Shocking Surge in NFC Payment Attacks Alarms Users Worldwide

What Is Happening With Contactless Payments?

Cybersecurity experts have discovered a new wave of cyberattacks targeting contactless payments made using NFC (Near Field Communication) technology. This is the same technology that allows people to pay by simply tapping their card or phone at a store counter. The attacks were first noticed among bank users in the Czech Republic but are now spreading across the world at an alarming rate.

A recent report by security company ESET shows that NFC payment attacks have grown 35 times more frequent since the end of 2024. That’s a massive jump in just a few months. Criminals are getting smarter and are finding ways to break into systems that were once considered safe.

NFC works by sending signals over very short distances—just a few centimeters. It’s used in many mobile payment apps and credit cards. People love the convenience, and as a result, the market is growing fast. From $21.69 billion in 2024, it is expected to go over $30 billion in the next few years. But this growth is also attracting cybercriminals who are using newer tricks to get past the security walls.

How the Attacks Work

The attacks combine several sneaky tricks to fool people and steal their money. Criminals start by sending fake SMS messages that look like they’re from a bank. These messages contain a link that leads to a fake banking website. The website then asks the person to install something called a progressive web app, or PWA. This app doesn’t come from the app store, so it skips most safety checks.

Once the victim installs the app and types in their banking password, the criminals can enter their bank account. But they don’t stop there. The scammers then call the victim, pretending to be from the bank, and say they need to install another app to protect their money. This second app is actually a virus called NGate.

Lazarus Rises Again: $4.2 Million Crypto Stolen in NFT Scam and Solana-to-Ethereum Swindle

This virus uses a tool called NFCGate, which was originally created by university students to test how NFC works. But now, hackers are using it in bad ways. Once the NGate app is installed, it can read credit card data when the card is held near the infected phone. The hackers then copy this data and make fake cards or use it for digital payments. They can even withdraw cash without anyone knowing.

In some cases, a version of the attack called Ghost Tap is used. It takes things a step further. Here, stolen card details and special one-time codes are added to the criminals’ Apple Pay or Google Pay wallets. Using these, they make many fake payments using contactless methods. Cyber experts say that entire “farms” of Android phones can be set up by hackers to do this on a large scale.

How People Can Protect Themselves

Even though these attacks are clever and dangerous, there are still ways people can protect themselves. Most importantly, they should never click on suspicious links or download apps from unknown sources. Real banks will never ask customers to install an app from a text message.

Iran’s Crypto Exchange “Nobitex” Struggles to Recover After being hacked by Pro-Israel hackers

People are also advised to use RFID-blocking wallets or card sleeves. These can help prevent anyone from secretly reading card data through a bag or pocket. It’s also a good idea to set daily or per-transaction limits for contactless payments. That way, if a criminal does manage to copy a card, they won’t be able to spend much.

In today’s world, where everything is going digital, it’s important to stay alert. NFC technology is useful and fast, but it must be used with care. By being cautious, people can stop these cyberattacks before they cause harm.

Renuka Bangale
Renuka is a distinguished Chartered Accountant and a Certified Digital Threats Analyst from Riskpro, renowned for her expertise in cybersecurity. With a deep understanding of cybercrimes, malware, cyber warfare, and espionage, she has established herself as an authority in the field. Renuka combines her financial acumen with advanced knowledge of digital threats to provide unparalleled insights into the evolving landscape of information security. Her analytical prowess enables her to dissect complex cyber incidents, offering clarity on risks and mitigation strategies. As a key contributor to Newsinterpretation’s information security category, Renuka delivers authoritative articles that educate and inform readers about emerging threats and best practices.

TOP 10 TRENDING ON NEWSINTERPRETATION

Former NFL player sentenced to over 16 years in prison for $197m medicare fraud — DOJ

A former NFL player who owned a marketing company...

The fraud division launches west coast strike force to target health care fraud schemes across arizona, nevada, and northern california — DOJ

The Justice Department’s National Fraud Enforcement Division (Fraud Division)...

Meta raises AI spending plans as investors look for clearer returns

Artificial intelligence (AI) is becoming the biggest focus for...

NASA uncovers long-running phishing plot aimed at sensitive defense technology

A major phishing and cyber-espionage operation has been uncovered...

EU develops data sharing rules for Google alongside digital identity wallet rollout

The European Union has launched a formal procedure through...

Elon Musk’s lawsuit against OpenAI raises questions over AI mission

A major legal battle is underway between OpenAI and...

Meta to cut 10 percent of workforce while Microsoft offers voluntary buyouts in the US

Two of the world’s largest technology companies are making...

Gold and Silver imports to be handled by 15 banks including HDFC, ICICI, Axis and Yes Bank till 2029

The Government of India has issued a fresh notification...

Trump informally gauges Vance and Rubio as public attention highlights contrasts

A new political development in the United States is...

Melania Trump denies connections to Epstein as Trump rejects media claims

Melania Trump made an unexpected public statement addressing claims...

Meta raises AI spending plans as investors look for clearer returns

Artificial intelligence (AI) is becoming the biggest focus for...

NASA uncovers long-running phishing plot aimed at sensitive defense technology

A major phishing and cyber-espionage operation has been uncovered...

EU develops data sharing rules for Google alongside digital identity wallet rollout

The European Union has launched a formal procedure through...

Meta to cut 10 percent of workforce while Microsoft offers voluntary buyouts in the US

Two of the world’s largest technology companies are making...