Taken together, the 2024 record shows how the rapid integration of renewable energy is reshaping the security profile of power grids. Incidents and research consistently point to cloud-based coordination layers as the points where individual installations become system-relevant. Public cases demonstrate that access at these coordination points can scale across many installations at once. At the same time, policymakers and regulators are beginning to recognize that inverter connectivity and concentrated supply chains introduce new dependencies into grid operations.
This is not a comprehensive news archive. Entries are filtered to include only events that materially shaped understanding at that time. Entries are ordered chronologically, starting in January 2024. Each item can be expanded to view the full summary and source context by clicking into the box.
Category: Cyber Activity & Intrusions
Title: Cyber Activity Targeting Solar Monitoring Systems in Japan
Date: 5 Jan 2024Summary
Hacktivist and criminal actors exploited vulnerabilities in CONTEC SolarView photovoltaic monitoring systems deployed at solar power facilities in Japan, gaining unauthorized access through command injection flaws. The activity is linked to exploitation of CVE-2022-29303, a vulnerability disclosed by Palo Alto Networks in June 2023, which the company reported was under active exploitation at the time, including for the propagation of the Mirai botnet. Public proof of exploitation emerged when attackers posted a YouTube video demonstrating successful compromise of a SolarView system. CONTEC issued a firmware update to address the vulnerability on 18 July 2023 Subsequent reporting in early 2024 indicated that approximately 800 SolarView Compact remote monitoring devices at Japanese solar power generation sites had been hijacked. In these later cases, compromised devices were reportedly used as part of broader criminal activity, including bank account theft.Source Perspectives
Vendor: Confirmed the attack,
Technical analysis: S2W South Korean security firm identified the threat actor as Arsenal Depository, also known as Hacker CN, likely Chinese or Russian actor, provided a detailed breakdown of the Operation Japan campaign, including exploitation details, referenced CVEs, and screenshot evidence of compromise.
Incident reporting: Japanese and international media reported the compromise of approximately 800 SolarView devices and the subsequent vendor response.
Risk commentary: Industry security commentary highlighted that while the incident did not disrupt power generation, it demonstrated exposure of internet-connected solar infrastructure.Why it matters
This case illustrates that internet-connected solar monitoring infrastructure has already been targeted and compromised in the wild.Category: Vulnerabilities & Technical Exposure
Title: Security Weaknesses in Solar PV Gateway Devices and Cloud Control Planes
Date: 11 Jan 2024Summary
Trend Micro published a technical report of “distributed energy generation” gateway devices used in solar PV systems, focusing on network gateways and their associated cloud services. The researchers analyzed gateway products from five vendors (Enphase, Outback, Phocos, Sol-Ark, Victron) and reviewed communication protocols, hardware, software and communication vulnerabilities, and user interfaces.Source Perspectives
Control plane risk framing: The authors explicitly discuss “large-scale outages via the cloud” as a scenario in which attackers target accounts or services that manage fleets, enabling remote influence where platforms allow control.
Data and sovereignty exposure: The report notes that some gateway ecosystems transmit operational data to infrastructure in different jurisdictions and provides a detailed example of Sol-Ark telemetry resolving to Alibaba Cloud infrastructure in China at the time of writing.Why it matters
This analysis is directly relevant to inverter and distributed energy risk discussions because it treats the PV “gateway plus cloud” layer as an enabling control surface. It shows that weaknesses can create routes to influence or disrupt distributed generation at scale, even when individual devices appear operationally marginal.Category: Policy & Regulation
Title: European Parliament Warns of Chinese Influence Over EU Critical Infrastructure
Date: 15 Jan 2024Summary
The European Parliament agenda briefing ahead of the January 2024 plenary session warned that growing Chinese influence over European critical infrastructure poses security risks and requires stronger EU action. The briefing highlighted concerns linked to China’s military-civil fusion strategy and identified critical sectors.Why it matters
This briefing signals increasing recognition at the EU level that foreign control or influence over critical infrastructure is a security and resilience issue.Category: Policy & Funding
Title: DOE Allocates $30M for Clean Energy Cybersecurity Tools for Distributed Energy Systems
Date: 19 Jan 2024Summary
PV magazine USA reported that the U.S. Department of Energy allocated $30 million to advance research, development, and demonstration of cybersecurity solutions intended to protect distributed energy resource systems and modern clean-energy delivery infrastructure from cyber threats. The funding is administered through DOE’s Office of Cybersecurity, Energy Security, and Emergency Response (CESER) and is framed as building cybersecurity into the energy transition, including protections relevant to DER-connected and increasingly digital infrastructure.Source Perspectives
Government announcement: DOE/CESER described the funding as support for next-generation tools to detect and mitigate cyber threats to clean energy delivery infrastructure.
