EFTA, and EU candidate states. They found exposed systems in 35 of them. heise picked it up this week, which is how the story reached most of the people who will read this post.
The numbers, and what the interfaces show¶
Solar: 7,942 exposed systems across 34 countries. Spain alone accounts for 2,766 — 35% of the total. Greece (1,860), Italy (753), and Germany (672) follow; the top four countries hold 76% of the exposed solar systems.
Wind: 605 exposed systems across 23 countries. Germany (212) and Italy (192) together account for 67%.
The Netherlands: 132 solar systems and 9 wind systems, which matters here because the presentation happened on Dutch soil, weeks after a September 2026 joint statement by the Dutch intelligence and security services, NCSC, NCTV, the Government CIO, the Public Prosecution Service, and the police warning that AI is accelerating the threat to exactly this kind of infrastructure.
What the exposed interfaces actually show, per the researchers: a single wind turbine's web interface with live production data, Start, Stop, and Reset controls, and the turbine's location on a map. Login pages that name the wind park they protect — a free reconnaissance gift to anyone enumerating targets. One page helpfully notes that the default username is root.
Context on scale, from figures Modat cites via Eurostat: renewables generated 54% of the EU's electricity in Q2 2026. This is not a marginal niche of the grid.
Two numbers deserve scrutiny before the panic sets in¶
8,547 is a floor, not a ceiling. The researchers counted a system only when they could confidently link it to a specific solar park or wind farm. Systems with the same characteristics that resisted attribution were left out. And they counted systems, not turbines or panels — one exposed system can control several turbines or a whole park. So the real number is higher, and the per-system blast radius varies widely. That is the honest structure of the claim: verified lower bound, unbounded upside.
No exploitation has been observed. Modat's writeup does not claim attackers are running turbines. The guidance ("assume breach") is posture advice, not an incident report. And on the adjacent vendor-cloud story, the discipline cuts both ways: in August, Jakkaru's managing director disclosed an admin-access weakness in the cloud system managing Sungrow inverters and called it a blackout risk — attackers could theoretically deactivate all inverters simultaneously. Sungrow disputed that, saying the extra password check for critical settings could not be bypassed; Germany's BSI reviewed it, saw no exploitation indicators, and took no further action after the vendor shipped a hotfix. This site has documented why vendor clouds recur in this kind of story — it has also learned to distrust the scariest headline in a security story, including the ones security companies publish about their own research. "8,547 exposed, verified, lower bound" survives scrutiny. "Gigawatts can be blacked out from one console" was contested by the people who run the cloud and cleared by the national regulator. Report both; believe neither until the dust settles.
This is the router story, one layer up¶
A month ago this site covered MikroTrick — a MikroTik exploit chain giving unauthenticated full control of 122,500+ routers with SSH exposed to the internet. The argument there was that community broadband networks run commodity routers at the edge and rarely write the firewall rules as if the management plane were the crown jewel. The renewable-energy finding is the same argument for a different constituency: the management plane of a generation asset is reachable from the internet, because somebody port-forwarded it to make the integrator's site visit easier and never closed it.
Modat found these systems fast. Their method was machine-learning clustering — automatically grouping similar systems online, which surfaced device types they had written no detection rules for. Whatever you think of that technology, the operational fact is symmetrical and the researchers state it plainly: what an analyst maps in hours, an attacker maps in hours too. The recon is now commoditized in both directions.
And the interfaces leak intent even when they leak nothing else. A login page that names your wind park, exposes your turbine layout on a map, and advertises its default username has done the attacker's targeting for them. The exposure is not just the control; it is the inventory.
The co-op angle: you own the panels, not the admin plane¶
A lot of this infrastructure is community-owned. Energy cooperatives — a model this site has covered in broadband, where the procurement is the hard part — own generation assets across Europe, and the co-op structure is spreading: members finance the solar park, the co-op holds the asset, the community sees the returns. The members who voted for the project would be startled to learn that the plant's Start button is a web page on the public internet, or that its admin plane is a vendor's multi-tenant cloud.
