REPORT ALL SUSPICIOUS OR CRIMINAL ACTIVITY TO 911

Saturday, August 29, 2026

TAP TO PAY FRAUD- New Technology May Act Like an Electronic Pick Pocket

 In April 2026 KIRO TV News published a warning about a new cybercrime tactic that they called “ghost tapping.” This is defined as getting close to your credit/debit card or smartphone with a mobile wallet to collect the account information that they contain. KIRO emphasized that this could occur in crowded areas where you would not realize that your account information has been collected. The fix is to put your credit/debit cards into a Faraday sleeve or wallet which would block any short-range radio signals that would initiate transmission of the card information. For a mobile wallet on your phone, most require approval, often by entering your PIN or the use of biometrics, before the information is sent. An additional protection step is to keep the NFC capability off until you need to make a transaction.

The Better Business Bureau (BBB) has observed that ghost tapping can occur in one of three situations,

·         Getting close in a crowd. A criminal can get close to you to collect the information on your credit/debit card or bump into you like a pick pocket. You might not even know that an incident occurred.

·         Pretending to be a vendor. A criminal can pretend to be a vendor at a special event, flea market, festival, etc.

·         Charity scams. This could occur in crowded areas where scammers pretend to collect donations for charity.

In the cases of pretending to be a vendor and charity scams the criminal may rush the process. They may not let you see a screen that has the agreed upon price and/or do not present you with a paper receipt that shows what was charged on your card. This way they can charge you more than you thought you were paying without you knowing.

BBB offers red flags to watch out for,

·         A request to tap without showing you the total charge or offering a receipt.

·         Bank alerts about small or unusual test charges.

·         Suspicious charges that show up after you have been in crowded areas.

BBB recommends the following to protect yourself from ghost tapping,

·         Use RFID protection such as a Faraday sleeve or wallet.

·         Confirm payment details before tapping your card or phone.

·         Set up transaction alerts with your bank and credit card provider.

·         Check your accounts frequently.

 

This seems to be prudent advice. Yet, there are those who say that the need for special measures to block an RFID or NFC signal is in reality not very high. They point out that the likelihood of someone bumping into you and collecting your information is unlikely in most cases. They also point out that transmissions are encrypted, making the information unusable by anyone who might manage to intercept it. Also, NFC transmissions often use “tokenization” that transmits enough information to complete the transaction but not give essential account information to strangers. Finally, they point out that to skim account information like a pick pocket is too difficult to be attractive to a criminal and that documented cases of criminals acting like electronic pick pockets is scarce.  

Yet several sources are sounding the alarm that cyber thieves are stealing credit card account information through RFID technology on modern tap to pay cards and NFC technology on cell phones.

As evidence, they point to a phishing scam that was discovered in Italy and Tennessee attributed to Chinese cyber gangs. A victim receives a text message claiming to be from their bank telling them that there is something wrong with their account and that they should call the phone number provided. One of the actions the victim is told to take is to download an app that they are told is a security tool or verification utility. Then the victim is told to tap their credit or debit card on their phone. The “security app” in reality transfers the information to a cell phone in the criminal’s control. The criminal can then use his cell phone to make purchases or collect cash at an ATM on the victim’s dime.

But you say, what does this have to do with stealing like a pick pocket?  This was a phishing scam that fully involved the victims. And two of the three ghost tapping situations cited by the BBB have to do with victims using sketchy circumstances to pay for a product, or service, or contribute to a charity.

The phishing scam could be a precursor to a new technique that mimics how pick pockets operate. The fake “security app” could be modified to collect credit card data and forward the data in mass to a cybercriminal’s cell phone. The app then can be distributed to “mules” who wittingly or unwittingly collect the data.

Disclaimer: I have seen anyone document this. But it is a potential, and I believe a highly possible, advancement in technology. The risk for the average person might be limited to crowded areas such as tourist traps, transit situations, popular bars, concerts, etc. And while the rewards may seem small, modern cybercriminals often play a numbers game.  It’s like plants. They often propagate with seeds. To survive, they spread lots and lots of seeds, which are easy to make. Most of the seeds won’t sprout. But enough sprout for the plant species to thrive. For cybercriminals who might try this as a technique it could be another source for personal data and cash.

If you are often in a crowd, you might consider using a Faraday sleeve or wallet. And, if you have a mobile wallet on your phone, be sure to set up your wallet to verify you with a PIN or biometrics like fingerprints or your face.