Industry reporting: pv magazine USA summarized the funding focus and positioned it in the context of growing cyber risk to DER systems.Why it matters
It signals that major governments are treating clean energy digitalization and DER scaling as a cybersecurity problem requiring dedicated tooling, not just compliance. It reinforces the relevance of control-plane and fleet-security risks in inverter-heavy power systems.Category: Policy & Regulation
Title: SolarPower Europe Rejects Import Duties Amid Growing Concern Over Chinese PV Dominance
Date: 6 Mar 2024Summary
PV magazine reported that SolarPower Europe called for stronger EU support to rebuild European PV manufacturing capacity while arguing against reintroducing import duties. The reporting framed the debate in the context of Chinese overcapacity and low priced imports that are accelerating European reliance on Chinese produced PV components.Source Perspectives
Industry position: SolarPower Europe argued that industrial support and targeted measures are preferable to import duties for strengthening the European PV sector while maintaining deployment momentum.
China dependency framing: pv magazine presented the discussion against the backdrop of Chinese manufacturing dominance and overcapacity as a driver of European supply chain dependency.Why it matters
This intervention is a policy signal in a debate where industry advocacy groups may face internal tensions between resilience objectives and the commercial interests of their membership. SolarPower Europe represents a broad industry coalition that includes companies with significant exposure to Chinese supply chains, which may shape its preference for measures that preserve import flows and deployment speed. Readers should therefore treat the position as an important indicator of industry sentiment, while recognizing that it may not fully reflect the security and dependency concerns raised by governments and critical infrastructure stakeholders.Category: Policy & Regulation
Title: EU Launches Investigation Into Chinese Wind Turbine Suppliers Under Foreign Subsidies Rules
Date: 10 Apr 2024Summary
pv magazine reported that the European Commission launched an inquiry into Chinese wind turbine suppliers, citing concerns that subsidized Chinese manufacturers may be distorting competition in the EU renewables market.Source Perspectives
Commission framing: The Commission indicated the review would examine conditions surrounding wind park development in several member states, including Spain, Greece, France, Romania, and Bulgaria, as part of a broader effort to use the EU’s Foreign Subsidies Regulation to address market distortion in strategic clean-tech sectors.
Industry context: WindEurope characterized the step as the first ex officio investigation under the Foreign Subsidies Regulation, linking it to concerns over low prices and financing terms offered by Chinese suppliers.Why it matters
This reflects an EU shift toward treating Chinese dominance in clean-energy supply chains as both an industrial and economic security issue. It signals growing readiness to apply regulatory tools to reduce strategic dependencies in core energy infrastructure technologies.Category: Policy & Regulation
Title: European Solar Charter Relies on Voluntary Commitments to Support EU PV Manufacturing
Date: 16 Apr 2024Summary
pv magazine reported that the European Commission announced the European Solar Charter, signed by 23 EU member states and industry bodies, as a measure to support European PV manufacturing. The Charter outlines voluntary actions such as accelerated permitting and the use of non price criteria in public procurement and renewable energy auctions, while not introducing trade restrictions or binding requirements to limit cheap imports.Source Perspectives
Commission framing: The Commission presented the Charter as a cooperation framework to strengthen European PV manufacturing and accelerate deployment, including early use of non price criteria in auctions and procurement.
Industry reporting: pv magazine emphasized that the measures are voluntary and do not include emergency interventions such as tariffs or mandatory restrictions, despite ongoing stress in European manufacturing.Why it matters
This illustrates the limits of voluntary de risking in a market shaped by large scale Chinese overcapacity and price pressure. Without binding procurement rules, voluntary charters are unlikely to materially change dependency trajectories or protect strategic manufacturing capacity.Category: Policy & Regulation
Title: EU Net-Zero Industry Act Seen as “New Era” for EU Solar, but Delivery Depends on Member States
Date: 28 Jun 2024Summary
A pv magazine press release carrying a statement from the European Solar Manufacturing Council (ESMC) presented the EU Net-Zero Industry Act (NZIA) as a turning point for European solar manufacturing. The statement also framed the context as a manufacturing crisis driven by global competition and Chinese price pressure, warning that implementation choices by Member States will determine whether Europe reduces dependency or remains exposed to concentrated external supply chains.Source Perspectives
Industry advocacy: ESMC framed NZIA implementation as urgent and called on Member States to apply resilience criteria immediately in procurement and auctions to support EU PV manufacturing.
