NFC and Tap-to-Pay Fraud: How "Ghost Tap" Scams Drain Contactless Cards

Contactless card emitting signal intercepted between two phones, NFC ghost tap fraud illustration

You tap your card on a payment terminal, the transaction goes through, and you walk away — but the terminal was never yours to trust. A wave of "ghost tap" and NFC relay fraud has been draining contactless cards and phone wallets without the card ever leaving the victim's pocket. Unlike traditional card skimming, which needs a compromised ATM or gas pump, this attack can happen while your card sits untouched in your bag.

Contactless payment is genuinely more secure than swiping a magnetic stripe in most ways, but the convenience that makes tap-to-pay fast is exactly what criminals are now exploiting.

How Ghost Tap and NFC Relay Fraud Actually Works

Near Field Communication (NFC) — the technology behind tap-to-pay — only works over a few centimeters, which is supposed to make it safe. Relay attacks defeat that distance limit using two coordinated phones. One phone, held close to your card or wallet (in a crowded train, a bag left on a café chair, or even brushed past you in a queue), reads the NFC signal. It instantly relays that signal over the internet to a second phone at a payment terminal somewhere else, sometimes in a different country, which replays it to complete a purchase. The whole exchange happens in under a second.

A newer variant, dubbed "ghost tapping," goes further: fraudsters trick victims into adding a stolen card to Apple Pay or Google Wallet through phishing links, then use malware to relay that phone's NFC signal to a mule's device anywhere in the world, allowing them to make in-person tap purchases or ATM withdrawals remotely using someone else's digitized card.

Warning Signs You've Been Targeted

  • Small, unfamiliar charges you don't recognize, often just under the amount that would require a PIN — fraudsters test with tiny purchases first.
  • A text message or email asking you to "verify" or "re-add" a card to your mobile wallet, especially after a supposed bank alert.
  • Notifications of a mobile wallet card addition you didn't initiate.
  • Unusual phone behavior after installing an app from a link sent by text — increased battery drain, new permissions requests, or an unfamiliar app icon.

How to Protect Yourself

  1. Use an RFID-blocking wallet or sleeve for physical cards you don't tap often, especially in crowded public transport where proximity attacks are easiest.
  2. Set a low contactless limit with your bank if the option exists, or require a PIN after every second or third tap — many banks let you configure this in-app.
  3. Turn on transaction alerts for every card and mobile wallet so you see a charge the moment it happens, not weeks later on a statement.
  4. Never tap "verify your card" links sent by text or email. Go directly to your bank's app instead. Legitimate banks do not ask you to re-add a card through a text link.
  5. Keep your phone's OS and banking apps updated. Most NFC relay malware relies on outdated Android accessibility permissions being exploited; current OS versions close many of these gaps.
  6. Review which apps have NFC and accessibility permissions on your phone (Settings → Apps → Special access on Android) and remove anything you don't recognize or no longer use.
  7. Be deliberate about physical proximity. Don't leave a wallet or unlocked phone sitting on a café table or bag pocket accessible to someone standing close for an extended time.

If It Already Happened

Contact your bank or card issuer immediately — most contactless fraud is covered under the same zero-liability protections as other unauthorized card use, but you need to report it quickly, ideally within 24 to 48 hours. Ask them to:

  • Freeze or cancel the affected card and issue a new one with a new number.
  • Remove the card from any mobile wallet remotely if it was digitized without your knowledge.
  • Open a formal fraud dispute for each unauthorized charge — get a case number for every one.

If you suspect your phone itself is compromised with relay malware, don't just delete the suspicious app — back up your essential data, then perform a full factory reset, and change your banking passwords from a different, trusted device before signing back in.

The Bottom Line

Tap-to-pay remains safer overall than handing your card to a stranger or swiping a stripe reader, and these relay attacks still require real technical coordination, so they're far less common than phishing or card skimming. But the fix is simple and takes five minutes: turn on transaction alerts, ask your bank about lowering the contactless limit, and never tap a link claiming to be your bank. Those three habits close off almost every version of this scam.

Comments

Popular posts from this blog

Best Antivirus Software of 2026: Top 5 Compared After Real Testing

Public Wi-Fi Dangers: 7 Critical Steps to Stay Safe

Best Identity Theft Protection Services of 2026: Top 5 Ranked and Reviewed