Commercial operators with significant financial investments in EV charging stations understand their value.
Not only are they power assets, they are part of a modern technology infrastructure composed of interconnected and networked pieces that create a complex – and widening – cyberattack surface. Given the fact that EV charging stations have built-in payment terminals and are connected to cloud services to help manage smart charging and load balancing for the local grid, it’s easy to see why bad actors would be interested in attacking them.
A cyber threat to their charging deployments is also a financial risk to be addressed.
A compromised EV charging station is not simply a piece of damaged equipment. Especially as they are now being deployed at scale, it’s important to recognize the robust amount of information and assets that could be accessed through them. In March of this year, ELECQ experienced a ransomware attack that resulted in stolen consumer data stored on AWS cloud systems. In this instance, financial information was not taken and the EV charging hardware remained fully operational, but it doesn’t take much imagination to see how the outcome might have been different.
Supply chain with multiple points of entry
Attackers are looking at EV charging stations for more reasons than the rapid deployment and access to lucrative information.
Charging stations have a deep supply chain, which includes everything from specialized hardware components and electrical grid infrastructure to cloud software platforms. Because there are so many different types of technology involved, the opportunity to successfully access one of them undetected is higher. And this isn’t a hypothetical case.
In 2024, we saw an unsecured third-party EV charging app that was digitally connected to Tesla charging stations hacked. In this instance, the hacker exposed 116,000 customer records that contained sensitive information like payment card details, as well as personally identifiable information like car make and model and geographical location of where the vehicles had been charged.
It’s critical that operators have visibility into what their assets are connected to, as well as the software versions they are running and who has access to them. Beyond this, it’s important to understand when responsibility changes hands. For example, an EV charger may sit in one physical location, but the software, payment functions and remote maintenance might be controlled by three different companies in various locations, each of which might be covered by different compliance requirements.
Following a framework such as the NIST Cybersecurity Framework Profile for Electric Vehicle Extreme Fast (EX/XFC) Charging infrastructure, which is detailed in NIST IR 8473, is a good starting point for operators because it highlights that cybersecurity is not tied only to a single device or vendor.
Operational demands complicate security
Because EV charging stations are increasingly considered critical infrastructure, they are required to maintain operational functionality. Cybersecurity policies that generate frequent false alarms, block legitimate charging or require long investigation windows can cause operational downtime.
In an effort to keep things charging smoothly, personnel might create “workarounds” that are well-intentioned, but introduce further risk. For example, if a charger is isolated because a cybersecurity tool identified a possible issue, but staff need it to help charge a fleet, it’s not a stretch to imagine that staff might reintroduce it to the network before the threat is fully investigated. Doing so would be for a good reason and for only a short period, but could open up a pathway for malicious behavior.
Additionally, EV charging stations are at the edge of commercial deployments. The physical charger is in one location but the internal technology connects back to a central data center or cloud platform. Often, this physical distance can make it difficult for commercial operators to gain visibility into what is happening at the physical location. For example, a critical file change or an unauthorized process might be missed if operators only see part of what is happening with the charger itself.
Human workarounds and edge security introduce legitimate security risks that operators must understand in order to protect their assets and understand the financial impact associated with them.
Understanding the financial impact
If operators don’t understand how their charging fleets are performing, they don’t understand the underlying financial impact to their business.
Yes, if a charger is breached and lets in a malicious threat like ransomware, there are hard financial decisions to consider. According to IBM’s Cost of a Data Breach Report 2025, the average cost of a cyber breach in the U.S. is $10.22 million. This includes identification, containment and reputational harm, but not necessarily a ransomware payment if a business decides to pay.
But beyond this, what is the revenue loss to your organization if a charger goes down? Consumers prioritize dependable access over lower cost, so taking a charging station offline where it’s needed can have a sizable impact on the bottom line.
Prioritize the risks that matter most
Operators cannot protect every one of their EV chargers entirely. What they can do is identify their risk threshold and decide what they can tolerate and what they can’t. That’s why gaining visibility into the cyber performance of their entire deployment fleet is critical.
For example, an operator might decide that a weakness affecting a lightly used charger in an area that has a lot of competition will have a different impact to her business than one that could take down an entire fleet or interrupt payment processing across a number of different locations.
The connection between financial risk and cyber risk will mirror the growth of EV charging infrastructure. Operators who have visibility into security weaknesses at stations that have the greatest impact to the business are the ones who have the freedom to make the smartest decisions about their operations.