A security vulnerability at the Chinese inverter and storage manufacturer Sungrow exposed around 250,000 solar installations in Germany to unauthorized access. The flaw was discovered in late August 2026 by Marlon Starkloff, Managing Director of the Kassel-based IT security firm Jakkaru. While testing Sungrow’s iSolarCloud platform, he managed to gain access to administrative accounts without a valid password. These accounts provided privileges sufficient to start and stop solar installations, control battery storage systems, and install new firmware. Collectively, the German installations have a peak capacity of approximately 7.8 gigawatts. Consequently, during periods of high solar output, a coordinated hacker attack could have abruptly disconnected several gigawatts of generation from the grid. In a worst-case scenario, this could have led to frequency disturbances and automatic power outages. According to the company, Sungrow found no evidence of misuse; the manufacturer promptly patched the vulnerability.

Image: Shutterstock
Sungrow consolidated the control of thousands of systems into a cloud platform
Inverters serve as the interface between solar panels and the power grid. They convert direct current into grid-compatible alternating current, while modern units simultaneously communicate with manufacturers’ platforms. Sungrow uses the iSolarCloud for this purpose, allowing operators and installers to monitor and manage their systems. However, this setup grants a central IT platform access to a vast number of distributed power generation units.
This is precisely where Starkloff focused his efforts. The login process transmitted a parameter indicating the login type alongside the username and password. According to Jakkaru, if the researchers set this value to five, the system ignored the entered password and logged them in directly. Furthermore, the platform issued no alert regarding the unauthorized login. By leveraging hierarchically linked accounts and additional information, the researchers ultimately gained access to Sungrow’s administrative level.
7.8 gigawatts of peak capacity in Germany were accessible
According to Jakkaru, these privileges allowed for the management of an entire region’s system infrastructure. Administrators could list, modify, start, or stop systems. Furthermore, it was possible to control battery storage units and upload custom firmware to cloud-connected devices. However, the researchers did not execute such commands on actual third-party systems. Consequently, while the potential for technical access was demonstrated, an actual mass outage was not triggered.
In Germany, approximately 250,000 Sungrow systems—with a combined installed peak capacity of 7.8 gigawatts—were affected. However, this capacity is not available at all times. Solar systems generate virtually no electricity at night, and cloud cover also reduces their power feed-in. On a sunny midday, however, a simultaneous shutdown could have impacted several gigawatts of generation. This places the security vulnerability on a scale far exceeding that of a typical IT incident.
A coordinated outage would have strained the European power grid
The Continental European synchronous grid maintains a frequency-stabilization reserve of around three gigawatts to handle sudden power imbalances. The 7.8 gigawatts of German Sungrow systems represent more than two and a half times that amount. However, this does not automatically result in a blackout. Germany is part of a synchronously coupled European grid, meaning that reserves and power plants across national borders respond to any drop in frequency.
Nevertheless, a sufficiently large and rapid loss of generation would have significant consequences. If the grid frequency drops significantly below 50 hertz, grid operators first activate automatic reserves, followed by additional ones. If stabilization efforts prove insufficient, automatic load shedding begins within the Continental European grid at 49 hertz. At that point, at least five percent of the national load must be disconnected from the grid. For the affected households and businesses, this translates into an actual power outage. The Sungrow case therefore highlights a structural problem: hundreds of thousands of decentralized power generators can be aggregated via a central cloud into a single digital target for attack.
Author: Blackout-News
Sources: Jakkaru (07.10.26) – ZfK (07.10.26) – Cleanthinking (07.10.26)
