- European power grids are becoming increasingly dependent on inverter based resources sourced from China, shifting distributed devices from operationally marginal assets to system relevant infrastructure whose coordinated behavior can influence grid stability at scale.
- China manufactured and China linked inverter ecosystems create a security exposure through scale of deployment, remote management features, and limited transparency across complex supply chains, with systemic risk increasing as vendor and platform concentration grows.
- Open source research demonstrates that Chinese scientists from universities linked to Chinese military and intelligence institutions are actively studying how to disrupt and collapse modern power grids.
- Observed activity indicate that China employs and prepares for both kinetic and non kinetic targeting of energy infrastructure, including military rehearsal against energy facilities and sustained cyber activity affecting energy sector, clearly demonstrating that energy systems are treated as instruments of pressure and coercion by Chinese military planners.
- Recent civilian cybersecurity authorities’ warnings and NATO statements reflect growing recognition that Europe’s rapid deployment of inverter based energy technologies supplied by China has outpaced existing security governance, visibility, and assurance mechanisms, creating structural exposure in power systems that underpin both civilian resilience and military readiness.
System Relevance of Inverter Fleets
European power systems are undergoing a structural transformation driven by decarbonization and electrification. Inverter based resources such as solar inverters and battery storage systems are increasingly integrated into distribution and transmission networks. At low penetration levels individual inverters are operationally marginal and have little effect on overall system stability. As penetration increases these devices become system relevant. Their operation is governed by firmware and configuration parameters that can be modified remotely and at scale.
From a security perspective, the primary concern arises from aggregation and coordination. Individual inverter failures have negligible impact, while correlated behavior across large fleets can influence system wide performance1. Coordination is enabled through shared firmware, centralized update mechanisms, vendor operated cloud platforms, and aggregator control systems2. These features support efficient grid operation but also introduce concentrated control planes whose disruption or manipulation could have wide geographic effects.
Chinese inverter ecosystems are relevant in this context due to their scale of deployment, reliance on remote management, and limited transparency across complex supply chains. As reliance on common platforms and software increases, the potential impact of malfunction, compromise and coercive access grows. Dependencies on technologies and services operated outside Allied jurisdictions introduce additional considerations for resilience and risk management.
Research Foundations for Power Grid Disruption Capabilities
Open source research provides insight into potential threat development. A substantial body of Chinese academic work examines cascading failures, critical node identification, and optimized disruption of Western power grids using realistic system models. Across dozens of peer reviewed publications, Chinese researchers examine how failures propagate through Western power grids, how critical nodes and links can be identified and targeted, and how limited interventions can be optimized to produce disproportionate system wide effects. This work includes detailed simulation of targeted and hybrid attack scenarios such as node removal, edge overload, and false data injection, often conducted under constraints including incomplete system knowledge, limited resources, or time sensitivity. Several studies explicitly focus on identifying the minimum number of components or control actions required to trigger large scale outages or cascading collapse, and some model control strategies designed to induce grid wide failure through manipulation of a small subset of nodes.
The institutional context of this research is also significant. Although the work is published in civilian peer reviewed journals and authored by researchers affiliated with universities, a substantial share originates from institutions and individuals with documented links to China’s defence and intelligence ecosystem, including organizations associated with military civil fusion and state owned grid operators. The scale, continuity, and thematic consistency of this body of work suggest the existence of a sustained, state backed research stream focused on power grid disruption. This does not in itself demonstrate intent to act against European systems. It does, however, indicate long term capability development and detailed familiarity with the operational characteristics of Western power grids, including the digitally controlled and inverter heavy infrastructures that are now being deployed and interconnected across Europe.
