NBC10 consumer alert

Watch: how ghost tapping works

SEVN-X cybersecurity expert Matt Barnett joins NBC10 Responds to explain how deceptive or concealed contactless readers can be used to attempt unauthorized payments - and what you can do before your next tap.

Quick answer

What is ghost tapping?

Ghost tapping is a contactless-payment scam in which someone uses a concealed or misleading payment reader to attempt a charge - or persuades you to tap for a transaction you did not fully understand. The most practical defenses are to verify the merchant and amount before tapping, require a passcode or biometric check for mobile payments, protect physical cards when they are not in use, enable real-time transaction alerts, and report suspicious charges immediately.

The important reality check

The phrase ghost tapping is useful shorthand, but it can make the threat sound more magical than it is. Near-field communication, or NFC, works at very short range. A criminal still needs a compatible reader, a merchant account or another way to route a payment, and enough proximity - or enough social engineering - to get a card or device near the terminal.

There is also a crucial difference between attempting an unauthorized transaction and copying everything needed for unlimited future purchases. EMVCo explains that an EMV contactless transaction generates a one-time security code. Modern mobile wallets add tokenization and transaction-specific security data as well.

What that means for you

Do not dismiss the risk - but do not assume that a nearby reader can silently empty an account or create a perfect clone of every contactless card. The more realistic concern is an unauthorized charge, a misleading transaction, or a victim being rushed into approving a payment without checking the details.

Common scenarios

How a ghost-tapping scam can happen

Scenario 01

A concealed reader gets close to a physical card

An attacker may carry a portable payment reader through a crowded area and bring it close to a contactless card. The attempt may be designed to look like an ordinary bump or moment of crowding. Distance, card settings, issuer controls, transaction limits, and terminal configuration all affect whether a charge can succeed.

Scenario 02

A fake vendor or fundraiser asks you to tap

At a festival, market, transit hub, or other busy venue, a scammer may pose as a seller or fundraiser and create urgency around a small payment. The terminal may show the wrong amount, an unfamiliar merchant, or no clear details at all. Here, the tap is not hidden - the deception is.

Scenario 03

A legitimate-looking terminal hides a bad transaction

A compromised, substituted, or attacker-controlled terminal may be presented as legitimate. A victim who is distracted or rushed may approve a higher amount or pay a different merchant than expected. Always read the screen before bringing your card or device near the reader.

Can someone charge your phone without Face ID or a passcode?

For ordinary Apple Pay purchases, payment information normally is not sent until the user authenticates with Face ID, Touch ID, or a passcode. Apple also uses a device-specific account number and a dynamic security code instead of sending the original card number. Apple documents those controls here.

Google Wallet similarly requires a screen lock and user verification for payment methods. Depending on the device and how recently you authenticated, Google may not ask again for every immediate transaction. Review the current Google Wallet verification guidance for your device.

One setting deserves special attention

Apple Express Mode and some Google Wallet transit settings can allow eligible transit payments without the normal unlock step. These modes are designed for speed at transit gates, but you should review them so you know exactly what your locked device can authorize.

Protection checklist

Seven ways to reduce your risk

1. Verify the merchant and amount before you tap

Pause long enough to read the terminal. If the display is hidden, the merchant name is unfamiliar, or the amount is wrong, do not approve the payment.

2. Keep your card and phone under your control

Do not hand an unlocked phone to a stranger or let anyone take your card out of sight. At events, be cautious when an unfamiliar person pushes a reader toward you or creates urgency.

3. Use a strong device lock and payment authentication

Enable a strong passcode and supported biometric authentication. Check your wallet and transit-payment settings instead of assuming every tap requires the same verification.

4. Shield physical contactless cards when practical

An RFID-blocking sleeve or wallet can prevent a nearby reader from communicating with the card while it is stored. It is a simple additional control - not a substitute for alerts and account monitoring.

5. Turn on real-time transaction alerts

Ask your bank or card issuer to notify you of every purchase - or set the lowest available threshold. An alert can reduce the time between a fraudulent charge and your response.

6. Review recent transactions, not only monthly statements

Small test charges can be easy to miss. Check the issuer's app regularly and investigate unfamiliar merchant names rather than waiting for the end of the billing cycle.

7. Treat unexpected tap requests like unexpected links

Slow down, verify independently, and walk away if the situation does not make sense. The strongest control is often refusing to complete a transaction under pressure.

Act quickly

What to do after a suspicious contactless charge

Lock the card or payment method. Use the issuer's app if available, then contact the bank or card issuer through the number on the card or its official website.

Report and dispute the charge immediately. Do not wait for more transactions. Reporting deadlines and potential liability can differ between credit cards, debit cards, and account transfers.

Ask whether the card should be replaced. The issuer can determine whether the physical card, wallet token, or another payment credential needs to be suspended and reissued.

Preserve the details. Save the alert, merchant descriptor, amount, date, time, location, receipt, and any description of the reader or person involved.

Continue monitoring. Review related accounts for additional activity. If your bank does not resolve the problem, you can use the CFPB complaint process.

Why speed matters: The CFPB advises consumers to notify their bank or credit union right away about an unauthorized transaction. For certain debit-card losses, reporting within two business days can affect liability, and a 60-day statement deadline can also apply. Review the CFPB guidance and follow your issuer's instructions.

