Archive for NCSC-NL

Over 8,500 European wind, solar systems publicly exposed

Posted in Commentary with tags on October 8, 2026 by itnerd

Researchers from the Dutch National Cyber Security Centre (NCSC-NL) and cybersecurity company Modat identified 8,547 internet-exposed systems across European wind farms and solar parks, including administrative interfaces and operational control panels that should not be publicly accessible, according to new research.

The researchers examined renewable energy facilities across 40 European countries and identified exposed systems in 35. Of those, 7,942 were associated with solar installations across 34 countries, while 605 were linked to wind farms across 23 countries.

Some exposed interfaces displayed live electricity production data, turbine locations and operational controls labeled Start, Stop and Reset.

Researchers estimated that approximately 181 sites could potentially allow full operational control. Other exposed pages included administrative login screens, with one displaying the default username “root.” Some interfaces could manage multiple turbines or an entire wind farm.

The researchers said the 8,547 figure is likely an undercount because only systems confidently associated with specific facilities were included.

ㅤDamon Small, Board of Directors, Xcape, Inc.:

“Unauthenticated, Internet-exposed interfaces on critical infrastructure threaten regional grid resilience and create operational, legal, and reputational risk across renewable energy portfolios. The discovery of over 8,500 exposed European wind and solar management endpoints, including over 180 permitting full operational intervention, highlights fundamental identity and network perimeter failures. While remote access to operational technology (OT) systems is a clear operational requirement, it must be delivered securely through zero-trust access, network segmentation, and multi-factor authentication rather than exposing control panels directly to the public Internet. To prevent these foolish architectural decisions, organizations must conduct mandatory threat models and architecture reviews before production systems go live, while immediately pulling existing interfaces behind secure gateways and enforcing credential rotation.”

Critical Takeaways

  • Publicly exposing OT control interfaces directly to the Internet turns standard management features into severe grid resilience vulnerabilities.
  • Remote access is a valid operational requirement, but it must be mediated via zero-trust architecture, multi-factor authentication, and secure gateways.
  • Formal architecture reviews and threat modeling must occur prior to live deployment to catch perimeter and identity flaws early.

Threat modeling before deployment costs a fraction of what an incident responder will charge to explain why “root” was still the password.

ㅤ

Steven Swift, Managing Director, Suzu Labs:

“This isn’t an AI problem, even if the authors of the research claim that “AI made things a little faster” We’ve seen decades of organizations putting resources directly onto the public internet with minimal to no protections in place, and then act surprised when its found and exploited.

“There’s already a rich well developed industry of mapping the entire attack surface of literally every single public IP. This isn’t new, and it doesn’t depend on AI. If you put a resource on the internet, existing (non-ai) automation will find it, document it, and put it into a database for easy access by others.

“For this research specifically, there’s a mix of single devices and management interfaces for groups of devices. That said, much of the wind and solar infrastructure is decentralized. So while 8,500 devices being directly exposed to the internet is a lot, if a threat actor wanted to cause harm, they would be limited to a subset of these at a time.

“That’s still a problem. Power is part of critical infrastructure. People want their power to keep working, and not to have an outage because someone decided to hack in. If an attacker wanted to cause harm, rather than simply turning power generation off they could tamper with the working configuration. If the system can be misconfigured to intentionally overload for example, permanent damage could result.

“This is an example where security best practices are completely basic, yet still not being followed. Literally just don’t have equipment directly exposed to the internet. Having remote access to systems is fine, but it needs to be secure. Putting equipment behind a secure VPN for example is only minimally more complex to setup, and orders of magnitude more secure.”

ㅤThreat actors will always target stuff like this because they can pwn it easily. Thus your job is to not be the guy who gets pwned.