Disruption Pathways, Cyber-Physical Consequences and Limited Visibility
Deniable Disruptions
Disruption scenarios assessed by this analysis as plausible follow two distinct pathways with different strategic uses. The first involves gradual and difficult to attribute interference that can be employed under normal operating conditions and below traditional conflict thresholds. Small changes to inverter parameters such as reactive power response, frequency support behavior, ride through thresholds, or ramp rates can cumulatively degrade grid performance without triggering immediate protective responses. When applied in a coordinated manner across large fleets, these changes can increase operating stress, reduce stability margins, and contribute to voltage instability or protection events that resemble technical faults or stress induced failures. Because such effects are difficult to distinguish from normal equipment behavior, misconfiguration, or environmental stress, they are well suited for long term pressure and coercion. Over time, this form of interference can force increased investment in grid reinforcement, imposing economic costs while remaining largely unattributable under current visibility conditions. This pathway is therefore usable well short of open conflict and aligns with strategies that seek to strain resources, shape policy choices, or erode confidence without crossing clear escalation thresholds.
Overt Disruptions
A second pathway becomes more relevant under conditions of heightened crisis or broader conflict escalation. In such scenarios, coordinated large scale disruption of inverter fleets, including rapid disconnection or forced shutdown, could be used to produce immediate and visible system effects. While more overt and therefore more likely to be attributed, this form of action would be consistent with the use of energy infrastructure disruption as an escalatory instrument observed in contemporary conflicts. The existence of remotely manageable control planes and concentrated update or management mechanisms means that such high impact actions, while less suitable for deniable pressure, remain a credible option in a high intensity or multi theatre conflict context.
Cyber-Physical Consequences
The same control mechanisms that enable deniable or overt disruption of grid stability also extend into the physical domain. Inverter-based resources are cyber-physical devices whose operation directly governs the flow of high currents at the edge of the grid. Under conditions of limited visibility and centralized firmware control, the distinction between stability effects and physical safety effects becomes one of degree rather than kind. As a result, the disruption pathways described above can, under certain conditions, manifest not only as grid disturbances but also as localized physical hazards.
From a cyber-physical perspective, protection mechanisms are not independent of control logic and configuration. Deliberate manipulation of firmware behavior, protection thresholds, or control timing could interfere with how safeguards are applied, particularly in systems that are poorly installed, improperly configured, degraded over time, or operating near design limits. Under such conditions, cyber manipulation does not need to defeat protections outright to increase physical risk; it may instead delay, desensitize, or misapply protective responses in ways that raise the likelihood of equipment damage or fire. This does not imply that such outcomes are likely or easily achievable, but it reflects a well-established principle in cyber-physical systems engineering that safety functions are only as robust as the assumptions under which they are designed, tested and operated.
This principle has been demonstrated in proof-of-concept and controlled settings across the power sector. Most notably, the <AURORA> demonstration showed that malicious manipulation of control and protection functions in electric power equipment could induce destructive physical stress without defeating hardware protections, by exploiting timing and sequencing assumptions rather than disabling safeguards. While <AURORA> involved large rotating machinery rather than inverter-based systems, it remains relevant as a foundational illustration of how cyber access to control and protection logic can translate into physical effects in energy systems.
In the context of inverter-based resources, in late 2025, a product safety recall in Australia for Chinese <Sigenergy SigenStor> single-phase energy controllers cited a risk that AC plugs could overheat and become damaged, posing a fire hazard. The way the issue was mitigated is instructive. Instead of relying solely on physical corrections, the supplier reportedly deployed a firmware update that allowed the system to monitor operating conditions and automatically reduce AC output when sustained load risked overheating. In practical terms, this means that key electrical behaviors that affect safety, such as how much power the system delivers and under what conditions it throttles or shuts down, are controlled by firmware that can be changed remotely by the manufacturer. Even when used responsibly, this level of control means that vendors retain the ability to alter safety-relevant behavior at scale, largely independent of local installers or system owners.
Interestingly, the notion that energy devices could be implicated in real-world cyber-physical attack has already entered public discourse. During the wave of pager explosions targeting Hezbollah operatives in Lebanon in September 2024, initial reporting by Lebanon’s National News Agency, followed by wider media pickup and social media circulation, amplified unconfirmed claims that residential solar inverters had also exploded. These reports contributed to heightened public anxiety at a time of already elevated tension. Subsequent reporting and investigation did not substantiate the claims, and the most plausible explanations pointed to secondary effects, such as nearby pager detonations.
