News

Report: Hack-a-wind-farm 1.0 event at TU Delft on June 2026

Overview

On 18 June 2026, the DCSC Laboratory at TU Delft hosted the first edition of the “Hack a Wind Farm v1.0” hackathon, focused on Operational Technology (OT) cybersecurity in the wind energy sector.

During this hands-on event, 16 selected participants from academia and industry worked with the Industrial Control System of a virtual offshore wind farm and explored cybersecurity challenges in a realistic energy systems environment.

The hackathon, which was supported by the EU projects TWAIN and SUDOCO, awarded the best teams that demonstrated the most creative, most disruptive and most technical exploits.

Background

Critical infrastructures such as offshore wind farms are increasingly exposed to cyberattacks that can disrupt energy supply, damage equipment, and threaten public safety. In recent years, operational technology (OT) and industrial control systems (ICS)—including SCADA networks, turbine controllers, and other grid devices—have moved from being theoretically at risk to frequently being targets of ransomware and state-sponsored attack campaigns. Recent examples include the shutdown for four days of a small power generator in the UK, and several state-sponsored attacks to energy and water treatment sites in Poland, Ukraine, Israel and the US.

Wind farms are an especially sensitive target for geo-political reasons, especially in countries where they account for a large portion of the energy generation mix.

Researchers in the Fault Tolerant Control group at TUD, being part of the two European Horizon projects TWAIN and SUDOCO, are actively involved in progressing the state-of-the-art of the research on safe, secure and resilient control of wind farms.

Technical description

TUD researchers created a testbed based on the hardware and software of an actual wind farm Industrial Control System (ICS), including functionalities such as Level 1 controllers, and SCADA functionalities such as a Human Machine Interface (HMI), a Data Historian and a Level 2 supervisory controller. The standard communication protocol IEC 61850 was used. The ICS was connected to a virtualized wind farm, implemented using customized digital twin models running on a real-time simulator. Such models accounted for each wind turbine dynamics and for the interaction of the wind field with each turbine. In this way, also so-called “waked” conditions, where one turbine operates in the low velocity, turbulent wake generated by an upstream turbine, can be simulated in real-time.

Participants were given the opportunity to use an API developed by TUD to easily implement eavesdropping and man-in-the-middle attacks or could directly craft their own attacks in case they wanted. The attacks were evaluated on the capability of causing economic and physical damage to the wind farm, for instance by reducing the amount of power produced or increasing the amount of mechanical stress on the turbines. A requirement was for the attack not to trigger any of the standard anomaly detection algorithms implemented in the SCADA, while the capability of reaching the attacker’s goal by compromising the least amount of SCADA resources was positively taken into consideration.

A jury of TUD researchers evaluated the participating teams along these metrics, and then assigned three awards for the most creative, most destructive and most technical exploit.

Academic and societal significance

The participation by students, external researchers and industrial practitioners was an opportunity to raise awareness on the cyber security risks for Critical Infrastructures such as wind farms. It further allowed cybersecurity experts to hone their skill on an IT/OT setup that is unique, and allowed TUD researcher to evaluate which kind of attacks may be carried out and can bypass standard, industrial grade detection algorithms.

The testbed will be further extended to host similar events in the future, and will be actively used by TUD researchers to test novel attack detection algorithms that are harder to be bypassed, as well as autonomous defense and reconfiguration functionalities for Industrial Control Systems.