pv magazine placement: The item is published as an industry press release, reflecting stakeholder messaging rather than independent reporting.Why it matters
This reinforces that EU “de-risking” in solar increasingly hinges on how Member States operationalize resilience criteria, not on voluntary commitments alone. It also highlights a persistent gap between recognizing Chinese supply-chain dominance as a strategic exposure and deploying binding national measures that would materially shift purchasing behavior.Category: Cyber Activity & Alerts
Title: FBI PIN Warns of Rising Cyber Threats to Renewable Energy Infrastructure
Date: 1 Jul 2024Summary
The U.S. FBI issued a Private Industry Notification (PIN) warning that expanding renewable energy infrastructure, including solar, wind, and microgrids, is increasingly targeted by malicious cyber actors. The alert highlighted that as the renewable sector grows, attackers may seek to disrupt power generation operations, steal intellectual property, or ransom critical operational information. In particular, the FBI noted that inverter-based resources (IBRs) and associated operational technology (OT) systems present exploitable attack surfaces, especially when connected to internet-accessible control and monitoring systems, and that unpatched or poorly secured equipment could enable unauthorized access or manipulation.Why it matters
The FBI warning explicitly treats internet-connected inverters and distributed energy resources as potential cyber attack pathways.Category: Commentary
Title: U.S. Congressman Warns of National Security Risks from Chinese-Sourced Solar Components
Date: 1 Jul 2024Summary
U.S. Representative Scott Perry (R-PA) issued remarks warning that China’s dominance in solar manufacturing and related technologies poses potential national security risks, particularly if components such as inverters, communications equipment, or transformers are sourced from China. Perry cited that China installed more solar capacity in 2023 than the United States has in its history and referenced a 2022 FBI investigation and a 2019 seizure of a transformer at the Port of Houston with alleged spyware to underscore concerns about foreign influence over energy infrastructure. He emphasized that components like inverters represent a locus of security concern and should be procured with consideration for national interests.Why it matters
The remarks reflect growing political attention in the United States to the security implications of dependence on foreign-sourced energy system components. By associating Chinese supply dominance with potential risks to military and critical infrastructure, the statement contributes to an emerging policy narrative that sees supply chain origin and remote connectivity as national security matters.Category: Research & Risk Assessment
Title: Dutch Secura Report Identifies Cybersecurity Threats and Mitigation Measures for Solar Sector
Date: 17 Oct 2024Summary
The Netherlands Enterprise Agency and Topsector Energie published a Secura-authored report assessing cybersecurity threats to the solar power sector and proposing mitigations. The public version of the study outlines a range of plausible cyberattack scenarios against PV installations of different scales, identifies threat actors and potential impacts, and emphasizes that successful attacks could disrupt electricity supply and produce severe economic, physical, and societal consequences. The report also stresses that securing solar infrastructure requires coordinated action across government, industry bodies, manufacturers, installers, and end users.Why it matters
This report is a sector-specific risk assessment indicating that cybersecurity vulnerabilities in solar PV are understood by domain experts as capable of causing wider energy system consequences.Category: Policy & Regulation
Title: SolarPower Europe Proposes EU Cybersecurity Baseline for Solar PV and Smart Inverters
Date: 11–12 Jul 2024Summary
SolarPower Europe published a position paper calling for a harmonised, sector specific cybersecurity baseline for solar PV, arguing that growing digitalisation and remote management of distributed PV assets increases exposure and requires consistent minimum requirements across the EU. pv magazine reported that the recommendations focus on establishing a common baseline for the sector in response to rising concerns about cyberattacks and the future system relevance of remotely managed PV and inverter fleets. A companion video summarizes the argument and frames the baseline as necessary to secure the benefits of digitalised PV deployment.Why it matters
The paper reflects growing recognition within the solar sector that cybersecurity is now a system-level issue. At the same time, it is published by a trade association whose membership includes companies with substantial commercial ties to Chinese manufacturing and platform ecosystems. In that context, it is reasonable to expect the document to focus on broadly acceptable baseline measures and areas of consensus, while some dependency-related or politically sensitive risks associated with China-linked technologies may receive less explicit treatment or be framed in more general terms. For readers, this means it should not be treated as a comprehensive account of all relevant risk factors, but rather as one input that benefits from being complemented by additional independent research and security-focused analysis.Category: Research & Standards
