How solar and wind farms can be turned on and off by anyone
Research by The Hague-based internet intelligence company MODAT has uncovered thousands of exposed systems linked to European wind farms and solar parks. Some provide access to controls for individual turbines, multiple turbines or an entire farm, highlighting the risk of unauthorised interference with electricity generation.
To See the Wind and the Sun
Joint ReportThe report, To See the Wind and the Sun, is presented at ONE Conference in The Hague on 6 October 2026 by Soufian El Yadmani of Modat and Bouke van Laethem. Using MODAT’s Magnify platform, the researchers identified 8,547 internet-facing systems across 35 countries in the European Union, EFTA and EU candidate states that should not be exposed online.
From a dashboard to the controls
One example in the report shows an internet-accessible wind turbine interface displaying live information about power production, wind speed and the machine’s operating status. Alongside this information, a control panel offers start, stop and reset functions. The interface also reveals the turbine’s physical location.
Other systems identified by the researchers control several turbines or a whole farm through a single interface. Access at this level could allow an intruder to interfere with a site’s electricity production remotely.
The findings concern exposed systems, rather than confirmed attacks on every site. The report does not state that the researchers actually switched farms off. It does, however, demonstrate how sensitive operational information and controls can be reachable from the public internet.
Thousands of systems exposed
Of the systems identified, 7,942 were linked to solar parks and 605 to wind farms. In the Netherlands, the researchers identified 132 solar-related systems and nine wind-related systems.
These figures count systems, rather than individual parks, turbines or panels. They also represent only those systems the researchers could confidently connect to renewable energy infrastructure. Further exposed systems may remain unidentified.
AI speeds up discovery
The researchers used machine learning to group similar internet-facing systems and establish their connection to energy infrastructure. This helps defenders identify weaknesses more quickly, but the same capabilities can also help attackers find potential targets.
“What we can map in hours, an attacker can map in hours too,” the researchers write in the report.
Securing the energy transition
The study highlights a challenge for renewable energy: spreading generation across many locations can improve resilience to physical disruption, while exposed digital controls can leave those same sites vulnerable to remote interference.
MODAT calls on operators to remove administrative interfaces from the public internet, secure remote connections and strengthen monitoring and software maintenance. They also urge operators, suppliers and service providers to share information and maintain a clear overview of their systems and access arrangements.