But the relevance of this pathway is not purely theoretical. Real-world incidents demonstrate that errors introduced through firmware updates already led to physical system damage even in the absence of malicious intent. In 2023, reporting documented 800 cases in Germany where a faulty firmware update affected Chinese <Sungrow> battery energy storage systems, resulting in abnormal behavior and physical damage that required system shutdowns and replacement of affected components. These incidents were attributed to software developer’s mistake, but they nonetheless illustrate that firmware changes alone can propagate rapidly across deployed fleets and have tangible physical consequences. This context matters because market data estimates suggest that more than 60% of inverter capacity deployed in the EU relies on firmware developed and maintained by Chinese manufacturers. Even without malicious intent, the concentration of such control outside European jurisdictions has direct implications for resilience, assurance, and governance.
Limited Visibility
These challenges are compounded by limited visibility into the operation of distributed inverter fleets, especially in the residential sector. Many small scale inverters operate without continuous network monitoring accessible to system operators. Error logs are often stored only in volatile or short retention memory and may be lost during power interruptions, precisely when forensic evidence would be most needed. This severely constrains post-mortem analysis and limits the ability to reconstruct the sequence of events that led to a disturbance. As a result, authorities may be unable to determine whether anomalous inverter behavior reflects technical malfunction, misconfiguration, systemic stress, or coordinated external manipulation. Similar concerns were evident during investigations following the Iberian blackout, where authorities undertook efforts to examine the potential role of large numbers of residential inverters.
These efforts highlighted not only the seriousness with which potential inverter-related contributions were examined, but also a deeper structural limitation. In highly digitalized power systems, reliably determining whether an incident involved malicious activity requires correlating electrical behavior with cyber/network, and control-plane data, including market signals. Electrical measurements alone are insufficient, and cyber and market indicators without electrical context are equally inconclusive.
This limitation remains poorly understood outside specialist communities, in part because responsibility and visibility are fragmented across the power system. Transmission and distribution system operators as well as operators of critical infrastructure level power plants are subject to regulatory requirements that mandate extensive logging, monitoring, and incident reporting across both electrical and cybersecurity domains within their own operational perimeter. As a result, they can credibly assess and communicate whether their control systems show signs of cyber compromise. By contrast, small distributed energy resources, like residential, sit outside this regulatory envelope. At low-voltage levels, there are typically no mandatory requirements to collect, retain, or make available cybersecurity logs, command histories, or network telemetry. At the same time, these assets are no longer operationally marginal and under certain conditions can influence system stability at the distribution and transmission level. This creates a structural asymmetry: assets with growing system-level impact remain among the least visible from a cybersecurity perspective.
The consequences of this asymmetry were visible during the Iberian blackout. When officials stated that no cyberattack had been detected on transmission system operator’s (REE) systems, this was widely interpreted as ruling out cyber involvement altogether. In reality, the statement only reflected the absence of indicators within the REE’s legally defined and technically observable domain. It did not, and could not, exclude cyber-related activity affecting residential inverter fleets or other distributed resources that fall outside REE’s operational control and visibility.
Recent reporting has further increased concern regarding limited visibility into deployed systems. In 2025 authorities reassessed risks after discovering undocumented communications components in some Chinese made energy equipment, including inverters and batteries. These components were not described in technical documentation and could enable alternative communication paths that bypass expected network controls. Although no public evidence demonstrated malicious use, the discovery confirmed that undocumented capabilities can exist and may be difficult to detect once devices are deployed at scale. This finding undermines assumptions that technical measures alone are sufficient to bound risk.