Title: NIST Highlights Smart Inverters as Cybersecurity Focus Area for Grid Resilience
Date: 15 Jul 2024Summary
pv magazine USA reported on ongoing work by the U.S. National Institute of Standards and Technology (NIST) to address cybersecurity risks associated with smart inverters. The article emphasizes that NIST is treating inverter-based resources as an increasingly important element of grid security due to their growing deployment, digital control, and system relevance.Why it matters
This signals that smart inverters are now being formally recognized by a major standards body as security-relevant infrastructure. NIST’s involvement reflects a shift from ad hoc best practices toward structured, standardized approaches to securing inverter-based resources as they become integral to power system stability and resilience.Category: Research & Resilience Tools
Title: SecDER Develops AI Based Intrusion Detection to Protect Virtual Power Plants
Date: 17 Jul 2024Summary
pv magazine Germany reported on the SecDER project, which developed an AI assisted intrusion detection system intended to protect virtual power plants that aggregate many distributed energy resources. The approach monitors communication data between assets and the virtual power plant platform to detect both cyberattacks and technical disturbances, aiming to prevent outages as fleets scale and operational complexity increases.Why it matters
As control and coordination shift toward aggregator platforms and virtual power plants, security increasingly depends on monitoring and defending the communications layer. SecDER reflects an emerging focus on scalable detection methods that can work across heterogeneous inverter and storage fleets where direct device visibility is limited.Category: Vulnerabilities & Technical Exposure
Title: Bitdefender Finds Large-Scale Exposure in China-Linked PV Management Platforms (Solarman, Deye)
Date: 7 Aug 2024Summary
Bitdefender published research describing vulnerabilities in PV monitoring and management ecosystems associated with Solarman and Deye, arguing that the affected platforms coordinate operations for millions of solar installations and therefore represent a fleet-scale control-plane risk. The post claims the exposed ecosystem covers roughly 195 GW of solar output and states that, if exploited, the vulnerabilities could allow attackers to access accounts used to modify inverter-related settings and potentially induce grid-relevant effects. Bitdefender reports the issues were disclosed to the affected vendors and fixed.Why it matters
This is a concrete illustration of why cloud-mediated PV management platforms matter more than individual devices: compromise at the platform or privileged-account layer can create fleet-scale leverage. It is also notable that the exposure is tied to China-linked vendors operating globally. It reinforces the relevance of jurisdiction and supply-chain governance in inverter-heavy energy systems.Category: Vulnerabilities & Technical Exposure
Title: Weak Cryptography in Home Energy System Enabled Control of a Virtual Power Plant (GivEnergy)
Date: 9 Aug 2024Summary
Ars Technica reported on research by Ryan Castellucci showing that a home solar and battery system could be used to gain unauthorized administrative access to GivEnergy’s cloud platform due to an authentication weakness tied to a 512 bit RSA key. With access to the platform, the researcher demonstrated the ability to control charging and discharging behavior across a fleet of grid connected batteries aggregated as a virtual power plant, estimated at around 200 MW of capacity. The report notes that the issue was disclosed to the vendor and a fix was introduced shortly after disclosure.Why it matters
This is a clear example of why virtual power plants and aggregator platforms concentrate risk: compromise at the cloud or privileged access layer can convert many individually marginal devices into fleet scale operational leverage.Category: Commentary
Title: “The Gigantic and Unregulated Power Plants in the Cloud” Argues Solar Inverter Fleets Function as Unregulated Critical Infrastructure
Date: 19 Aug 2024Summary
Bert Hubert published a long-form commentary arguing that large fleets of consumer and commercial solar installations effectively operate as cloud-managed power plants. The article’s central claim is that remote management platforms and vendor cloud control planes can coordinate behavior across millions of inverters, yet are not subject to the kinds of operational oversight, monitoring, certification, and incident accountability applied to traditional large generators. Hubert frames this as a systemic risk to grid stability if cloud platforms were to fail or be compromised, and calls for regulatory attention to remote control and governance of inverter fleet management.Why it matters
