Ghost Tapping: The Tap-to-Pay Scam Draining Cards

A professional at a walnut desk beside blank contactless cards and a Vaultskin VAULTCARD RFID-jamming card

Ghost Tapping: The Tap-to-Pay Scam Draining Cards

In March 2025, the Knox County Sheriff's Office in Tennessee announced arrests of 11 people accused of buying tens of thousands of dollars in gift cards using mobile wallets built from phished card details, in what authorities called the first arrests in the US for this style of tap-to-pay fraud, Krebs on Security reports. The scheme now has a name: ghost tapping. It has also reached the Better Business Bureau's list of active scam warnings. Four free habits that reduce your exposure are below.

Gift cards, phished wallets, and an arrest in Tennessee

The Knox County case did not involve a stolen physical card at all. Investigators said the group had loaded stolen payment details onto mobile wallets, most likely obtained through phishing, then walked into stores and tapped to pay as if the cards were their own (Krebs on Security).

A parallel case picked up in Sacramento shows the same pattern at speed. Two men were arrested after running a mobile app that cycled through more than 80 stolen payment cards at a Target store, tapping through them one after another to buy $1,400 worth of gift cards before staff or systems caught up (Krebs on Security). Victims elsewhere have described losses building through a string of small, easy-to-miss transactions rather than one dramatic charge, with reported losses running past $1,000 before the pattern became obvious (Fox News).

How ghost tapping actually works

Contactless payment relies on near field communication, a radio protocol built on the assumption that a card or phone will be held within about 1.5 inches of a reader (BankInfoSecurity). Ghost tapping breaks that assumption. Card data, in the documented cases harvested by phishing rather than by skimming, is loaded onto a phone in one location, then relayed in real time to a second phone standing at a till anywhere else, using an app called NFCGate, originally built in 2015 by students at the Technical University of Darmstadt for legitimate research and since repurposed by criminal groups (BankInfoSecurity).

The result looks, to a cashier and to the payment network, like an ordinary tap. The card was never physically present, and the person tapping may be hundreds of miles from the account holder. This is not skimming in the traditional sense of a hidden reader brushing a wallet in a pocket. It is a software relay that turns a phished card into cash-out capacity anywhere the crew has a phone and a till willing to take a tap (BankInfoSecurity).

How big is this, really

Ghost tapping is not a one-off curiosity. Researchers tracked at least $355,000 in illegitimate transactions linked to a single point-of-sale malware vendor advertising openly on Telegram between November 2024 and August 2025, with one vendor group, TX-NFC, reportedly amassing more than 21,000 subscribers (Infosecurity Magazine). Arrests and advisories tied to this malware have surfaced in the Czech Republic, Singapore, Malaysia and the United States, with detections rising steadily from mid-2024 through late 2025 (Infosecurity Magazine). Visa's own fraud-control team blocked 134.3 million presumed fraudulent transactions of all kinds between July and December 2024, a figure covering the full range of payment fraud rather than NFC relay fraud specifically. That same Visa report separately flagged a fresh resurgence of NFC relay fraud in spring 2025 (American Banker).

How likely is any one cardholder to be hit? Contactless is now the default way most people pay: the UK alone has more than 150 million contactless cards in issue, with contactless accounting for 76 percent of debit transactions and £25.1 billion spent that way in March 2024 alone (UK Finance). Ghost tapping rides on that same infrastructure, and the figures above describe an underground economy in the tens of thousands of subscribers, not a handful of opportunists. It remains a fraction of all contactless spending, but it is documented, growing, and organised enough to have its own malware vendors advertising openly.

Protecting your cards: the four free habits

Most of what stops ghost tapping costs nothing. The scheme depends on stolen card data reaching a criminal's phone in the first place, in the documented cases via phishing, so the strongest defence is refusing to hand that data over.

  1. Your card should be readable only when you choose. Never tap it against someone else's phone, and never follow NFC instructions from a stranger. Legitimate banking apps do not typically ask you to scan your own card against a reader on someone else's request, so any message asking for this should be treated as a likely scam.
  2. Treat unsolicited "verify your card" links and apps with suspicion. The arrests documented so far began with phishing, not a technical exploit of the card itself (Krebs on Security).
  3. Keep only the cards you actually use loaded into mobile wallets. Fewer stored cards mean less for a single phishing attack to harvest at once.
  4. Watch statements for small, easy-to-ignore charges, a pattern described in cases reported by Fox News (Fox News).

The verdict

Ghost tapping is a phishing problem wearing a payments disguise. The arrests in Tennessee and California show real people caught relaying real stolen card data through real tills, not a theoretical exploit. The fix that matters most is behavioural and free: guard your card details, ignore anyone asking you to tap for them, and watch your statement for the small charges that give the game away.

FAQ

How do criminals get my card details in the first place? In the arrests documented so far, the starting point was phishing, tricking a victim into entering card details on a fake site or app (Krebs on Security).

Is ghost tapping only happening in the US? No. Arrests and law enforcement advisories tied to this malware have been recorded in the Czech Republic, Singapore and Malaysia as well as the United States, with detections rising through 2024 and 2025 (Infosecurity Magazine).

What should I do if I spot an unfamiliar small charge on my card? Report it to your card issuer immediately rather than waiting to see if more appear. In cases reported by Fox News, ghost tapping losses built through a string of small transactions before a victim noticed, so early reporting limits how much of that string plays out (Fox News).

Zurück zum Blog

Kommentar hinterlassen

Bitte beachte: Kommentare werden erst nach Prüfung veröffentlicht.