There is a specific kind of vulnerability that feels almost too simple to be true. Imagine a bank that installs the most advanced, reinforced steel vault door ever engineered, only to leave the keys in the lock and a sign on the street that says "The password is password."
In the world of European renewable energy, we are seeing the digital equivalent of that open door. In some of the systems managing our power, the administrator account name is still set to the factory default: "root." This isn't just a matter of someone's office email being exposed. These systems control the pitch of turbine blades across the North Sea and the voltage inverters of massive solar arrays in Spain. They are the physical switches of our modern world, and many of them are currently visible to anyone with an internet connection.
In October 2026, the Dutch research firm Modat and the National Cyber Security Centre (NCSC-NL) published a mapping of Europe's green energy infrastructure. They found 8,547 systems—hardware that should be protected by strict network isolation—exposed directly to the open internet. Of these, 7,942 are related to solar energy and 605 are wind power systems.
Spain leads this list in a way no country wants to: with 2,766 exposed systems, it accounts for 35% of all open solar infrastructure in Europe. Meanwhile, Germany and Italy together make up 67% of Europe's open wind energy systems.
Here is the contradiction that should bother us. In the second quarter of 2026, renewable energy produced 54% of all electricity in the European Union. For the first time in history, wind and sun are the backbone of the European power grid—and yet that backbone is digitally fragmented into thousands of open windows.
The Paradox of Distributed Energy
For decades, our power came from a few massive, centralized points—mostly coal or gas plants. If an attacker wanted to take out the lights, they had one big target. Shifting to distributed renewable energy actually made the grid physically much more robust. If a turbine blade breaks, one park goes offline, not an entire region. It's a resilient, spider-web architecture.
But here is the strange part: that same distribution, which gives us physical strength, creates thousands of tiny digital entry points.
Industrial controllers—the devices that manage turbine rotation, solar panel inverters, and battery storage—are the central nervous system of a power park. Unlike your laptop, the software on these controllers isn't updated every Tuesday. Some are running on versions of software that haven't been supported for years. Many were never intended to be connected to the internet at all. And yet, they are. When researchers scanned them, some answered with that one chilling word: "root."
Soufian El Yadmani, the founder and CEO of Modat, noted that while wind and sun are physically robust, they are digitally fragmented and often unmonitored. He added a warning that lands with a snap of clarity: "What we can map in hours, an attacker can map in hours too."
What "Mapping in Hours" Really Means
Now, hold that thought. Modat's work is legitimate research, meant to find holes before the wrong people do. But the arrival of AI-driven tools has accelerated this process to a degree that is hard to wrap the human mind around. Mapping the vulnerable infrastructure of an entire continent no longer takes weeks of careful probing. It takes hours.
This isn't a hypothetical worry. We have already seen incidents in Poland where energy production continued even after attackers managed to cut off remote management systems. This suggests the goal wasn't to physically stop the flow of electricity—not yet. Instead, the goal was to test the fences, map the terrain, and secure access for future use. It is the digital equivalent of a scout marking the back doors of a fortress.
The Baltic Position
Estonia, Latvia, and Lithuania live in a reality with an additional layer of complexity that the rest of Europe doesn't share.
On February 8, 2025, the Baltic states finally disconnected themselves from BRELL—the common electricity grid shared with Russia and Belarus since the Soviet era. This wasn't just a technical change; it was a massive geopolitical divorce that cost €1.6 billion. Estonia's share was €298 million, with 75% of that covered by the European Union. Elering, the Estonian system operator, was responsible for the technical readiness of this transition.
Why does this matter for cybersecurity? Because BRELL was a strategic chain. Russia controlled the frequency of the Baltic grid, meaning they could theoretically disrupt the lights without hacking a single computer. Moving away from that made the Baltics independent, but it also placed the full burden of maintaining grid frequency on our own local infrastructure.
That makes sites like the Kiisa battery storage park—an €85 million facility managed by Evecon—a critical target. Since leaving BRELL, Kiisa has been subject to constant cyber-probing. It is one of the key mechanisms keeping the Estonian grid stable without Russian support. The same applies to the Risti solar park, developed by Sunly. With 350,000 panels and a cost of €120 million, it is one of the largest production units in the country. It is no longer just a power plant; it is a piece of the front line.
Hybrid War: A Fuzzy Word for a Precise Threat
We need to pause on the term "hybrid war." In official Estonian terminology, it is often discouraged because it is considered vague. But the phenomenon it describes is very real.
The Estonian Internal Security Service (Kaitsepolitseiamet) has noted that these operations are often the first phase of conflict. Before the tanks move, you see sabotage, disinformation, and cyberattacks designed to erode a society's trust in its own foundations. In 2024, Estonia detained about a dozen individuals acting on behalf of Russia to attack civilian targets. Russia also deliberately spreads narratives about the "decline of the West," using energy policy as a wedge to split the public.
As journalist Kadri Paas wrote in Postimees: "Russia has been attacking NATO for years—just not in the way the West is used to imagining war in its own head." We saw the reality of this in 2023 when the Balticconnector gas pipeline between Estonia and Finland was sabotaged. The vulnerability of our underwater cables and pipelines is no longer an abstraction.
The Anatomy of the Risk
How do those 8,547 open systems actually become a danger? It generally comes down to five factors:
- Default Passwords: Admin accounts named "root" with factory settings never changed.
- Legacy Software: Industrial controllers running versions of software that are no longer patched or supported.
- Direct Exposure: Systems that should live on a private internal network are instead visible on the public internet.
- Fragmented Management: Smaller energy parks often manage their own IT without specialized security teams.
- AI-Enhanced Discovery: Attackers can now find these vulnerabilities as quickly as security researchers can.
Poland's experience is a lesson for us all. When remote access was cut, the physical production stayed on because the turbine controllers were designed to be autonomous. That is the good news and the bad news at once: the grid is physically tough, but losing remote control means the operators are essentially flying blind.
The Horizon
There is a great deal we still don't know. Modat and the NCSC-NL mapped the exposed systems—the ones that are potentially reachable. But how many of those 8,547 are already compromised? How many have a quiet piece of code sitting inside them, waiting for a signal? No one knows.
Because the data is grouped by country, we don't have the exact number for how many of Estonia's solar and wind systems are among the exposed.
In 2007, when Estonia suffered its first major wave of cyberattacks—now seen as a landmark case of what we call non-linear conflict—no one knew exactly what was happening in the moment. The full picture only emerged years later.
Today, the backbone of European energy is more distributed and physically resilient than it has ever been. But it is also a collection of 8,547 open windows, many of them guarded by nothing more than a factory-set password.
How many of those windows are being looked through right now? We don't know yet. Hybrid warfare in the energy sector isn't just about the attacks we see; it's about the ones we haven't noticed. That, honestly, is the most important question.