This piece has been influential in shaping public discussion by translating technical inverter and platform risk into a governance problem: large fleets can be coordinated through cloud services, but accountability and mandatory security requirements remain uneven. It also highlights a recurring theme across PV security reporting that platform-level compromise can have larger consequences than isolated device hacking.Category: Cyber Activity & Intrusions
Title: Hacktivists Target Solar PV Monitoring Platforms in Lithuania (Ignitis, Sungrow iSolarCloud)
Date: 20 Sep 2024Summary
Cyble reported that the pro Russian hacktivist group “Just Evil” claimed and presented evidence of unauthorized access targeting a solar PV monitoring solution associated with Lithuania’s Ignitis Group. Cyble’s analysis of the shared screenshots assessed the impacted monitoring environment as consistent with Sungrow’s iSolarCloud platform, and noted claims of defacement following access.Why it matters
This case reinforces that adversaries and hacktivists are actively probing and publicizing access to solar monitoring and management platforms, which function as control-plane infrastructure for distributed assets. It is also notable that the implicated ecosystem is linked to a major China-based vendor platform.Category: Vulnerabilities & Technical Exposure
Title: Dutch Researchers Report Vulnerabilities in Enphase IQ Gateway Devices
Date: 5 Sep 2024Summary
pv magazine reported that Dutch security researchers disclosed multiple vulnerabilities affecting Enphase IQ Gateway devices, which act as communications and control gateways for Enphase residential PV systems. The reporting emphasized that gateways sit on the boundary between inverter fleets and cloud management platforms, making weaknesses security-relevant even if individual PV systems are operationally marginal. The researchers stated that the issues were reported to Enphase and addressed through patches and mitigations.Why it matters
Gateway devices are a common control-plane choke point in distributed PV ecosystems. Security weaknesses at this layer can create fleet-scale exposure when combined with cloud-connected management and remote update features.Category: Cyber Activity & Intrusions
Title: Unconfirmed Reports Linked Solar System Explosions to Lebanon Pager Attack
Date: 19 Sep 2024Summary
L’Orient Today reported that Lebanon’s state-run National News Agency (NNA) claimed residential solar energy systems also exploded in several areas of Beirut and southern Lebanon during the second wave of device explosions associated with the Hezbollah pager and radio attack. The article emphasized that these solar-related claims were singular and remained unconfirmed, and cited statements from energy-sector officials and industry sources who said they had not received corroborated reports of solar systems exploding.Source Perspectives
Initial claim: NNA reporting introduced the allegation that solar systems were affected alongside communications devices.
Verification gap: L’Orient Today highlighted lack of independent confirmation and included denials or non-confirmation from sector stakeholders.
Industry pickup: pv magazine later repeated that NNA reported rooftop PV system explosions but noted the lack of detail provided in the initial reporting.Why it matters
Although the claims about exploding solar systems were never independently confirmed, the episode is relevant because it surfaced an underlying technical reality. Inverter-based energy systems are cyber-physical devices that manage high voltages, currents, and thermal limits through firmware-controlled logic. Under certain fault, misuse, or manipulation conditions, failures in power electronics and associated components can escalate into overheating, fire, or equipment damage. There is no evidence that such effects were deliberately induced in this case, but the rapid spread of the narrative illustrates how plausible cyber-physical risk pathways can amplify fear and confusion during crises.Category: Policy & Regulation
Title: Cyber Insurance Requirement for Italy’s “Reddito Energetico Nazionale” Seen as Hard to Source
Date: 24 Sep 2024Summary
pv magazine Italia reported that a cybersecurity insurance requirement linked to Italy’s “Reddito Energetico Nazionale” (REN) support scheme is proving difficult to meet in practice. Higeco and representatives cited in the article said the main issue is not only potential cost increases but the limited availability of suitable cyber insurance products, with brokers reportedly not yet offering standardized coverage due to the lack of consolidated risk profiles for PV-related cyber exposure.Source Perspectives
Industry view: Stakeholders framed the challenge as a market maturity problem, where insurers and brokers lack established models to price and underwrite PV cyber risk consistently.Why it matters
This highlights a growing gap between policy requirements that assume cyber risk can be transferred or managed via insurance and the reality that PV cyber risk remains hard to quantify, underwrite and operationalize, especially for small-scale installations.Category: Policy & Regulation
Title: Dutch Government Acknowledges Cyber Vulnerabilities in Solar Inverters and Points to Upcoming EU Product Cybersecurity Rules
Date: 2 Oct 2024Summary
