The short answer
Yes. Low-frequency 125 kHz proximity cards, including HID ProxCard II and ISOProx, Indala, EM4100 and their many compatibles, send a fixed ID number with no encryption and no authentication. Any reader that powers the card can read that number, and a writable blank card can be programmed with it. The reader on your door cannot tell the copy from the original.
The tools are not specialist. Handheld cloners are sold openly online, and researchers have demonstrated modified long-range readers that capture a prox card from a few feet away, from inside a bag, in an elevator or in line at the coffee shop.
Why this is still a live problem
Most organizations know prox is old. The exposure usually survives because of how migrations are done:
- New secure cards are issued, but the readers are multi-technology and still accept the old 125 kHz cards too. The old credential keeps working at every door until someone switches that off.
- One site migrated and another did not, and both share a cardholder database.
- Visitor, contractor and "spare" badges were never reissued, so the drawer at reception is still full of prox cards.
- Parking, elevators and secondary doors run on a separate controller nobody included in the project.
A migration only reduces risk once the old technology is turned off at the reader. Until then you have added a second way in, not replaced the first.
How to tell what your office uses
- Look at the card. Many are printed with the product name, such as "HID ProxCard II" or "ISOProx".
- Try a phone. Phone NFC works at 13.56 MHz and cannot see a 125 kHz card at all. If your phone does not react to the badge, it is probably low frequency. (If it does react, that does not make it secure; see the MIFARE Classic vs DESFire vs Seos guide.)
- Ask your access control integrator for two things in writing: the reader models installed at each door, and which credential technologies each reader is configured to accept.
What to do about it
Some of this costs nothing. Some of it is a capital project. It helps to know which is which before anyone gets a quote.
| Step | What it involves | Price range |
|---|---|---|
| Stop accepting prox where cards are already reissued | A configuration change on multi-technology readers, door by door | No cost, or integrator time |
| Add a PIN at the doors that matter | Card plus PIN at server rooms, labs, cages and the data hall | Small spend if keypads exist |
| Pull spare and visitor prox cards | Reissue or retire everything in the reception drawer | Small spend |
| Migrate to a modern credential | DESFire EV2/EV3 or Seos with diversified keys, or phone credentials; readers that support them; a reissue plan | Capital project, get quotes |
When you migrate, specify that readers authenticate the credential cryptographically, not just read its serial number. A modern card read by a reader configured for serial number only is barely better than prox.
How we assess it
We identify what the credentials and readers in your building actually are, check what each reader accepts, and, where you authorize it in writing, show whether a copied credential opens the door. Findings name the credential and reader class to move to, with a price range on each. We take no referral fee or commission on anything we recommend. See the full assessment.
Last reviewed September 23, 2026.