Ghost Tapping and Skimming: A Two-State $300,000 Scheme

Ghost Tapping and Skimming: A Two-State $300,000 Scheme

Ghost Tapping and Skimming: A Two-State $300,000 Scheme

A skimming device sat on a card reader at a Bank Newport drive-through in Bristol, Rhode Island, until an employee noticed it in October 2023. By then the operation behind it had taken more than $300,000. Six people were later charged with running the scheme at banks and shops across Rhode Island and Massachusetts, according to the Boston Globe.

A drive-through card reader is a piece of street furniture. Nobody studies it. You reach out of the window, you push a card into a slot you have used a hundred times, and the machine does what machines do. That is the whole business model: a skimmer reads your card in the one place your card is meant to be read.

What makes that case worth remembering is not the money. It is the effort. Somebody had to drive to Bristol, fit hardware to a live machine in daylight, and come back later to collect what it had captured. The theft required a body in a place.

That requirement is what the newest version of card fraud has removed. Skimming has not gone away, but it now sits at the primitive end of a spectrum that ends with a phone relaying a payment credential to a stranger on another continent. Most of what still protects you takes five seconds, costs nothing, and appears on no card, statement or product page.

Ghost tapping: the same theft, with nobody in the car park

A man stands at a till in a shop, unhurried, buying a phone or a handbag with a card that is sitting in your coat pocket three time zones away. He is a mule, and he is the last link in the chain. Recorded Future documents ghost-tapping crews relaying stolen card details linked to mobile wallets to mules who buy in person, collecting physical goods that are resold later. No suspicious wire transfer, no cash withdrawal, just a person at a counter paying with a card he has never touched.

Two minutes of admin blunts that, and it costs nothing. Open your banking app tonight and switch on per-transaction alerts rather than weekly summaries. Ghost Tap cash-outs run through mobile wallets, so a verification code arriving when you are not adding a card to anything is that same warning arriving early: call the number on the back of your card. Not a reply, a call.

Ghost Tap, also tracked as TX-NFC, is a relay attack. Group-IB describes it as a method that lets fraudsters make card-present, tap-to-pay purchases by relaying a stolen card's NFC signal to a remote device, bypassing the physical proximity that contactless payment security normally relies on. The terminal believes the card is at the till, because electronically it is.

The tooling is not exotic. Researchers at ThreatFabric exposed the technique in which an attacker reads a victim's card data using an NFC-enabled Android phone running the NFCGate app, then relays it to a receiver anywhere in the world to cash out through Google Pay or Apple Pay. NFCGate was built for academic NFC research. Fraud tutorials on Telegram and dark web forums did the rest.

And it adds up. Group-IB documented at least $355,000 in illegitimate Ghost Tap transactions processed through a single point-of-sale vendor between November 2024 and August 2025. One vendor. Ten months.

What the numbers actually say

One figure is worth carrying out of the statistics. In 2024, UK Finance recorded 3.13 million confirmed cases of unauthorised card and payment fraud, up 14% on 2023, with unauthorised fraud losses of £722 million.

Honest bounding: that total is not a Ghost Tap total. Relay fraud is the newest technique in a very large field, and the documented sums so far are small beside the field. What the data shows is direction, and the direction is the same everywhere it is measured.

The rest of the picture, for the same year: across the European Economic Area, payment fraud losses reached €4.2 billion, a 17% rise, with card fraud alone at roughly €1.3 billion. In the United States, consumers reported more than $12.5 billion in fraud losses to the FTC, a 25% increase, including over 458,000 credit card fraud reports.

The more useful comparison is exposure. Contactless skimming, in which fraudsters use illicit devices to capture the data transmitted during a contactless transaction, is a documented risk of the technology rather than a theoretical one. Every technique in this article, old and new, turns on the same thing: your card details ending up somewhere you did not put them.

What the two crimes actually have in common

A skimmer reads your card at the slot, in the moment you hand it over. A relay does not touch the card at all. Per Group-IB and ThreatFabric, a Ghost Tap chain starts with card credentials that have already been phished or harvested by malware and provisioned into a mobile wallet the fraudster controls; the relay then carries that wallet's signal to a mule's phone at a till. Different hardware, different starting points, one shared requirement: your card details have to end up in hands that are not yours.