 

 

KIRO TV News:

https://www.kiro7.com/news/local/ghost-tapping-scam-charging-your-card-without-you-knowing/LO7BM345F5AOLLBV6MTRQCX6E4/

 

Better Business Bureau:

https://www.bbb.org/all/consumer/scam/how-to-spot-and-avoid-tap-to-pay-scams

https://www.bbb.org/article/news-releases/26288-what-to-know-if-youre-using-nfcs-and-you-probably-are

 

ZDNET:

https://www.zdnet.com/article/this-ghost-tapping-scam-can-steal-money-from-your-mobile-wallet-or-card-how-to-block-it/

 

Finance Buzz:

https://financebuzz.com/what-is-rfid-blocking

 

Consumer Threats:

https://www.idx.us/knowledge-center/rfid-skimming-is-the-danger-real

 

AARP:

https://www.aarp.org/money/scams-fraud/rfid-wallets-purses/?src=psn?cmp=EMC-DSM-NLC-OTH-WBLTR-2239402-2353302-e318cf4ba79e412d9bf3ba234e3e628a-NA-07102026-Webletter-MS2-foundry-BTN-NA-article-1f3094e836&encparam=WnvEyp%2FiTaKWUyvgb9wdGFaTDfrqFFWXvVB%2FMiAIV5E%3D

 

Recorded Future News:

https://therecord.media/new-payment-card-scam-involves-malware-tap

https://therecord.media/scammers-ghost-tapping-retail-fraud-launder-cash

 

Cleafy:

https://www.cleafy.com/insights/nfc-relay-attack-understanding-and-preventing-contactless-payment-fraud

https://www.cleafy.com/cleafy-labs/supercardx-exposing-chinese-speaker-maas-for-nfc-relay-fraud-operation

 

Krebs on Security:

https://krebsonsecurity.com/2025/03/arrests-in-tap-to-pay-scheme-powered-by-phishing/

 

Monday, August 17, 2026

SNOHOMISH COUNTY SHERIFF’S OFFICE- Auto Thefts Continue Downward Trend

Car thefts have continued to go down in 2025 in Washington and Snohomish County, but new technology gives car thieves a new tool to take your wheels. To learn more about this technology and how you can protect your vehicle from theft check out the latest issue of the Sheriff’s Office’s crime prevention newsletter, “Partners in Crime Prevention.”

 

 

Snohomish County Sheriff’s Office:

https://www.snohomishcountywa.gov/ArchiveCenter/ViewFile/Item/7527

 

Friday, August 14, 2026

CAPTCHA- New Phishing Scam

We are all used to CAPTCHA’s, those check boxes and picture matching tasks that prove you are a human. Scammers have found a way to steal the information from your computer by pretending to use a CAPTCHA.

A true CAPTCHA has you click on a box, or type letters or numbers just as they appear on the screen, or match pictures of objects. The fake CAPTCHA has you type a specific sequence of keys. A common sequence is the Windows Key+ R then Ctrl+ V. The sequence is a series of commands to your computer to download a script that downloads a virus onto your computer. The virus can then copy your email account login information, mobile banking credentials, or other information.

Legitimate CAPTCHA’s will NOT ask you to,

·         Run commands on a device

·         Open the Windows Run dialog

·         Paste text into a command box

·         Download files

·         Install software

·         Enable special permissions

If a website asks you to open a “Run” box or paste computer code, close the window immediately. Legitimate CAPTCHA’s will not ask you to run code or download anything as part of their verification that you are a human.

If you do follow keyboard prompts and think you have been infected, take the following actions:

·         Disconnect from the internet. Turn off Wi-Fi or unplug your internet cable. This cuts off the data link between you and the scammer.

·         Scan your device for viruses.

·         Change the password for the account that you were trying to access when the fake CAPTCHA window popped up. Use a clean device, such as your phone, to do the change.

·         Check your bank statements for any charges that you do not recognize.

 

Identity Theft Resource Center:

https://www.idtheftcenter.org/post/new-captcha-scam/

 

Federal Trade Commission:

https://consumer.ftc.gov/consumer-alerts/2026/06/how-spot-captcha-scam

 

CBS News:

https://www.cbsnews.com/philadelphia/news/fake-captcha-scams/

 

 

Saturday, August 8, 2026

IDENTITY THEFT- Trends

The Identity Theft Resource Center (ITRC- https://www.idtheftcenter.org/) is a non-profit organization that educates the public on how to prevent identity theft in their lives and helps victims of identity theft to recover from crimes as a result of identity theft. As a result of its work, the ITRC collects data on identity theft. The ITRC periodically publishes reports based on this data.

The recently published 2026 Trends in Identity Report (TIR) provides insights into how criminals steal identities and the effects those thefts have on the lives of their victims.

