Contactless Card Fraud: Cloned and Paid in as Little as 13 Minutes

Buying guide

Researchers watched criminals clone contactless cards and authorise payments in as little as 13 minutes. Here is how relay and skimming attacks actually work, what the fraud figures show, and the three checks that decide whether anything in your pocket helps.

Updated September 2, 2026 7 min read Vaultskin Publishing
Contactless Card Fraud: Cloned and Paid in as Little as 13 Minutes
The short answer

Contactless card fraud runs on two mechanisms: close-range skimming, which needs an antenna within about 10 cm of the card, and NFC relay malware, which carries the card's exchange to a distant terminal. Researchers recorded payments authorised in as little as 13 minutes.

  • Researchers saw NFC-relay malware clone contactless cards and authorise payments in as little as 13 minutes.
  • UK contactless fraud totalled £46.8 million in 2025, 8% above 2024, per UK Finance.
  • NFC operates at 13.56 MHz with an effective range of up to 10 cm.

In one 2026 case, researchers recorded fraudulent payments being authorised in as little as 13 minutes after criminals got hold of victims' contactless card details, using an NFC-relay malware toolkit called WindRelay against people in Czechia, Slovakia and Slovenia.

Most of us picture contactless fraud as a stranger with a concealed reader working a crowded carriage. That version exists, and it is still worth defending against. The 13-minute version is different: the card and the terminal never have to be in the same country.

None of this requires you to become suspicious of a machine you tap 20 times a week. It does split into two questions with two different answers. Relay fraud is not a shielding problem at all, because the card in your pocket is never the thing being approached; what limits it is instant transaction alerts and a freeze button you have already found. Shielding answers the narrower, older question: which of the cards you are carrying right now can be read at close range without being touched, and what sits between them and somebody else's antenna. Both answers cost nothing and take about a minute to put in place.

What a relay attack actually is

WindRelay belongs to a wider family of NFC-relay campaigns. One of the better documented is Ghost Tap, first identified in 2024, which Group-IB linked to losses exceeding $355,000 in the months after its discovery.

A contactless payment is a very short radio conversation. Your card says what it is, the terminal asks for a cryptogram, the card answers, and the whole exchange is over before your hand has left the reader. Relay software does not break that conversation. It carries it, passing each side's messages to the other over the internet, so the tap can happen in one place and the till can be somewhere else entirely.

That is the shift worth understanding. Skimming steals the conversation by getting close to your card. Relay steals it by removing the need to be close at all, which is why the same toolkit turned up against victims in three separate countries.

Two free defences beat everything else against relay fraud, and you can set both up now. Turn on instant transaction alerts in your banking app, and learn where the freeze button is before you need it.

The 10 cm rule your bank is relying on

The technology underneath is not exotic. NFC operates in the 13.56 MHz band with an effective range of up to 10 cm, built to the ISO/IEC 14443 or 15693 standards. Short range is the security model: the assumption is that nothing gets that near your card unless you have decided it should.

Hold a card in your hand and look at it. Roughly 10 cm is the long edge of that card plus a fingernail. That is the entire distance between a card sitting in a coat pocket and a reader held on the other side of the fabric, which is what a skimming attempt looks like in practice: not a dramatic grab, just someone standing closer than they need to on an escalator.

Take your cards out and find the ones printed with the four curved lines. Those are the ones that answer a reader at that range, in your pocket, all day, whether or not you are paying attention.

The 13-minute version is different: the card and the terminal never have to be in the same country.

The numbers, and the direction they are moving

In the UK, contactless fraud reached £46.8 million in 2025, 8% up on 2024, according to UK Finance's Annual Fraud Report 2026. That is on top of an earlier jump: the same body's 2023 fraud report recorded contactless losses rising 82% alongside a 30% rise in lost-and-stolen card losses, as normal routines resumed and criminals had more chance to get hold of cards in the first place.

The pattern is not confined to one country: an analysis of over 3.7 billion transactions put detected digital payment fraud in Europe, contactless included, at 5.57 cases per 100,000 transactions in 2024, a 43% increase on the previous year, ESET's telemetry recorded NFC-related attacks surging more than 35 times in the first half of 2025 compared with the second half of 2024, and Singapore's authorities issued a joint advisory on unauthorised contactless transactions in February 2025.

Banks are not passive in this. The UK payments industry prevented £1.45 billion of unauthorised fraud in 2024, equivalent to 67p in every £1 attempted. Read that the other way round and the point becomes obvious: about a third of attempted fraud still lands, and in 2023 £1.17 billion was lost across UK-issued accounts and cards. Detection is a net, not a wall.

Three checks that separate real protection from packaging

The market for anti-skimming products is full of claims you cannot test in a shop. These three you can.

