In April 2022, four charge points run by the council on Britain's Isle of Wight stopped charging. Anyone who pulled up got no power, just a porn site on the screen. No brilliant break-in was needed. Someone had simply redirected the web address the units displayed. The chargers themselves did nothing wrong. They dutifully showed what they were told to.
That is the uncomfortable starting point for any honest conversation about charging fraud. The attacks that make the news sound spectacular. The fraud that actually costs money is usually dull, cheap and surprisingly simple.
The headlines are hard, the fraud is not
In early 2026, security researchers gathered in Tokyo for Pwn2Own Automotive. One team took full control of an Alpitronic fast charger through the charging cable itself, the first public exploit of a supercharger. Six months earlier, a widely sold DC charger turned out to hand a root shell to anyone who plugged in their car, because admin services were accidentally exposed on the charging connector. Impressive, and rightly big news.
But attacks like that need the right vulnerable hardware, physical access and weeks of work. They are rare. The fraud that truly hits operators sits one level down, in the everyday. It needs no exploit. It needs a sticker, a cheap gadget, or simply patience.
Five minutes and a sticker
The easiest fraud of all requires zero technical skill. You stick a fake QR code over the real one on a charger. Whoever scans it lands on a counterfeit payment page that swallows their card details. Such stickers have been reported in Belgium, the Netherlands, the United Kingdom and beyond. Researchers suspect some fraudsters use a jammer so the charging app fails and the driver is forced to scan the QR instead.
The driver loses money. But the operator loses something slower to rebuild: trust. And the chargebacks land on them.
The card that is not a lock
A charge card feels like a key but behaves like a name tag. Most RFID cards use a chip whose security has been broken for twenty years. With a thirty-euro device you copy one in minutes. In practice the damage from cloning is limited, for a dull reason: you are physically stuck at the charger while charging on a cloned card, which makes getting caught likely. But the lesson stands. The card does not prove who you are.
The kilowatt hours nobody counts
The quietest fraud leaves no sticker and no cloned card. It lives in the numbers. A meter reading that dips back during the session, so fewer kWh are billed than delivered. A session that starts but whose settlement never arrives. A tariff on the screen that differs from what is charged. None of these looks suspicious on an invoice, because the invoice is exactly where the manipulation hides.
Why it is so easy
All of this grows in the same soil. Many chargers talk to their management platform in plain text, over an unencrypted connection, with an access key that simply sits in the web address, and without the charger having to prove itself with a certificate. We recently measured this ourselves on a test charger: the connection came up without a single form of authentication. That means the charger's credentials travel across the internet in the clear. Whoever is listening reads everything.
What you can actually see
This is where the story turns. You rarely catch the break-in. But you catch the consequence. The energy leaking away, the session being hijacked, the price that does not match. That consequence leaves traces in the OCPP traffic between charger and platform and in the billing, and at most operators nobody is watching that traffic today.
That is exactly where Proxilink sits. A second device trying to identify as your charger, the classic sign of hijacking. The same card appearing on two chargers at once, or too soon after one another to have driven between them, the trace of a cloned or shared card. QR sessions collapsing on a charger while the charger keeps charging normally, which can point to a fake sticker. A paid session whose books never close. Meter readings that jump backwards. A billed tariff that deviates from what you set. Firmware that quietly changed version. Nine detection lines, and they run every night.
The framing that holds is not that nothing can ever go wrong. It is that you know the same day when something did.
And what we deliberately do not see
Honesty belongs in this story, because the opposite promise is more dangerous than the fraud. A charger taken over at the hardware level sends perfectly normal OCPP. We see none of it, and nobody at this layer does. A relay attack on Plug and Charge plays out below the protocol we read. A jammer or a physical skimmer sits entirely outside our view. We do not sell device security. We sell integrity: we do not see the break-in, we see the money leaving.
The road to a hundred percent
So what is still needed to close the gap completely? The platform layer we can seal today. The device layer is waiting on technology that is coming, and on standards that still have to mature.
It starts with the connection itself. The new generation of the charging standard, ISO 15118-20, makes TLS encryption mandatory between vehicle and charger. That removes the soil under eavesdropping and under a range of man-in-the-middle attacks that are possible today because the older norm encrypts nothing. It arrives with new vehicles and new chargers, and it takes years to reach the whole fleet.
Plug and Charge, the convenience where your car identifies itself without a card or app, has a certificate problem that must be solved first. Research showed that today one certificate from one charger is enough to impersonate any other charger. Before that convenience can truly be trusted, the underlying certificate system has to mature or be replaced.
Alongside that, signed, tamper-evident metering is needed, meter values that cannot be quietly edited, in the direction Germany's Eichrecht rules already require. And on the charger itself, secure boot and hardware attestation are needed, so a charger can prove it runs untampered firmware. That last piece is what would finally let us answer whether a charger is compromised, instead of only whether it runs a patched version.
And there is a piece we hold ourselves. When a charger's OCPP traffic runs through our proxy, we see every message in real time, not just the billing aftermath the next morning. That is what lifts detection from forensic to live. As that fork becomes the standard on every connection, our view shifts from after the fact to the moment itself.
Lay those pieces on top of each other, encryption on the wire, a trustworthy Plug and Charge, signed meters, chargers that prove their own integrity, and a platform reading every frame live, and you approach a charger you can trust end to end. That is what we are building toward, one detection line at a time.
Until then, the most valuable thing is not the promise that nothing will go wrong. It is that you notice on the day it happens, and not three months later on your statement.
Frequently asked questions
How easy is it really to defraud a charging station?
Easier than most operators think, but not in the way of the headlines. The spectacular hardware hacks need specific vulnerable devices, physical access and weeks of work, and are rare. The fraud that actually costs money is low-skill: a fake QR sticker over the real one, an RFID card cloned in minutes, a meter reading quietly altered, or a session that starts but never settles.
What does Proxilink detect?
Proxilink watches the OCPP and billing traffic and catches the consequence of fraud: a second device impersonating your charger, the same card appearing on two chargers when it physically cannot, QR traffic collapsing while the charger keeps working, paid sessions without settlement, meter readings jumping backwards, tariffs deviating from what you set, and firmware that quietly changed version. Nine detection lines, every night.
What can Proxilink not detect?
Device compromise. A charger taken over at the hardware level sends perfectly normal OCPP, and nobody at that layer sees it. A relay attack on Plug and Charge, a physical skimmer or a jammer also sit outside our view. Proxilink sells integrity at the platform level, not device security.
What technology is still needed for a complete solution?
Mandatory TLS encryption between car and charger via ISO 15118-20, a mature certificate system for Plug and Charge, signed and tamper-evident metering in the direction of Eichrecht, and secure boot with hardware attestation on the charger itself. Together with a platform that reads every frame live through the fork, that approaches a charger you can trust end to end.