That is the principle worth carrying out of this piece. Your card details should only ever be readable, and only ever usable, when you have decided they are. Everything else, the alerts, the freezes, the checks, is cleanup after that decision has been made for you.

There is a card in your wallet right now that you could not name without looking. It is contactless, which means it will answer a payment reader held within a few centimetres of it, and it will answer that reader whether you meant it to or not. The good news is that every one of the moves that narrows the window is free, and you can make most of them tonight.

Seven free things worth doing this week

None of this needs a purchase, a subscription or a call to a fraud line. Four of the seven are decided at home on the sofa, before anything has happened to you.

  1. Tug the machine before you use it. At a fuel pump, ATM or bank drive-through, pull the card slot and press the corner of the keypad. Loose plastic, a lip that moves, a keypad sitting proud of its frame: any of that, and you go inside and pay at the counter. The Bristol device was found because somebody looked.
  2. Turn on per-transaction alerts, not weekly summaries. Most major banking apps offer this free of charge. The difference is finding out about the first small purchase in ninety seconds instead of the twelfth one in three weeks.
  3. Read line items, not the total. Totals hide things. A statement scanned for its final figure is not a statement you have checked.
  4. Find the freeze switch before you need it. If your bank's app can lock a card, learn where that control lives while you are sitting on the sofa, not while you are standing in a car park. Use it once, on purpose, so your thumb knows the way.
  5. Treat an unrequested verification code as an event. Ghost Tap cash-outs run through mobile wallets, so a code arriving when you are not adding a card to anything deserves a call to the number on the back of your card. Not a reply, a call.
  6. Carry fewer readable cards. The dormant contactless card, the second current account, the store card you use twice a year: they are all readable and none of them are watched. They belong in a drawer at home.
  7. Choose the staffed till when the unattended machine looks tired. Unattended readers are where hardware gets fitted, because nobody is standing next to them for nine hours a day.

The alerts, the freeze switch, the statement habit and the drawer full of dormant cards can all be done in one sitting. The other three are things you do with your hands in the thirty seconds before you pay.

Questions readers keep asking

What is ghost tapping, in one sentence? It is an NFC relay attack: a stolen card credential, typically already loaded into a mobile wallet, is relayed from one device to another somewhere else in the world, so a fraudster can make a tap-to-pay purchase that the terminal treats as card-present, as Group-IB documents.

Is physical skimming finished, then? No. A skimming device on a Rhode Island bank drive-through was the thread that led to six people being charged in 2024 over a scheme that stole more than $300,000 at banks and shops across Rhode Island and Massachusetts. Old methods do not retire when new ones arrive; they just stop making headlines.

Why do the mules buy goods instead of taking cash? Because goods launder themselves. Recorded Future's research describes stolen card details being relayed to mules in person so they can obtain physical items that are resold for profit, which draws far less attention than moving money.

How would I know it had happened to me? Set yourself up to know quickly, tonight. Open your banking app, find the control that locks or freezes a card, and use it once so you know exactly where it lives. Then switch on per-transaction alerts for every card you carry. A statement read line by line will eventually show you a purchase in a currency or a city you have never visited, but alerts show you the first one rather than the twelfth, and the freeze switch is what turns knowing into stopping.

The verdict: proximity is no longer proof

For twenty years, contactless payment leaned on a comforting assumption: the card had to be there. Relay fraud retires that assumption, and the tooling to do it spread through Telegram tutorials rather than laboratories. Card fraud reports and values are up across the UK, the EU and the US, and the newest method is the one that needs nobody in your car park.

So stop thinking only about where your card is, and start thinking about who else could be holding its details. That is the part of this chain you have some say over, and the moves that give you that say are free.

Vaultskin publishes this blog and makes leather wallets in London, including RFID wallets whose lining blocks wireless card reads at close range. To be clear about the limits of that: a shielding lining does not stop a skimmer fitted inside a card slot, and it does not stop Ghost Tap, which relays credentials already provisioned into a mobile wallet. The checks above are what apply to those two.

Back to blog

Leave a comment

Please note, comments need to be approved before they are published.