Help Net Security reported on 9 October that Modat and NCSC-NL, the Dutch government's cyber center, found 8,547 wind and solar systems that anyone online can reach. They span 35 countries in and around the EU. Solar makes up 7,942 and wind 605. Modat's software groups similar devices automatically, so it caught types nobody had written a rule for. One turbine page shows live power data and offers Start, Stop and Reset buttons. A menu item away sits the web server of the Siemens controller running the turbine. A map page gives its location.
Spain, Greece, Italy and Germany hold most of the confirmed systems. The true total is higher, since the team counted only systems it had matched to a named site. Two wind park logins named their sites, and one said newer releases use root as the default username. Help Net Security does not say whether anyone has attacked these systems or whether operators have been told.
The authors say spread-out generation is hard to attack physically, yet online it offers no such shield. Some exposed wind systems control several turbines at once, so one login can reach more than one machine. Tributech CEO Thomas Plank told Help Net Security that boards should ask how many outside parties can change how assets run, and whether each change can be proven authorized.