In a written parliamentary Q&A triggered by reporting that TenneT wants rules for solar “apps” and warned of blackout risk, the Dutch Minister for Climate and Green Growth stated that digitalization of the energy transition is necessary but introduces risks, and that the government recognizes vulnerabilities affecting solar PV installations and inverter-connected systems. The answers identify current weaknesses noting that internet-connected inverters can be manipulated at scale in theory, even if the government assesses the probability as low. The government points to cybersecurity requirements coming into force via the revised Radio Equipment Directive from 1 August 2025 for wireless-connected devices including inverters, and later the Cyber Resilience Act expected from end-2027 for products with digital elements.Why it matters
This is an official acknowledgment that inverter connectivity and remote management create a scalable cyber exposure, and that current safeguards rely heavily on future product regulation and user/installer hygiene rather than existing enforceable requirements today. The “low probability” characterization should not obscure the fact that inverter connectivity introduces a scalable control surface. When probability cannot be confidently bounded and consequences could be system-wide, risk management practice generally prioritizes limiting exposure and improving resilience over reliance on likelihood estimates.Category: Research & Threat Modeling
Title: DEF CON 32 Talk Warns EV and Solar Cloud APIs Create Fleet Scale Grid Security Exposure
Date: Aug 2024Summary
In the DEF CON 32 AppSec Village talk “Gridlock: The Dual Edged Sword of EV and Solar APIs in Grid Security,” Vangelis Stykas argues that the security weak point in modern distributed energy is often not the inverter hardware itself but the cloud platforms and APIs used for installer and fleet management. The talk frames EV charging and PV ecosystems as increasingly interconnected with grid operations and highlights common web and API security failures, that can translate into unauthorized remote control over large numbers of devices.Why it matters
This talk reinforces a recurring theme across inverter security reporting: fleet scale risk is created by privileged cloud and installer access paths. As distributed energy systems scale, weaknesses in platform APIs can convert many individually marginal assets into concentrated operational leverage.Category: Research & Risk Assessment
Title: DERSec Catalogues Public Solar Cyberattacks and Vulnerability Disclosures, Highlights Cloud and Monitoring as Main Exposure
Date: 15 Nov 2024 (report label); last updated 20 Oct 2024Summary
DER Security Corp (DERSec) published a short report compiling a public history of OT relevant solar cybersecurity incidents and vulnerabilities. The scope focuses on attacks and disclosures that could affect PV monitoring or control. The report states it identified four publicly reported cyberattacks on solar systems and 50 vulnerability disclosure events, noting that most issues involve solar monitoring systems and cloud infrastructure, with inverters and gateways also representing a sizable share.Source Perspectives
Incident compilation: Provides a chronological table of public solar cyberattacks and disclosure events and summarizes several recent cases.
Scale framing: Argues that grid impacts become plausible at grand scale when vendor, operator, or aggregator cloud systems are compromised, and repeatedly treats cloud and monitoring platforms as the dominant risk surface.
Regulatory gap: Notes that in the US regulation applies mainly to the largest sites and the gap is filled by voluntary standards and certifications, while pointing to EU frameworks such as NIS2, CRA, and the Network Code on Cybersecurity as more comprehensive.Why it matters
This report consolidates scattered public cases into one reference and reinforces a consistent pattern: most real world exposure sits in monitoring and cloud control planes, while governance is still uneven and often voluntary.Category: Commentary
Title: pv magazine Germany Commentary Warns Cloud Energy Management Often Brings More Drawbacks Than Benefits
Date: 25 Oct 2024Summary
pv magazine Deutschland published an opinion piece arguing that cloud-based home and commercial energy management systems are often adopted for convenience and cost reasons, but can introduce practical downsides and new dependencies. The commentary highlights that relying on vendor cloud services can reduce user and operator control, create availability risk when cloud services fail, and raise concerns around data handling and long-term vendor lock-in.Why it matters
This supports a broader governance argument seen in inverter security discussions: as control and optimization move into the cloud, failure modes and leverage points shift from local hardware to platform operators, making resilience and accountability increasingly dependent on vendor-operated services.Category: Policy & Regulation
Title: Romania Proposes Mandatory Cyber Audits for Solar Power Plants, Including Inverters
Date: 31 Oct 2024Summary
