A passive probe of internet-facing EV charging equipment has counted 1,000 distinct management endpoints across 56 countries, and 720 of them accepted a connection with no transport-layer encryption. Threat intelligence firm Flare ran the scan and published the findings September 1.
The exposure sits in OCPP, the Open Charge Point Protocol that links a charger to its backend management system. The dominant version, OCPP 1.6 from 2015, has no built-in encryption, so traffic carrying authentication tokens, session commands and payment routing can cross the internet unprotected unless operators add VPNs or isolated cellular links.
Flare also found the risk concentrates on a few common platforms. The open-source SteVe management system, an embedded firmware stack without TLS and one commercial platform together account for about a third of the 1,000 endpoints. One vulnerable default setting can propagate across an entire fleet when hundreds of chargers share the same platform.
Past incidents show what that reach enables. Vandalism-style attacks redirected Isle of Wight chargers in 2022, an exposed Shell Recharge cloud database in 2023 spilled nearly a terabyte of logs and customer data, and roughly 116,000 records including VINs and authentication keys surfaced on a deep-web forum in 2024. A March 2026 CISA advisory described critical flaws in the Everon OCPP backend that could let attackers impersonate chargers and hijack sessions.
Flare’s prescriptions are familiar: move to OCPP 2.0.1 or newer with certificates, or VPNs for legacy hardware; pull management interfaces off the public internet; inventory charger platforms and firmware; remove default credentials; segment charging networks from business and payment systems; and monitor exposure passively. Adoption stalls because legacy OCPP 1.6 hardware keeps earning money and no single player owns the problem across the fragmented charger ecosystem.