  • Does it work at contact range, or only at arm's length? The threat distance is 10 cm and under, so anything that only claims to help at a metre is answering a question nobody asked. Shielding works when the cards are enclosed and the wallet is shut. A jamming card works within a stated radius of itself, and 4 cm is the figure ours is rated to, which gives you a benchmark to hold other packaging against before you buy.
  • Does it cover the whole stack, or 1 card? Take the cards out of your wallet and count them. If the total surprises you, a single blocking sleeve for your debit card leaves the rest exposed, because the card you forgot about is contactless too.
  • What happens when you stop thinking about it? Anything that needs charging, pairing or an app will eventually be flat, unpaired or uninstalled. The defences that survive contact with real life are the ones that work while you are doing something else.

Where each option honestly lands

We make wallets with shielding built into them, so treat the recommendation that follows as disclosed interest. Neither a wallet nor a jamming card does anything about credentials that were phished, typed into a fake page, or loaded onto a criminal's phone; those attacks never go near the card in your pocket. Anyone selling you shielding as a cure for all card fraud is selling you the wrong story.

What shielding does address is the physical read: someone taking a contactless conversation from a card you have not taken out. If you want the technical case for that rather than our word for it, we have set it out separately in our evidence page on whether RFID wallets work. It is not a sales page, and it is honest about the limits.

If you like the wallet you already own, the retrofit is the smaller change. The VAULTCARD is an RFID-jamming card powered by the scanner's own field, with no battery to charge: it senses a reader and emits an electromagnetic jamming signal, blocking readers from reading any RFID card within 4 cm of it. It sits in a card slot and behaves like a card, which is the only reason people keep using it.

The verdict

If your cards live loose in a jacket pocket or in an unshielded fold of leather, the fix is not vigilance, because vigilance is not available at 8am on a packed platform. It is a container that answers close-range readers with silence by default.

For most people that means a wallet with the shielding already in the material rather than a gadget added later. The Chelsea is a slim RFID-blocking wallet holding 4 to 8 cards, which is the right choice if your carry is a debit card, a credit card, a transit card and the two you keep forgetting about. It is the wrong choice if you carry a dozen, in which case buy the jamming card and keep the wallet you have.

So be clear about which job each thing does. Shielding stops an enclosed card from answering a reader held close to it, and that is the whole of what it does; it has no bearing on a relay case like the 13-minute one, where the card is tapped to an infected phone or the credentials are already on someone else's device. The counterweight to that is the unglamorous part: alerts on, freeze button learned, statements read on the day they arrive rather than the month. When you want the shielded version for the close-range read, the full range of RFID-blocking wallets is here.

Questions people ask

Can someone really take money from my card without touching it?

A contactless card answers any compliant reader that comes within roughly 10 cm, because NFC operates at 13.56 MHz with that effective range by design. Close-range skimming exploits exactly that. Relay attacks go further: NFC-relay malware carries the card's exchange to a payment terminal somewhere else, and researchers recorded one 2026 campaign authorising fraudulent payments in as little as 13 minutes after obtaining card details. Physical shielding addresses the close-range read. It does not address credentials that were phished or loaded onto a criminal's device.

Is contactless fraud actually increasing?

In several recent reporting periods, yes. UK Finance recorded £46.8 million of contactless fraud in the UK in 2025, 8% higher than 2024, after its 2023 fraud report recorded contactless losses rising 82%. Across Europe, an analysis of over 3.7 billion transactions put detected digital payment fraud at 5.57 cases per 100,000 transactions in 2024, up 43% year on year. ESET's telemetry recorded NFC-related attacks rising more than 35 times in the first half of 2025 against the second half of 2024.

Do I need an RFID wallet if I pay with my phone?

If every physical card has left your pocket, close-range skimming has nothing to read. Most people are not there yet: a transit card, a building pass, a backup debit card or a credit card kept for emergencies usually stays in the wallet, and each of those answers a reader at contact range. Count what you actually carry, then decide. Phone payment does not protect the plastic still sitting in your jacket.

What should I do first if I think a contactless payment was not mine?

Freeze the card in your banking app before you do anything else, then report the transaction to your bank. Turn on instant transaction alerts if they are not already on, so the next unfamiliar payment reaches you in seconds rather than at the end of the month. Detection systems catch a great deal but not everything: the UK payments industry prevented £1.45 billion of unauthorised fraud in 2024, equivalent to 67p in every £1 attempted, which means a share still gets through.

Does a jamming card work differently from a shielded wallet?

Yes. A shielded wallet blocks wireless card reading passively, while the cards are enclosed and the wallet is closed. The VAULTCARD is active: powered by the scanner's own field, with no battery, it senses a reader and emits an electromagnetic jamming signal that blocks readers from reading any RFID card within 4 cm of it. Both address the close-range read only, not credentials phished or loaded onto a criminal's device. The wallet approach suits people replacing their wallet anyway; the jamming card suits people who like the one they own.

Built To Last
Money-Back
Guarantee
Secure
Checkout
Fast
Delivery
Made by Vaultskin
The real choice is not whether the protection works, but how you want to carry it.
Browse RFID wallets Read the evidence