NFC and Tap-to-Pay Fraud: How "Ghost Tap" Scams Drain Contactless Cards
You tap your card on a payment terminal, the transaction goes through, and you walk away — but the terminal was never yours to trust. A wave of "ghost tap" and NFC relay fraud has been draining contactless cards and phone wallets without the card ever leaving the victim's pocket. Unlike traditional card skimming, which needs a compromised ATM or gas pump, this attack can happen while your card sits untouched in your bag.
Contactless payment is genuinely more secure than swiping a magnetic stripe in most ways, but the convenience that makes tap-to-pay fast is exactly what criminals are now exploiting.
How Ghost Tap and NFC Relay Fraud Actually Works
Near Field Communication (NFC) — the technology behind tap-to-pay — only works over a few centimeters, which is supposed to make it safe. Relay attacks defeat that distance limit using two coordinated phones. One phone, held close to your card or wallet (in a crowded train, a bag left on a café chair, or even brushed past you in a queue), reads the NFC signal. It instantly relays that signal over the internet to a second phone at a payment terminal somewhere else, sometimes in a different country, which replays it to complete a purchase. The whole exchange happens in under a second.
A newer variant, dubbed "ghost tapping," goes further: fraudsters trick victims into adding a stolen card to Apple Pay or Google Wallet through phishing links, then use malware to relay that phone's NFC signal to a mule's device anywhere in the world, allowing them to make in-person tap purchases or ATM withdrawals remotely using someone else's digitized card.
Warning Signs You've Been Targeted
- Small, unfamiliar charges you don't recognize, often just under the amount that would require a PIN — fraudsters test with tiny purchases first.
- A text message or email asking you to "verify" or "re-add" a card to your mobile wallet, especially after a supposed bank alert.
- Notifications of a mobile wallet card addition you didn't initiate.
- Unusual phone behavior after installing an app from a link sent by text — increased battery drain, new permissions requests, or an unfamiliar app icon.
How to Protect Yourself
- Use an RFID-blocking wallet or sleeve for physical cards you don't tap often, especially in crowded public transport where proximity attacks are easiest.
- Set a low contactless limit with your bank if the option exists, or require a PIN after every second or third tap — many banks let you configure this in-app.
- Turn on transaction alerts for every card and mobile wallet so you see a charge the moment it happens, not weeks later on a statement.
- Never tap "verify your card" links sent by text or email. Go directly to your bank's app instead. Legitimate banks do not ask you to re-add a card through a text link.
- Keep your phone's OS and banking apps updated. Most NFC relay malware relies on outdated Android accessibility permissions being exploited; current OS versions close many of these gaps.
- Review which apps have NFC and accessibility permissions on your phone (Settings → Apps → Special access on Android) and remove anything you don't recognize or no longer use.
- Be deliberate about physical proximity. Don't leave a wallet or unlocked phone sitting on a café table or bag pocket accessible to someone standing close for an extended time.
If It Already Happened
Contact your bank or card issuer immediately — most contactless fraud is covered under the same zero-liability protections as other unauthorized card use, but you need to report it quickly, ideally within 24 to 48 hours. Ask them to:
- Freeze or cancel the affected card and issue a new one with a new number.
- Remove the card from any mobile wallet remotely if it was digitized without your knowledge.
- Open a formal fraud dispute for each unauthorized charge — get a case number for every one.
If you suspect your phone itself is compromised with relay malware, don't just delete the suspicious app — back up your essential data, then perform a full factory reset, and change your banking passwords from a different, trusted device before signing back in.
The Bottom Line
Tap-to-pay remains safer overall than handing your card to a stranger or swiping a stripe reader, and these relay attacks still require real technical coordination, so they're far less common than phishing or card skimming. But the fix is simple and takes five minutes: turn on transaction alerts, ask your bank about lowering the contactless limit, and never tap a link claiming to be your bank. Those three habits close off almost every version of this scam.
Comments
Post a Comment