In April 2026 KIRO TV News published a warning about a new cybercrime tactic that they called “ghost tapping.” This is defined as getting close to your credit/debit card or smartphone with a mobile wallet to collect the account information that they contain. KIRO emphasized that this could occur in crowded areas where you would not realize that your account information has been collected. The fix is to put your credit/debit cards into a Faraday sleeve or wallet which would block any short-range radio signals that would initiate transmission of the card information. For a mobile wallet on your phone, most require approval, often by entering your PIN or the use of biometrics, before the information is sent. An additional protection step is to keep the NFC capability off until you need to make a transaction.
The Better Business Bureau (BBB) has observed that ghost tapping can
occur in one of three situations,
·
Getting close in a crowd. A criminal can get close to you to
collect the information on your credit/debit card or bump into you like a pick
pocket. You might not even know that an incident occurred.
·
Pretending to be a vendor. A criminal can pretend to be a vendor
at a special event, flea market, festival, etc.
·
Charity scams. This could occur in crowded areas where scammers
pretend to collect donations for charity.
In the cases of pretending to be a vendor and charity scams the
criminal may rush the process. They may not let you see a screen that has the
agreed upon price and/or do not present you with a paper receipt that shows
what was charged on your card. This way they can charge you more than you
thought you were paying without you knowing.
BBB offers red flags to watch out for,
·
A request to tap without showing you the total charge or offering
a receipt.
·
Bank alerts about small or unusual test charges.
·
Suspicious charges that show up after you have been in crowded
areas.
BBB recommends the following to protect yourself from ghost
tapping,
·
Use RFID protection such as a Faraday sleeve or wallet.
·
Confirm payment details before tapping your card or phone.
·
Set up transaction alerts with your bank and credit card provider.
·
Check your accounts frequently.
This seems to be prudent advice. Yet, there are those who say that
the need for special measures to block an RFID or NFC signal is in reality not
very high. They point out that the likelihood of someone bumping into you and
collecting your information is unlikely in most cases. They also point out that
transmissions are encrypted, making the information unusable by anyone who
might manage to intercept it. Also, NFC transmissions often use “tokenization”
that transmits enough information to complete the transaction but not give
essential account information to strangers. Finally, they point out that to skim
account information like a pick pocket is too difficult to be attractive to a
criminal and that documented cases of criminals acting like electronic pick
pockets is scarce.
Yet several sources are sounding the alarm that cyber thieves are
stealing credit card account information through RFID technology on modern tap
to pay cards and NFC technology on cell phones.
As evidence, they point to a phishing scam that was discovered in
Italy and Tennessee attributed to Chinese cyber gangs. A victim receives a text
message claiming to be from their bank telling them that there is something
wrong with their account and that they should call the phone number provided. One
of the actions the victim is told to take is to download an app that they are
told is a security tool or verification utility. Then the victim is told to tap
their credit or debit card on their phone. The “security app” in reality
transfers the information to a cell phone in the criminal’s control. The
criminal can then use his cell phone to make purchases or collect cash at an
ATM on the victim’s dime.
But you say, what does this have to do with stealing like a pick
pocket? This was a phishing scam that
fully involved the victims. And two of the three ghost tapping situations cited
by the BBB have to do with victims using sketchy circumstances to pay for a product,
or service, or contribute to a charity.
The phishing scam could be a precursor to a new technique that mimics
how pick pockets operate. The fake “security app” could be modified to collect
credit card data and forward the data in mass to a cybercriminal’s cell phone. The
app then can be distributed to “mules” who wittingly or unwittingly collect the
data.
Disclaimer: I have seen anyone document this. But it is a potential,
and I believe a highly possible, advancement in technology. The risk for the
average person might be limited to crowded areas such as tourist traps, transit
situations, popular bars, concerts, etc. And while the rewards may seem small,
modern cybercriminals often play a numbers game. It’s like plants. They often propagate with
seeds. To survive, they spread lots and lots of seeds, which are easy to make.
Most of the seeds won’t sprout. But enough sprout for the plant species to thrive.
For cybercriminals who might try this as a technique it could be another source
for personal data and cash.
If you are often in a crowd, you might consider using a Faraday sleeve
or wallet. And, if you have a mobile wallet on your phone, be sure to set up
your wallet to verify you with a PIN or biometrics like fingerprints or your
face.
KIRO TV News:
Better Business Bureau:
https://www.bbb.org/all/consumer/scam/how-to-spot-and-avoid-tap-to-pay-scams
ZDNET:
Finance Buzz:
https://financebuzz.com/what-is-rfid-blocking
Consumer Threats:
https://www.idx.us/knowledge-center/rfid-skimming-is-the-danger-real
AARP:
Recorded Future News:
https://therecord.media/new-payment-card-scam-involves-malware-tap
https://therecord.media/scammers-ghost-tapping-retail-fraud-launder-cash
Cleafy:
Krebs on Security:
https://krebsonsecurity.com/2025/03/arrests-in-tap-to-pay-scheme-powered-by-phishing/
No comments:
Post a Comment