Here the pattern this site keeps documenting repeats exactly. The demand goes to the rented layer — the one component of your stack you do not own is the one legal process, a breach, or a supplier's negligence reaches first. For the No Gods No Masters collective, that layer was Cloudflare. For A/I, it was the payment processor and the registry. For an energy co-op, it is the monitoring portal and the vendor cloud that administrates the inverter fleet — often the single piece of the system the co-op did not pay to own, because it came bundled with the hardware "for free."
A vendor cloud also concentrates a failure mode no firewall rule at the co-op can mitigate: one admin plane, thousands of customers' plants. The Sungrow episode is the shape of it. Even the disputed version of that story has a useful residue: it established that the question — what happens if the vendor cloud administering a continent's inverters is breached or compelled — is now a legitimate regulatory and procurement question rather than a hypothetical. The blackout headline needed verifying; the architecture question underneath it did not.
What the researchers are telling operators¶
Modat's recommendations to exposed operators, lightly compressed:
- Take admin interfaces off the internet, immediately.
- Assume breach; plan and monitor as if an attacker is already inside.
- Implement secure connectivity following the published OT security principles.
- Consider operating modes, including manual operation of OT.
- Adapt standard operating procedures so they can change with threat level.
- Build visibility of assets, architecture, and access — including everything suppliers and service providers connect.
- Share information across the sector, nationally and at EU level.
One more thing deserves attention because it is unusual: Modat has invited every operator to ask whether their own systems are in the findings — "every operator who asks will get an answer." The publication itself is aggregated-only (country counts, no parks, IPs, or locations), with affected parties notified through national CERTs. That is the responsible-disclosure shape this site wishes were more common in research: verifiable aggregate, actionable private channel, open door for the people who own the assets.
What this means for the community energy co-op¶
Six items, in the order a board should take them:
1. Inventory the management plane first. Every portal, vendor cloud account, mobile app, integrator credential, and forgotten port-forward that can reach a control function of the plant. Include the "free" monitoring app that came with the inverters — it is a management interface with a marketing budget. You cannot defend what you cannot see; neither can your members subsidize a breach of what nobody wrote down.
2. Get control functions off the public internet. Admin interfaces belong behind a VPN, allowlists, or a jump host — the same rules you would apply to a Proxmox or a firewall GUI. If the plant's only interface is the vendor cloud, it is rented infrastructure with a shared tenant plane; the mitigation is not paranoia but specificity: which jurisdictions hold the data, who at the vendor can access it, what logging exists, what happens on legal demand. Get answers in writing. If they are unavailable, that is procurement signal, not a footnote.
3. Use the open door. Ask Modat whether your systems are in the findings. It costs an email. A board that can tell its members "we asked, and here is the answer" is doing exactly the accountability the co-op structure promises.
4. Monitor the management plane like it is the crown jewel, because it is. Log administrative actions. Alert on Start/Stop/Reset commands. Assume breach means treating a stranger's session on your plant's admin interface as an incident, not a curiosity.
5. Make the management plane a procurement line item. For the next plant, inverter, or monitoring contract: who hosts the management plane, in what jurisdiction, over what protocol, with what data export path for your production data. OT security principles exist as a reference you can cite in tender documents. The Data Act already obliges vendors to hand your data back in machine-readable form — exit is now an architecture requirement; use the leverage while the contract is unsigned, not after.
6. Keep a manual path. A plant that can only be operated through somebody's cloud is a plant that does nothing during an internet outage, a vendor bankruptcy, or a vendor-compromise scare. Manual operation of OT is on Modat's list; it should be on your drill schedule. The physical plant was built to outlast its vendors. The management plane should be built the same way.
The quiet part¶
Europe's renewables rollout succeeded because it was cheap, fast, and distributed. The same distributedness made the management plane nobody's job: each site small, each integrator busy, each admin interface "temporary." Ten thousand temporary openings later, a Hague startup with a clustering algorithm catalogued them between breakfast and lunch — and says so plainly, so nobody has to pretend otherwise.
No appliance is being recommended here, because none is needed. The fix is configuration discipline and procurement language, both free: close the port forward, put the management plane behind your own infrastructure, and write the contract so the next plant ships without its Start button bolted to someone else's cloud. Community infrastructure won the argument for owning generation. The management plane is where that argument continues.