Your Personal Identity Information (PII) can be compromised in one of 5 ways,

·         Scams- Scams are the leading method of identity compromise at 36% of all reported cases. This represents a 7% decrease compared to its 2025 TIR. The report notes that scams require the victim’s participation for the criminal to receive the PII. Criminals will use psychological techniques known as social engineering to get the victim into an emotional state and to convince the victim that they need to act often to pay some money and to give over their identity information.

·         Unauthorized Device Access- This is where a cybercriminal inserts malware that extracts information useful to the criminal into your PC, laptop, tablet, or smart phone. A leading method for this type of attack is a phishing email or text message. But malware can also be inserted into your device through a website that you visit that may not be from a reputable company or organization. 27% of all cases reported to ITRC involved unauthorized device access, a 12% increase from the year before. Having access to your device gives cybercriminals access to all of your personal information stored in it.

·         Physical Theft- Physical theft of a document or device (such as a smartphone, laptop, or tablet computer) amounted to 16% of all cases reported. Documents that are stolen and are the building blocks of an identity include driver’s licenses and state ID’s (23%), Social Security cards (20%), credit and payment cards (12%), and birth certificates (10%). Theft of phones and tablets, which can be a treasure chest of personal information, was about (7%).

·         Data Breaches- This was 10% of all reported cases; a decline compared to last year. The victim will not know about a data breach unless they are notified by the holder of the data.

·         PII on the Dark Web- 4% of cases involved PII on the Dark Web. The Dark Web is especially murky but often include purchases of stolen PII by people who use it to perform criminal acts.

 Now that the criminal has your PII, what do they do with it?

·         Account Takeover- Cyber criminals often take over (or try to) one of your accounts. Accounts that they often target include 1. Checking accounts, 2. Credit cards, 3. Email accounts, 4. Social media, 5. Cell phone accounts, 6. P2P payment apps. While an account takeover is easiest to discover, this is where prevention techniques become important such as Multifactor Authentication (MFA) or passkeys to prevent unauthorized persons from entering your accounts. Frequently monitoring your accounts can help you detect unusual account activity early.

·         New Account Fraud. If the criminal has enough information about you, they may open a new account in your name. This can be a new credit card account, a loan, or they sign a lease. The most common accounts that cybercriminals take out include 1. Credit cards, 2. Checking accounts, 3. Personal loans, 4. Cell phone accounts, 5. Auto loans, 6, Mortgage loans, 7. Federal student loans. The victim often has no idea that a new account has been taken out in their name. If there is discovery the method is more passive and takes longer, often weeks or months after the act. The primary detection method is a notice, from usually a financial institution, that alerts the victim that an account has been taken out in their name. Regularly checking your credit reports can lead to discovery. The most jarring discovery method is a notice from a collection agency that you owe for unpaid bills. To prevent new account fraud, freeze your credit with the 3 credit reporting agencies.

Some crimes just are not on the victim’s radar as far as detection. There is no statement to review, no login to check, no balance to monitor. The hardest crimes to detect include,

·         Fraudulent Employment. If someone applies for a job in your name you have no idea that they have gained employment by impersonating you. You may discover this crime at some point if you apply for a government benefit and learn that it has already been claimed. Or you might learn that income has been reported under your SSN. Fraudulent employment is the most common crime against children giving it a disproportionate impact on kids. A child’s SSN is clean, making it most valuable to criminals. Also, most parents and guardians are not checking their child’s existing credit history or employment record. Therefore, a criminal can use a child’s identity for years before being discovered.

·         IRS Misuse. This is where a criminal files an income tax return in the victim’s name using the victim’s information. This victim most often finds out through a notification from the IRS or another government agency. A few might find out when they check on their account when an expected refund did not arrive or was issued to an account that they did not recognize.

·         Criminal Identity Theft. If someone commits a crime then uses your name when contacted by police, the discovery is a complete shock. Discovery frequently comes with contact with police, such as during a traffic stop. Others learn of the crime during a background check applying for a job. Still others learn about it from an employer.

 

To effectively protect yourself from these crimes you need to use “layered defenses;” that is steps that help you cover several situations. For example,

·         Credit report monitoring helps guard against new account fraud but does not help with account takeover.

·         Account activity monitoring helps protect against existing account takeover but not employment fraud.

·         Credit freezes prevent creation of a new account but does not help with protecting existing accounts.

·         Using MFA or Passkeys protects against device compromise.

 

For more insights from the Trends in Identity report go to- https://www.idtheftcenter.org/wp-content/uploads/2026/06/The-2026-ITRC-Trends-in-Identity-Report.pdf

 

 

Identity Theft Resource Center:

https://www.idtheftcenter.org/