The short answer

Yes. Low-frequency 125 kHz proximity cards, including HID ProxCard II and ISOProx, Indala, EM4100 and their many compatibles, send a fixed ID number with no encryption and no authentication. Any reader that powers the card can read that number, and a writable blank card can be programmed with it. The reader on your door cannot tell the copy from the original.

The tools are not specialist. Handheld cloners are sold openly online, and researchers have demonstrated modified long-range readers that capture a prox card from a few feet away, from inside a bag, in an elevator or in line at the coffee shop.

Why this is still a live problem

Most organizations know prox is old. The exposure usually survives because of how migrations are done:

  • New secure cards are issued, but the readers are multi-technology and still accept the old 125 kHz cards too. The old credential keeps working at every door until someone switches that off.
  • One site migrated and another did not, and both share a cardholder database.
  • Visitor, contractor and "spare" badges were never reissued, so the drawer at reception is still full of prox cards.
  • Parking, elevators and secondary doors run on a separate controller nobody included in the project.

A migration only reduces risk once the old technology is turned off at the reader. Until then you have added a second way in, not replaced the first.

How to tell what your office uses

  • Look at the card. Many are printed with the product name, such as "HID ProxCard II" or "ISOProx".
  • Try a phone. Phone NFC works at 13.56 MHz and cannot see a 125 kHz card at all. If your phone does not react to the badge, it is probably low frequency. (If it does react, that does not make it secure; see the MIFARE Classic vs DESFire vs Seos guide.)
  • Ask your access control integrator for two things in writing: the reader models installed at each door, and which credential technologies each reader is configured to accept.

What to do about it

Some of this costs nothing. Some of it is a capital project. It helps to know which is which before anyone gets a quote.

StepWhat it involvesPrice range
Stop accepting prox where cards are already reissuedA configuration change on multi-technology readers, door by doorNo cost, or integrator time
Add a PIN at the doors that matterCard plus PIN at server rooms, labs, cages and the data hallSmall spend if keypads exist
Pull spare and visitor prox cardsReissue or retire everything in the reception drawerSmall spend
Migrate to a modern credentialDESFire EV2/EV3 or Seos with diversified keys, or phone credentials; readers that support them; a reissue planCapital project, get quotes

When you migrate, specify that readers authenticate the credential cryptographically, not just read its serial number. A modern card read by a reader configured for serial number only is barely better than prox.

How we assess it

We identify what the credentials and readers in your building actually are, check what each reader accepts, and, where you authorize it in writing, show whether a copied credential opens the door. Findings name the credential and reader class to move to, with a price range on each. We take no referral fee or commission on anything we recommend. See the full assessment.

Last reviewed September 23, 2026.

Contact

Want to know how your sites would hold up?

Twenty minutes is enough to know whether an assessment is worth it. We’ll be honest either way.