What organizations and event operators should do

Ghost tapping is also a trust and physical-security problem. Markets, festivals, nonprofits, retailers, and other organizations that allow mobile payment terminals should make legitimate transactions easy to recognize and rogue devices difficult to introduce.

A practical control set

• Inventory and assign every portable terminal.

• Use visible merchant identification and show the amount before every tap.

• Restrict who can configure, carry, or replace payment devices.

• Train staff to challenge unknown terminals and suspicious solicitation.

• Monitor refunds, unusual transaction patterns, and merchant-account changes.

Frequently asked questions

Ghost tapping FAQ

Is ghost tapping real?

A nearby or deceptive payment reader can be used to attempt an unauthorized transaction, so the underlying risk is real. However, some viral descriptions overstate what can be stolen from a modern EMV card or authenticated mobile wallet.

Can a contactless card be charged through a wallet or pocket?

A reader must be close enough to communicate with the card, and materials or other cards can interfere. A shielding sleeve or RFID-blocking wallet can prevent that communication while the card is stored.

Can a criminal clone my contactless card with one tap?

Modern EMV contactless transactions generate a one-time security code, so reading a card is not the same as obtaining reusable data for unlimited future EMV purchases. That does not make unauthorized charges impossible; it makes the 'perfect clone from a quick bump' description misleading.

Is a mobile wallet safer than tapping a physical card?

Mobile wallets can add device authentication, tokenization, and transaction-specific security data. They are not risk-free, and transit or express-payment settings may work differently, but their controls can make an unintended payment harder to authorize.

Do RFID-blocking wallets work?

A properly made shield can block the radio communication used by a nearby contactless reader. Test the product with your own card and a legitimate terminal, and remember that shielding does not protect you when you deliberately remove the card and approve a deceptive transaction.

What is the first thing I should do after an unfamiliar charge?

Lock the card or payment method and contact the issuer immediately through a trusted channel. Then dispute the transaction, preserve the details, and follow the issuer's replacement and monitoring instructions.

Video transcript

Matt Barnett on NBC10 Responds

Transcript lightly edited for readability.

NBC10 introduction: A warning tonight about a scam that can steal your money in seconds. In some cases, the scammer doesn't even need to interact with you. NBC10 Responds reporter Valeria Aponte Feliciano explains how it works so you don't become a victim.

Valeria Aponte Feliciano: Tap to pay has become a common way to buy something.

Matt Barnett: Being able to just tap and go makes your life very easy.

Valeria Aponte Feliciano: But the same convenient technology can also make it easier to steal your money.

Matt Barnett: That reader is also able to be duplicated or cloned or just registered by an attacker.

Valeria Aponte Feliciano: Cybersecurity expert Matt Barnett is talking about what's called ghost tapping.

Matt Barnett: It's basically the modern version of pickpocketing.

Valeria Aponte Feliciano: Here's how it works: a stranger can bump into or get close to you with a concealed card reader. That reader could charge your contactless-enabled card or the digital wallet on your phone without your authorization. Another example is in clear sight. These scammers could be found at public events - think an open market or a festival. They approach you saying they're looking for a small donation or even pretending to be a vendor trying to sell you a product.

Valeria Aponte Feliciano: The scammer can work quickly, asking you to tap to pay to complete the transaction in just a matter of seconds.

Matt Barnett: It's the same amount of time as when you tap to pay - seconds or less.

Valeria Aponte Feliciano: You are the best defense when protecting your money from ghost tapping. Make sure facial recognition or a password is required to use your digital wallet.

Matt Barnett: You kind of have to look at it and use Face ID, or you have to put your passcode in before it will unlock the readability of those cards.

Valeria Aponte Feliciano: For credit cards, Barnett suggests using an RFID blocker. It's as simple as sliding your card into a sleeve.

Matt Barnett: A sleeve that has some metal sheeting in it, or some other technology that won't allow it to be read unless you remove it.

Valeria Aponte Feliciano: Check your account daily for unauthorized charges. You can also set up transaction alerts with your bank so they send real-time notifications for every charge. Always confirm payment details before you tap your card or phone. That means verifying the merchant's information and the amount on the terminal screen.

Achieve better cybersecurity

Turn fraud awareness into practical protection

Payment fraud crosses technology, identity, physical security, employee awareness, and incident response. SEVN-X helps organizations find the gaps, prioritize the real risks, and build controls that work in the field.

Meet with a SEVN-X expert

Looking specifically at facilities and on-site controls? Explore SEVN-X Physical Security services.

Authoritative resources

EMVCo: EMV Contactless Chip - how contactless transactions and one-time security codes work.

Apple: Apple Pay security and privacy overview - authentication, tokenization, dynamic codes, and Express Mode.

Google Wallet: Verify it's you to make a purchase - supported screen locks and transit exceptions.

Consumer Financial Protection Bureau: Unauthorized transactions - reporting and investigation guidance.

You may also like

Does Your Office Miss You?
Does Your Office Miss You?
21 January, 2025

The New Normal It's no surprise that we live in a digital age. Particularly in this COVID era—where the majority of the ...

The Dark Web Exposed Part 1
The Dark Web Exposed Part 1
21 January, 2025

Introduction The dark web is a lot like rodeo riding: many have heard of it, few understand it, and most are too intimid...