Thousands of European wind and solar sites reachable online, but few confirmed attacks
About 181 renewable sites appeared to offer interfaces able to switch turbines on or off, sharpening the case for strict limits on remote access rights.
A team of researchers in the Netherlands, in cooperation with the country’s national cyber security centre, counted 8,547 wind and solar installations across 35 European countries that were reachable from the internet when they should not have been.
In brief
- The smaller figure is the sharper one: according to Reuters, roughly 181 of those sites seemed to present interfaces that could do more than display data, including commands to start or stop turbines.
- Renewable generation is scattered over rooftops, farmland, industrial plots and isolated hillsides.
- None of these steps requires abandoning connected infrastructure; the author explicitly rejects reading the findings as a case against renewable energy or networked systems.
The headline count describes reachability. The smaller figure is the sharper one: according to Reuters, roughly 181 of those sites seemed to present interfaces that could do more than display data, including commands to start or stop turbines. In an opinion piece for Daily News Hungary, the security and control-room researcher Abdulla Saeed Alhebsi argues that this finding deserves precision rather than alarm. What the researchers documented, he writes, were exposed systems and possible routes to control, and he warns against treating each such discovery as the prelude to an unavoidable cyber disaster.
For Central Europe the issue is not abstract. Alhebsi notes that Hungary is embedded in a European energy system that grows more interconnected each year, with national installations, regional grids and digital services relying on each other, so a renewable asset that can be reached remotely becomes a concern beyond one site’s IT team.
Why connected renewables are harder to fence in
Connectivity itself is not the villain in Alhebsi’s account. Online links let operators watch, service and balance modern energy assets efficiently; remote access cuts downtime and spares engineers a trip to every location when equipment needs diagnosing.

The difficulty is geography. A conventional power plant gathers its machinery, its staff and its security measures inside one defined compound. Renewable generation is scattered over rooftops, farmland, industrial plots and isolated hillsides. In that landscape, Alhebsi writes, every inverter, turbine controller, gateway, supplier login and remote-maintenance channel may end up forming part of the operational perimeter that has to be defended.
Reach, authority and consequence
To sort serious exposure from harmless visibility, Alhebsi proposes what he calls a Reach-Authority-Consequence test. Three questions apply to any asset: who is able to get to it, what that access entitles them to do, and what physical outcome could result.
The answers separate very different credentials. A login limited to reading output figures is not equivalent to one that can halt machinery, and he argues that a site’s security design should make that gap obvious. His rule for maintenance follows from it: such an account should carry precisely the rights maintenance demands, only for the period it is required, and nothing beyond.
Paperwork alone cannot confirm this. A procurement checklist may certify that a product offers encryption, authentication or logging, Alhebsi observes, yet it says nothing about the effect of a hijacked contractor account, whether a remote instruction could override a local safety mechanism, or how fast a control room could cut off a connection. As an example, he cites a project unveiled on 6 October in the United Arab Emirates: the national cyber security council and SCC Middle East intend to create a centre of excellence focused on cyber resilience and trusted technology, in which public bodies, companies and specialists would test concrete cases and look at how to deploy such systems securely on a large scale.
Where owners can start
Alhebsi lists a sequence of practical measures for asset owners:
- Find every operational interface that can be reached from the internet.
- Take down any public exposure that is not needed.
- Split monitoring rights from command rights.
- Restrict and tighten supplier access.
- Check that operators can withdraw remote privileges quickly.
None of these steps requires abandoning connected infrastructure; the author explicitly rejects reading the findings as a case against renewable energy or networked systems.
Featured image. Source: Pexels. Credit: Quang Nguyen Vinh. License: Pexels License.



