Scam Alert:

ACTIVE SCAM ALERT

“Ghost Tapping” and Contactless Payment Fraud

Scam Alert: “Ghost Tapping” and Contactless Payment Fraud

Tap-to-pay makes purchases quick and convenient, but criminals exploit payment systems through deception, stolen credentials, and unauthorized transactions. Warnings about “ghost tapping” describe several different schemes, including dishonest vendors, attempted close-range charges, and sophisticated payment relay attacks. Understanding those differences helps consumers choose useful protections without assuming that every crowded place makes their bank account accessible to strangers.

Contactless payments use near-field communication, or NFC, to exchange information over a short distance. Visa states that ordinary contactless transactions require the card or device to be approximately one to two inches from a payment terminal. Each transaction generates a unique security code, making captured information difficult to reuse for counterfeit purchases. Someone standing several feet away cannot simply drain a card through its normal contactless function.

One version of contactless fraud involves a dishonest seller or supposed fundraiser. The criminal requests a small payment but enters a substantially larger amount, conceals the terminal screen, or pressures the customer to tap before checking the total. The Better Business Bureau describes a reported incident involving someone selling chocolate for an alleged charitable purpose who charged hundreds of dollars without allowing customers to see the amount. Here, the deception concerns the transaction the customer approves.

Consumer warnings also describe digital pickpocketing, in which criminals bring a payment reader close to a physical contactless card inside a pocket or bag. Michigan’s Attorney General warns about attempted charges in busy settings, including festivals and markets. Visa has also documented digital pickpocketing involving mobile payment terminals. However, these warnings do not establish that every incidental bump causes a charge or that the technique works equally against physical cards and mobile wallets.

Phone payments have additional protections. Ordinary Apple Pay purchases require authentication, such as Face ID, Touch ID, or a passcode. Certain Express Mode functions, including supported transit payments, operate without the same authentication step. Device settings and payment modes therefore matter. A physical card and an authenticated mobile wallet should not be treated as identical targets, and merely enabling NFC does not mean that every nearby reader can charge a phone.

Cybersecurity researchers use “Ghost Tap” more specifically for a scheme involving stolen payment credentials and relayed contactless transactions. ThreatFabric described criminals enrolling stolen cards in mobile wallets, then relaying payment communications to accomplices making purchases elsewhere. The cardholder need not be near those purchases or even in the same country. The theft begins with compromised credentials, while the contactless transaction provides a way to spend the stolen funds.

A related relay scam begins with someone impersonating a bank. The caller claims that an account is compromised and directs the victim to install an application resembling banking software. The victim is then instructed to hold a physical payment card against the phone for supposed identity verification. The malicious application relays the card’s payment communications to the criminal’s device, enabling unauthorized transactions. Visa describes this sequence as a documented form of relay fraud.

These schemes target different circumstances rather than one clearly established demographic. Dishonest sellers exploit customers making hurried purchases or donations. Close-range attempts concern accessible physical contactless cards. Credential theft and relay scams target people persuaded to follow fraudulent banking instructions, disclose verification codes, or install malicious software. Crowds provide distraction and proximity for some offenses, but the documented Ghost Tap relay scheme also reaches victims remotely.

Protection starts with examining the payment before authorizing it. Customers should check the amount, merchant information, and any added tip, then retain a receipt. A seller who hides the total or demands an immediate tap deserves scrutiny. An RFID-blocking sleeve or wallet offers an optional barrier against close-range reading of a physical card while it remains inside. It does not prevent overcharging after the card is removed, phishing, or fraudulent use of credentials already stolen.

Many important protections cost nothing. Transaction alerts help identify unexpected purchases, and regular account checks reveal charges that were missed initially. Phones should use strong authentication and current software. Instructions from unsolicited callers to install banking applications, disclose security codes, or tap a card against a phone should be independently checked with the bank through its official application or a trusted telephone number. A caller’s knowledge of personal details does not authenticate the caller.

Anyone discovering an unauthorized transaction should promptly contact the card issuer, report the charge, and ask about freezing or replacing the affected card and securing associated mobile-wallet access. Receipts, messages, and transaction notifications should be preserved. Tap-to-pay remains a payment method with substantial security protections; the FBI identifies it as more resistant to conventional skimming. Effective prevention depends on checking transactions and protecting credentials, rather than relying on fear of invisible theft or a single protective accessory.

Leave A Comment

Your comments help the SCARS Institute better understand all scam victim/survivor experiences and improve our services and processes. Thank you

Thank you for your comment. You may receive an email to follow up. We never share your data with marketers.