ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

EV charge points could become a cyber-security attack surface unless the industry acts now

Electric vehicle (EV) charging infrastructure has rapidly expanded in recent years to support surging EV adoption. Hundreds of thousands of public charge points are now easily accessible across Europe; the UK doubled its chargers from under 30,000 at the end of 2021 to nearly 77,000 by early 2025 ; and in the United States, networks are growing by approximately 19% year-on-year. 

 

But while attention is given to charging capacity, speed and convenience, there is an elephant in the room – what happens if a network of chargers come under the control of cyber-criminals and could it impact electric grids?

 

Concerned about potential exposure to threat, we recently conducted passive discovery research of internet-facing EV charging infrastructure and identified 1,000 distinct Open Charge Point Protocol (OCPP) endpoints across 56 countries. Of these, 720 accepted connections without transport-layer encryption. To be clear, most UK electric vehicle chargers use the OCPP, a standard way to connect hardware to backend management. 

 

Charging infrastructure that is reachable over the internet and communicating without adequate protection should concern everyone involved in the charging ecosystem, particularly EV drivers.

 

Charging infrastructure without encryption

OCPP enables the communication between chargers and charge point management systems, carrying authentication tokens, session commands and, in many deployments, the route to payment and backend systems. But the dominant version of the protocol, OCPP 1.6, was released in 2015 and does not have built-in encryption, meaning that without measures such as VPNs or isolated cellular connections, data is being transmitted without any protection. 

 

Perhaps more concerning than the sheer number of exposed endpoints is the concentration around a relatively small number of software platforms. Flare found that three platforms—the open source SteVe management system, a common embedded firmware stack without Transport Layer Security (TLS), and a commercial platform—accounted for approximately one third of the 1,000 endpoints it identified.

 

If an individual charger has a security weakness, the consequences may be limited to that device. But when the same software or firmware is deployed repeatedly across hundreds of chargers, a vulnerability or insecure default can propagate throughout an entire network. Common platforms introduce efficiency and scalability but they also introduce risk. 

 

The threat is not hypothetical

In fact, researchers and attackers have already demonstrated that vulnerabilities in charging infrastructure can have consequences. 

 

Most visible have been nuisance attacks, such as in 2022 when chargers operated by a local authority on the Isle of Wight were redirected to display pornography instead of the council’s website. On the surface this was offensive but not dangerous, but it demonstrates that connected charging infrastructure is already being accessed in ways its operators did not intend.

 

The consequences are more serious when the information behind the chargers is the focus. In 2023, an unprotected cloud database associated with Shell Recharge was discovered containing almost a terabyte of charging-network logging data. Flare research showed that the information included customer names, email addresses and telephone numbers, as well as charging-station locations, including private residential points. Similarly in 2024, around 116,000 records surfaced on a deep-web forum. The data reportedly included names, addresses, vehicle identification numbers, authentication keys and tokens, and precise charging-station locations.

 

The next level relates to control of the hardware. In March 2026, a Cyber-security and Infrastructure Security Agency advisory in the USA documented critical vulnerabilities in the Everon OCPP backend. These flaws could allow remote attackers to issue OCPP commands while impersonating a legitimate charger, hijack sessions and potentially escalate their access.

 

Finding a solution

Which takes us back to the question of how networks of chargers could come under the control of a bad actor. Could this mean that large numbers of chargers could be switched on or off in coordination, creating a mechanism for influencing electrical demand?

 

While our research does not demonstrate this capability, it does show that a significant number of charging endpoints are internet-reachable and poorly protected, based on platforms that prioritise function over security.

 

In terms of securing EV charging infrastructure there are six priority controls that should be put in place. Operators and enterprise teams should encrypt all charger connections, using OCPP 2.0.1+ with certificates or VPNs for legacy systems; remove management interfaces from the public internet; maintain accurate inventories of CSMS platforms and firmware; eliminate default credentials and identifiers, enforcing proper authentication; segment chargers from business, payment and building-control networks to limit attack impact; and continuously monitor exposure using passive sources such as device-search indexes, certificate transparency and passive DNS. 

 

Security assessments should cover the entire charging chain – charger, communications link and backend – to identify vulnerabilities and prevent attacks crossing system boundaries.

 

But it’s not that simple. Replacing hardware is costly, creates operational disruption and may introduce compatibility problems. Meanwhile, OCPP 1.6 continues to work commercially which creates a fundamental incentive problem. An operator can continue charging customers using an older system. Moving to a more secure architecture requires investment but the benefit is largely invisible unless something goes wrong. 

 

Responsibility is divided among charger manufacturers, charging point operators, software providers and government agencies, meaning that everyone has a stake in security, but no single organisation owns the entire problem.

 

Security cannot remain an afterthought

This is not a tale about one vulnerable charger, one negligent operator or one sophisticated cyber-attack. It is about an infrastructure ecosystem in which insecure configurations, legacy protocols and common software platforms can be replicated across large numbers of connected devices, leaving the door open for a cyber-attack, at worse on our electricity grids.

 

As EV charging becomes an increasingly important part of the transport and energy landscape, the industry needs to decide whether cyber-security will be treated as an essential characteristic of the infrastructure, or as something to address after the next vulnerability is discovered and the damage is done.

 


 

Adrian Cheek is Senior Cybercrime Researcher at Flare

 

Mainn image courtesy of iStockPhoto.com and SimonSkafar


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543