Balkan Green Energy News reported that Romania’s Ministry of Energy drafted an executive order proposing mandatory cybersecurity audits for newly built photovoltaic power plants. The proposal would require periodic cyber audits covering inverters and other IT components in PV systems, with the ministry citing concern that imported equipment could transmit data to third parties without operator consent. The measure was presented as part of broader legal changes intended to strengthen energy security and protect critical infrastructure against digital vulnerabilities.Why it matters
This is a rare example of a Member State moving from general guidance toward mandatory, PV-specific cybersecurity assurance.Category: Research & Risk Assessment
Title: IEA 4E EDNA Report Warns Cybersecurity Risks Are Rising as Connected PV, Batteries, EV Chargers Become Grid-Relevant
Date: Nov 2024Summary
The IEA 4E Technology Collaboration Programme (EDNA platform) published a report on “Cybersecurity for Demand Flexible Appliances,” assessing cyber risks created by rapidly growing fleets of connected devices such as residential PV systems and batteries, EV chargers, and air conditioning. The report argues that grid operators and aggregators increasingly manage millions of network-connected devices and that this digital access creates opportunities for disruption of electricity supply, price impacts, and data theft. The authors emphasize that the risk landscape is complex and evolving, and call for DFA-specific cybersecurity frameworks, improved visibility and control mechanisms, and adaptive regulatory approaches.Why it matters
This is a high-level policy reference that explicitly treats residential PV and batteries as part of a larger class of grid-relevant, internet-connected appliances and frames their cybersecurity as a systemic issue requiring governance.Category: Policy & Regulation
Title: Lithuania Moves to Block Remote Access by China-Linked Inverter Suppliers Through Cybersecurity Legislation
Date: 12 Nov 2024 (law adopted; entered into force 1 May 2025)Summary
PV Tech reported that Lithuania adopted amendments to its Law on Electricity introducing stricter cybersecurity requirements for electricity generation and information management systems, explicitly aimed at limiting influence from countries designated as hostile under Lithuania’s national security strategy. The legislation is designed to prevent manufacturers from such countries, including China, from having remote access to the control systems of solar and wind power plants and larger storage systems, reducing the ability to manage devices and parameters remotely. The measure applies to installations above a defined capacity threshold and is framed as a grid security and critical infrastructure protection step rather than a trade measure.Source Perspectives
National reporting: Lithuania’s public broadcaster LRT described the law as blocking Chinese companies from remote access to control systems for solar, wind, and batteries above 100 kW, with implementation timelines for new and existing systems.
PV Tech framing: links the law to concern over remote access and the distributed nature of PV assets.
Industry follow-up: pv magazine characterized the change as a ban on remote access by manufacturers from national security threat countries, explicitly including China.Why it matters
This the clearest EU example of a Member State translating inverter and platform risk into binding national rules that directly address China-linked remote access as a security issue.Category: Incidents & Control-Plane Risk
Title: Reports of Remote Deactivation of Deye-Branded Inverters in the US Linked to Vendor Dispute
Date: 17 Nov 2024Summary
A Solarboi report described cases where Deye-branded inverters deployed in the United States displayed shutdown messages and ceased normal operation, which the article framed as a remote deactivation event affecting non-authorized units. The reporting connected the event to a commercial dispute and exclusivity claims involving Sol-Ark and Deye, noting that affected devices appeared to be Deye-branded units sold through unauthorized channels rather than Sol-Ark branded inverters. Sol-Ark provided a statement acknowledging the situation and clarifying it does not support Deye-branded inverters, while offering a discounted replacement pathway for households affected by the disablement.Source Perspectives
Initial reporting: Solarboi framed the incident as intentional bricking/disablement of Deye-branded inverters and emphasized consumer impact amid a supplier dispute.
Additional confirmation: heise reported the issue and published statements from both Deye and Sol-Ark, with Sol-Ark emphasizing the affected units were not Sol-Ark branded.
Community documentation: DIY Solar Forum posted Sol-Ark’s response describing a time-limited discounted replacement offer for households whose Deye-branded inverter functions were disabled.Why it matters
This incident is a practical demonstration of vendor-mediated control at the fleet edge: remotely managed inverter ecosystems can be disabled through upstream control mechanisms, even when the trigger is commercial or policy related rather than cyber intrusion. It underscores that remote access and lifecycle control concentrate leverage outside the site boundary, with immediate operational consequences for end users and potential implications for resilience if similar mechanisms were ever activated at larger scale.