Wind

Researchers identify cybersecurity risks from compromised offshore wind sensors and converter stations

By Daniel Garcia · September 25, 2026 · 4:40 PM · 5 min read
Researchers identify cybersecurity risks from compromised offshore wind sensors and converter stations

Offshore wind farms are among the most promising tools in the shift away from fossil fuels — but a team of researchers from Concordia University and Hydro-Québec is raising an uncomfortable question about what that promise may be quietly carrying with it.

Operating dozens of kilometers from shore, these farms run almost entirely on remote connections — coordinating with onshore grids, maintenance vessels, and inspection drones through layered communication networks. That connectivity is what makes them efficient. It may also be what makes them dangerous.

A clean-energy success story with an overlooked weak point

Offshore wind has grown into one of the most cost-effective renewable energy options available. Governments and utilities are betting heavily on it, and VSC-HVDC technology — voltage-source-converter high-voltage direct-current connections — has become the dominant method for moving that power from sea to shore. These systems are efficient, scalable, and increasingly central to national energy strategies.

Automated systems capable of recognizing unusual data patterns in real time may eventually provide a layer of defense that human monitoring alone can’t match.

Efficiency, though, comes with complexity. A single offshore wind farm must coordinate with onshore grid operators, maintenance vessels, inspection drones, and neighboring turbines — all through layered digital networks. That web of connections creates what researchers call a broad attack surface. Researchers from Concordia University and Hydro-Québec brought this concern to the 2023 IEEE SmartGridComm conference in Glasgow, presenting findings that challenge a quiet assumption: that cleaner energy is automatically safer energy.

How a cyberattack could cascade from a wind farm to the main grid

The attack scenario the researchers describe is precise. An attacker who gains access to the local area network of a converter station could quietly tamper with sensor data, swapping real readings for false ones. The control systems, seeing nothing unusual, would respond to information that doesn’t reflect reality.

Those false signals create electrical disturbances at the points of common coupling — the junctions where a wind farm feeds power into the broader grid. Isolated disturbances may be manageable on their own. The danger multiplies when farms are running at full output and the disturbances repeat at just the right frequency, amplifying poorly dampened power oscillations that don’t stay offshore. They travel through the HVDC system and can reach the main power grid, threatening stability far beyond the farm itself. The attacker never needs to touch a turbine blade.

Why offshore farms are harder to defend than onshore ones

Distance is part of the problem. Offshore farms operate dozens of kilometers from land, with no on-site staff to notice something is wrong. Everything runs through remote connections — wide-area networks linking the farm to onshore control centers, and local networks coordinating turbines, drones, and vessels with each other.

That hybrid architecture creates multiple entry points. Each communication link is a potential door, and the redundancy systems built into these networks weren’t designed with malicious actors in mind. They handle physical failures — a router going down, a signal degrading over distance — not an attacker deliberately feeding false data into the system. As Concordia’s Jun Yan put it, “If there is an attacker in the middle who is trying to hijack the signals, then that becomes more concerning.” A man-in-the-middle attack is fundamentally harder to detect than equipment failure because, from the system’s perspective, everything appears to be functioning normally.

Regulation lags far behind the technology

The technology has moved faster than the rules governing it. Current regulatory standards in both the US and Canada identify what needs to be protected but leave the question of how largely unanswered. That gap gives operators flexibility — and it also means there’s no consistent baseline for what “secure enough” actually looks like.

The industry gap runs deeper than regulation. Yan notes that many manufacturers and utilities concentrate their security efforts on corporate systems — data access controls, network perimeters — while operational technology, the systems that actually run the turbines and manage power flows, receives far less attention. Concordia is pushing for international standardization, but the researchers are candid that this work is early-stage. The study is part of a broader collaboration involving Concordia, Hydro-Québec, and Hitachi, with support from NSERC and PROMPT — a coalition that signals the problem is being taken seriously, even if solutions remain incomplete.

What needs to happen next

The clearest recommendation from the research is also the most structural: cybersecurity needs to be built into offshore wind infrastructure from the beginning, not patched in after the fact. Retrofitting security onto complex operational systems is harder, costlier, and less effective than designing it in at the start.

Doing that requires coordination across groups that don’t always work closely together — grid operators, turbine manufacturers, national regulators. Each controls a different piece of the system, and gaps tend to form at the boundaries between them.

Yan’s own research focus — AI-driven threat detection — points toward one potential tool for identifying anomalies before they escalate. Automated systems capable of recognizing unusual data patterns in real time may eventually provide a layer of defense that human monitoring alone can’t match.

The urgency is real. As electrification accelerates and more offshore capacity comes online, the window to establish robust, standardized protections is narrowing. The farms being built today will operate for decades, and the security decisions made now — or deferred — will shape how exposed those systems remain for years to come.

You can check more about this study here: Juanwei Chen, Hang Du, Jun Yan, Rawad Zgheib, Mourad Debabbi. A Data Integrity Attack Targeting VSC-HVDC-Connected Offshore Wind Farms. 2023 IEEE International Conference on Communications, Control, and Computing Technologies for Smart Grids (SmartGridComm), 2024 DOI: 10.1109/SmartGridComm57358.2023.10333872

Author Profile
Chief Editor

Daniel García is an Editor-in-Chief with strong expertise in structural work and engineering principles. He combines this technical foundation with deep knowledge of energy, spatial design, and emerging technologies, bringing a forward-thinking and analytical approach to editorial leadership.

Daniel Garcia
Daniel Garcia

Daniel García is an Editor-in-Chief with strong expertise in structural work and engineering principles. He combines this technical foundation with deep knowledge of energy, spatial design, and emerging technologies, bringing a forward-thinking and analytical approach to editorial leadership.

Daniel Garcia

Daniel García is an Editor-in-Chief with strong expertise in structural work and engineering principles. He combines this technical foundation with deep knowledge of energy, spatial design, and emerging technologies, bringing a forward-thinking and analytical approach to editorial leadership.