Security1 publisher3 min readPublished
GivEnergy's administration leaves a backdoor with nobody left to patch it
Pen Test Partners says the battery maker declined to fix exposed older installs and did not act when the UK regulator asked. On 9 April 2026 it entered administration.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- GivEnergy Ltd entered administration on 9 April 2026.
- GivEnergy Ltd filed a notice of intention to appoint administrators on 7 April 2026.
- Two days elapsed between the notice of intention to appoint administrators and the administration itself.
- In late 2024, Pen Test Partners found multiple vulnerabilities in GivEnergy home battery systems that could allow attackers to access customers' home networks, disrupt battery operation, and potentially violate UK product security regulations.
- GivEnergy updated installer guidance for newer deployments, but older installations may still be exposed, with no clear remediation plan communicated to customers.
Compiled by The WatchSomething wrong?How this is made
Why it matters
GivEnergy Ltd entered administration on 9 April 2026, two days after filing a notice of intention to appoint administrators on 7 April 2026 [1][2][3]. According to Pen Test Partners, which found multiple vulnerabilities in the company's home battery systems in late 2024, that collapse arrives with older installations still exposed and no clear remediation plan communicated to customers [4][5].
The technical story is unglamorous, which is the point. PTP reports that earlier batteries ran a Wi-Fi access point as well as acting as a client, and that some shipped with the pre-shared key set to 12345678 [6][7]. On its own units the key was not default, but the broadcast SSIDs matched the serial numbers printed on the gateway labels, in the form WK12345G67 [8]. Section 8 of GivEnergy's 2024 Wi-Fi dongle installer guide recommended using the inverter serial number as the password [9]. PTP notes the serial is also broadcast in the SSID, and that a query against the public wardriving dataset wigle.net by SSID pattern returns the GPS location of these batteries alongside the key [10][11].
Getting onto the access point was not the end state. A port scan of the gateway found HTTP on 80, Telnet on 23, an API on 8899 and an exposed Modbus TCP interface [12]. PTP's summary is that the deployment created a backdoor onto customer networks and also allowed the battery to be made inoperative [13].
The vendor response is the part worth reading twice. GivEnergy updated installer guidance for newer deployments but, per PTP, refused to address the issue for existing customers [5][14]. PTP also says the company failed to act when the Office for Product Safety and Standards contacted it about a breach of the UK PSTI Act [15]. Then it went insolvent [1].
Most third-party risk programmes have a box for supplier failure, and it is filed under continuity: who answers the phone, who honours the warranty, where do we source replacements. PTP, a customer itself, says the collapse leaves customers wondering exactly that about support and warranty [16]. But the residue here is not a service gap. It is a physical device sitting on a home or small-office LAN, with a documented weak-key pattern, a Telnet listener and a Modbus interface, and now no party with either the code signing keys or the commercial incentive to ship a fix. Vendor viability is usually scored as a financial control. It is a patch-availability control.
The regulatory gap is the same shape. PSTI-style IoT rules work by pointing an enforcement agency at a manufacturer, importer or distributor. That model assumes the target continues to exist. Roughly sixteen months passed between PTP's late-2024 findings and the administration, including a regulator contact that PTP says produced no action [4][1][15][17]. An enforcement notice against a company in administration is not a firmware update.
What to watch: whether the administrators, or any buyer of the assets, accept the outstanding security obligation along with the brand; whether OPSS says anything about how it handles PSTI cases when the duty-holder dissolves; and whether PTP's own self-help guide for non-technical owners remains the only remediation route on offer [18]. For operators, the near-term question is narrower: whether any of this kit is on a network you are responsible for, and whether it is segmented away from everything else.