Thousands of wind and solar park systems sit exposed on the internet across Europe

Modat and NCSC-NL, the Dutch government’s cybersecurity center, found 8,547 internet-facing systems at wind farms and solar parks in 35 countries in and around the EU that should not be reachable from the internet. The systems range from login screens to a turbine control page that offers a Stop button to anyone with a browser.

Operators in Spain, Greece, Italy and Germany account for most of the confirmed systems. The real number is higher. A system only made the list once the team could link it to a specific solar or wind site.

Europe’s renewables do have one defensive advantage on the ground. Solar parks and wind farms scattered across the continent make a poor target for bombs, drones or saboteurs, and the International Energy Agency has linked Ukraine’s push toward decentralized power to energy security. The authors put the catch this way: “Physically, decentralised renewable energy is a very hard target. But in cyberspace, there is no there there.”

One web page, one turbine

Modat found the devices with machine-learning clustering, which groups similar systems automatically, so new device types turn up without someone first writing a rule to detect them. Some of the solar and wind devices were ones the team had not known to look for.

One wind turbine shows what the exposure looks like. Its web dashboard displays live power, wind speed and rotor data, and its control panel offers Start, Stop and Reset buttons. One menu item further sits the web server of the Siemens ET 200SP PLC, the industrial controller that runs the turbine. A map page gives away the turbine’s location, and aerial imagery of that spot shows the neighboring turbine, the service buildings and the access road.

That page runs one machine. Other systems in the data set sit a level higher and control several turbines or a whole farm, so one exposed system can stand for far more generating capacity than a single turbine. Two wind park login pages named their sites outright. One of them noted that the default username is root in all newer releases.

renewable energy cybersecurity

Redacted login page on a wind park, with aerial imagery of the site (Source: Research report)

Spain leads on solar, Germany on wind

Solar accounts for 7,942 of the systems, across 34 countries. Spain alone has 2,766, or 35 percent. Add Greece (1,860), Italy (753) and Germany (672), and those four countries hold 76 percent of the solar total. Wind accounts for 605 systems across 23 countries, with Germany (212) and Italy (192) making up 67 percent. Spain, the solar leader, has 11 on the wind side.

The smaller wind figure is less comforting than it looks. The wind farms in scope run from 10 megawatts to more than 4,500, and some of the exposed wind systems control several turbines at once.

Vendors and remote access

Lithuania bars entities from countries it considers national security threats, including China, from remotely controlling solar parks, wind farms and storage above 100 kW. Asked whether other countries should copy that rule, Thomas Plank, CEO of Tributech, said:

“Restricting remote control by high-risk vendors is a reasonable national security step, but it addresses who connects, not what happens once they do. Most of the systems in this report are exposed regardless of where the vendor is based, and a European vendor with a stolen maintenance account gives an attacker the same access.”

Plank said wind and solar parks now rely on dozens of remote links to outside parties, and that some of those links will be compromised. “Once an attacker is inside, the network can’t tell a legitimate stop command from a malicious one,” he told Help Net Security.

“Every command that reaches a turbine or inverter should be checked for who sent it, whether that sender is authorized for that specific asset and action, and whether it arrived unchanged,” Plank said. “That protection applies to every vendor equally, whatever their origin.”

What CIOs should ask vendors

NIS2, the EU’s cybersecurity directive, requires the management bodies of essential and important entities to approve and oversee cybersecurity measures and makes them liable, whether systems are run in-house or outsourced. For a CIO whose turbines and inverters are maintained remotely by the manufacturer, Plank said:

“Start with a complete list of every remote connection: who connects, from where, to which assets, and whether they can only read data or also change how assets operate. Many operators can’t produce that today.”

From there, he would have CIOs require individual vendor accounts with strong authentication and no shared credentials, plus access limited to specific assets and actions, with the right to send commands split from the right to monitor. Operators should keep their own record of every command and configuration change, verify data and commands without leaning on the vendor’s systems, and get incident notice in time for NIS2’s 24-hour early warning.

“For the board, this turns into a few clear questions: how many external parties can change how our assets operate, can we prove every change was authorized, and can we trust the data our decisions are based on?”

The authors’ first step for operators is shorter. Take admin interfaces off the internet immediately, plan and monitor as if an attacker is already inside, and keep the option of running sites by hand.

Download eBook: Identity-First Threat Intelligence

Don't miss