Civilian Authorities’ Assessment of Chinese Dependencies
Civilian security authorities and regulators in Europe have begun to publicly frame inverter ecosystems as a security relevant dependency rather than a purely technical component of the energy transition. In the Czech Republic, the National Cyber and Information Security Agency <NÚKIB> issued a formal warning that treats remote administration of technical assets from China and transfer of system and user data to the China as a cybersecurity threat, and it explicitly notes solar inverters among examples of products that may fall within this risk context. In Germany, the Federal Office for Information Security <BSI> has raised concerns that proposed approaches to remote or grid supportive control of photovoltaic systems could enable foreign influence over parts of the energy supply, and it has warned against designs where manufacturers retain the ability to exercise remote control through vendor platforms.
At the EU level, the dependency dimension is also becoming more explicit. Reporting on European Commission materials on economic security has highlighted reliance on Chinese solar inverters as an example of high risk dependency, indicating that the issue is being considered within a broader framework that links supply concentration, cybersecurity exposure, and strategic vulnerability. International Industry and sector bodies have reinforced this direction, including calls for an EU level inverter security toolbox and restrictions or governance measures focused on remote access and vendor risk management in inverter ecosystems. Taken together, these signals suggest a shift from viewing inverter security as a niche technical matter toward treating it as a cross cutting dependency problem.
NATO’s Assessment of Chinese Dependencies
These structural and technical vulnerabilities must be considered alongside demonstrated behavior in contemporary conflict and military preparation. Open source reporting indicates that China is integrating energy infrastructure disruption into both its military planning and its non kinetic operational activity. Chinese military exercises and strike drills have included attacks on full scale replicas of Taiwanese liquefied natural gas terminals, signaling explicit interest in disabling energy supply chains through precision strikes. At the same time, Taiwanese authorities report persistent and large scale Chinese cyber activity directed at Taiwan’s energy systems, with publicly reported statements indicating Taiwan’s national power company being hit by cyberattacks on daily basis. These actions demonstrate that degrading energy supply through both kinetic and non kinetic means is treated as a credible instrument of pressure and political signaling within Chinese military planning and operational thinking.
Recent NATO statements reinforce this assessment of the threat environment and reflect a shift in how the Alliance views energy systems within the broader security landscape. Alliance officials have highlighted that Europe’s energy transition has created new structural dependencies on externally supplied technologies, materials, and digital control systems that underpin both civilian electricity supply and military logistics chains. In this context, large fleets of remotely manageable energy devices are no longer viewed solely as civilian assets, but as infrastructure whose disruption could produce systemic and cross border relevant effects. NATO officials have explicitly drawn attention to Europe’s growing reliance on Chinese supplied technologies across the energy sector, including solar panels, inverters, wind components, batteries, and critical raw materials. These dependencies intersect directly with military logistics, which rely on secure and reliable civilian energy infrastructure. As a result, NATO is increasingly scrutinizing the green transition as a potential source of strategic exposure, particularly where remote access, or concentrated supply chains could be exploited.
Overall Assessment and Strategic Implications
Europe is constructing a power system that increasingly relies on software-defined control points operated directly or indirectly by Chinese vendors. Open source research shows that China is actively studying how such systems can be disrupted. Open reporting demonstrates that undocumented technical pathways can exist in complex supply chains. Recent conflict confirms that energy systems are treated as strategic targets by China. NATO statements underscore the relevance of Chinese threats to critical infrastructure.
From a policy perspective, the risk described in this assessment is shaped by the mismatch between growing system reliance and existing governance, visibility, and assurance mechanisms. Current security, visibility and control frameworks were largely designed for traditional centralized assets and do not provide equivalent oversight of distributed inverter fleets, particularly in the residential sector. As inverter penetration increases, assumptions that market forces or industry-led self-regulation can manage security exposure become progressively weaker. This is particularly the case where industry associations represent member bases with significant dependence on Chinese vendors, which shapes the range of positions they are structurally incentivized to advance. Addressing this gap will require sustained regulatory intervention and coordinated action by public authorities and standards bodies to ensure sovereignty across the full inverter ecosystem.