Public EV Charger Fraud Has a Cost Now. Here's What It Actually Takes to Catch It

A cloned-RFID scheme cost a Dutch operator over 200,000 euros before anyone caught it. Not a hack, a gap in what got checked. Why catching this needs a system watching your whole network every night, not a checklist.

Want to know if this kind of fraud is already happening on your chargers? See how Proxilink checks for it across your whole network, every night. See revenue protection Nine detection lines · one overview · every night

A Dutch shared-mobility operator spent part of 2025 discovering that cloned RFID cards were generating fraudulent charging costs into the thousands of euros a month before anyone caught it. A separate case in the Netherlands, cited as a warning sign for the wider industry, put the damage from a single RFID fraud scheme at over 200,000 euros. Neither needed a supercharger exploit or a zero-day. They needed a cheap card reader and an operator who was not watching.

That is the pattern worth sitting with. Most public charging fraud is not a hacking story. It is a visibility story: the signal that would catch it exists in data operators already generate, but almost nobody is actually watching across the whole estate, every night, for it.

That distinction matters, because it changes what catching this requires. Not a smarter card, not a smarter sticker. A system that looks at every session, on every charger, continuously, and flags the pattern the moment it appears. Here is what that pattern looks like for the fraud types operators keep running into, and why it is the kind of check that has to run on top of a billing system rather than live inside one person's weekly routine.

RFID cloning: the tell only shows up at estate level

RFID cards were never designed as a strong identity layer, and the cloning tools are cheap and widely available. You are not going to out-engineer that at the card level alone. What cloning does leave behind is a pattern: the same card ID appearing on two chargers at once, or starting a second session somewhere else too soon after the first one to be physically possible. That overlap is the tell. But it only shows up if something is cross-checking every card against every charger, every session, continuously, across the entire network. A person spot-checking invoices once a month will never see it. It has to be a standing check, running in the background, on all of it at once.

Fake QR stickers: the signal is aggregate, not visual

Fraudulent QR stickers placed over legitimate ones have been reported on public chargers in Belgium, the Netherlands, the United Kingdom, France, Spain and Italy. The mechanic is simple: a fake code sends the driver to a lookalike payment page, while the charger itself does nothing wrong. That is exactly the problem: there is nothing in the charger's own data to flag. What does show up, if you are tracking it, is the pattern at location level: a sudden, unexplained drop in successful QR-initiated sessions at one specific charger, out of step with the rest of the network. That is not something a driver complaint tells you in time. It is something a system comparing session volume across the whole estate, hour by hour, can flag before the complaints start.

Billing gaps: invisible unless something reconciles it nightly

The quietest fraud never touches a card or a QR code. It is a meter reading that regresses mid-session, a session that starts but never produces a settled charge detail record, or a tariff that does not match what the screen showed. None of this looks suspicious on an invoice, because the invoice is where the manipulation hides. Catching it means reconciling the tariff you planned against what actually got billed, every session, every day, not at month-end close when the trail has gone cold. That is a lot of continuous cross-referencing between pricing configuration, meter data and settled charges for one person to keep up with by hand across more than a handful of chargers.

The transport layer: the exposure, not the fix, is the hard part to see

A meaningful share of public chargers still talk to their management platform over plain, unencrypted connections, with an access key sitting openly in the URL and no certificate requirement on the charger's side. That is not fraud by itself, but it is the soil the rest grows in: anyone intercepting that traffic reads the charger's credentials in the clear. Fixing a single charger's configuration is usually straightforward. Knowing which chargers in a mixed, multi-vendor, multi-generation estate are still exposed like this, without checking each one by hand, is the part that actually takes tooling.

Why this ends up being infrastructure, not a checklist

The common thread across all four is that none of them are caught by looking harder once. They are caught by something that looks every night, across every charger, and hands a person a short list of exactly what is off instead of a haystack of raw session data. Operators who only look at this after a chargeback or a customer complaint are, by definition, finding out too late to prevent anything. Building that continuous, network-wide layer yourself means building session reconciliation, card-overlap detection, QR anomaly tracking and firmware and configuration visibility as a standing internal tool, on top of running the network itself. Most operators reasonably do not want that as a side project.

It is also worth being honest about the ceiling. None of the above catches a charger that has been compromised at the hardware level, that kind of attack sends completely normal-looking data. What continuous reconciliation catches is the fraud that actually costs most operators money today: cloned cards, fake stickers, and numbers that quietly do not add up. That is a narrower promise than "total security," and it is also the one that is actually deliverable.

Frequently asked questions

How expensive can charging fraud actually get for an operator?

More than you would expect from something that starts with a cheap gadget. A Dutch case involving cloned RFID cards ran up over 200,000 euros in damage before it was caught, and a separate Dutch operator saw fraudulent charging costs running into the thousands of euros a month before real-time controls were introduced. Neither needed sophisticated technology, just the absence of a daily check.

Why is a cloned card so hard to spot on an invoice?

Because the session looks entirely normal: a valid card, a normal amount of kWh, a normal settlement. The only thing that gives it away is the comparison with other sessions on the same card: the same card on two chargers at once, or a second session too soon after the first to be physically possible. That comparison only happens if something is checking every session against every charger.

What makes fake QR stickers hard to detect?

The charger itself does nothing wrong, so there is nothing incriminating in its own data. The signal is in the comparison: a sudden, unexplained drop in successful QR sessions at one specific charger while the rest of the network keeps running normally. You only see that if you are comparing session volumes across locations, not looking at one charger in isolation.

Why isn't a manual check enough?

Because the patterns that give fraud away only become visible at the level of the whole network, every day: card overlap, session volume by location, tariff versus actual billing. Keeping that up by hand across more than a handful of chargers is not sustainable for one person. That is why this ends up being infrastructure rather than a checklist you tick off once.

Back to blog Book a demo