- A Dutch hacker demonstrated control over 4 million solar panels, exposing major vulnerabilities in centralized management systems.
- Consumer and business solar panels are managed by a few companies, often outside Europe, with virtually no regulation, despite controlling gigawatts of power.
- These cloud-based platforms could accidentally, after a hack, or intentionally shut down all panels simultaneously, causing a collapse of the European electricity grid.
- The grid requires precise balance, but central management of solar panels bypasses strict regulations applied to large power plants.
- Hackers can modify inverter firmware via manufacturer servers, potentially causing grid disruption or permanent damage to installations.
- Current EU regulations treat these management platforms as ordinary websites, not as critical energy infrastructure, leaving them largely unregulated.
- Upcoming EU directives (NIS2 and Cyber Resilience Act) offer opportunities to impose stricter rules, but explicit inclusion of solar panel managers is essential.
- Proposed solutions include removing centralized remote control capabilities or regulating these platforms as energy companies.
- The same risks apply to heat pumps, home batteries, and EV charging points, which also have grid-disruptive potential.