Research by The Hague-based internet intelligence company Modat and the Dutch National Cyber Security Centre (NCSC-NL) has identified 8,547 internet-facing systems at European solar parks and wind farms that should not be directly accessible from the internet. These include exposed administrative interfaces and control panels. The researchers mapped operating wind farms and solar parks in 40 countries across the European Union, European Free Trade Association (EFTA) and EU candidate states, and found exposed systems in 35 countries.
The research identified 7,942 exposed systems at solar sites in 34 countries. Spain accounted for 2,766, or 35% of the total. Together, Spain, Greece, Italy and Germany accounted for 76%.
For wind farms, 605 exposed systems were identified in 23 countries. Germany accounted for 212 and Italy for 192, together representing 67% of the total. In the Netherlands, the researchers identified 132 exposed systems at solar sites and nine at wind sites.
Examples of the exposure included a web interface for a wind turbine displaying live production data, with Start, Stop and Reset controls and the turbine's location shown on a map. The researchers also found login pages identifying the wind park they protected, including one that stated that the default username was "root".
To identify the systems, the researchers used machine-learning clustering in Modat Magnify. The system automatically groups similar systems found online and identified device types for which no detection rules had previously been developed.
The researchers recommend that operators immediately remove administrative interfaces from the public internet and plan and monitor their systems on the assumption that an attacker may already have gained access. They also recommend secure connectivity based on established operational technology principles, consideration of manual operating modes, and operating procedures that can be adapted to different threat levels or specific events.
Operators should also maintain an overview of their assets, network architecture and access, including connections provided by suppliers and service providers. The researchers further recommend information sharing between operators and organisations at national and European level.
The research publishes aggregated figures by country. Names of parks and operators, IP addresses and locations have not been made public. Affected parties are being informed through their national computer emergency response teams (CERTs).




