Yes, it is possible to get scammed via contactless payment through techniques like "ghost tapping" or "NFC relay attacks," where scanners steal data or initiate unauthorized charges. While rare, scammers can use portable readers in crowded areas to skim information from cards or phones at close range.
Here are some of the most secure payment methods available online:
Your data is encrypted and your details are kept safe during every transaction. The retailer must enter an amount into the payment terminal first, and then you need to hold your card very close to it. This means you can't accidentally spend money from walking by or being near the payment terminal.
Contactless Tap
Criminals have developed an RFID-enabled card cloning device they can conceal on their bodies while walking down the street. This allows them to steal information from RFID-enabled cards just by being in close enough proximity to their owners.
A thief can easily electronically pickpocket your contactless card or device. There are smartphone applications that enable the phone to read some data from a contactless enabled card or device, but they can only read the account number and expiration date.
An NFC relay attack is a contactless payment fraud in which criminals intercept and relay the communication between a payment card (or device) and a payment terminal, often without the cardholder's knowledge.
The risk of fraud occurring during a tap-and-pay transaction is minimal. Some people purchase RFID-blocking wallets to protect their cards, but the Identity Theft Resource Center states that this is an unnecessary — and often expensive — precaution.
The the actual card details can be stolen by hackers, but that wouldn't involve Apple Pay. Neither Apple or you phone store the card data in unencrypted form. Apple Pay only has encrypted data which is useless to hackers. You and the bank have card details.
Line your wallet or cardholder with tin foil to block scamming devices from reading your card. If you don't fancy the DIY approach, there are products like RFID readers available which do the same thing. Don't let anyone take your card out of sight while taking a payment – even for just a few seconds.
Yes, tapping your card is generally considered safer than inserting it because it uses tokenization and encrypted one-time codes, preventing your actual card details from being exposed to the terminal and reducing the risk of skimming, keeping your card in your possession at all times, and often requiring biometric authentication with mobile wallets, though both methods are secure due to EMV technology. While both tap and insert (chip) use strong EMV security, tapping avoids physical contact with potentially compromised readers and keeps your data encrypted for each transaction, making it a superior choice for security and hygiene.
Because contactless payments require neither PIN nor signature authorisation, lost or stolen contactless cards can be used to make fraudulent transactions.
Contactless fraud can happen in 2 ways. The first is when a criminal steals another person's card and then uses contactless technology to make small purchases in shops. The second is when someone uses a “skimming device” to access the personal information of a card or ID owner.
Ways scammers reach you
And remember: Apple Pay doesn't make you immune to fraud. Your card details can still be exposed through third-party data breaches, stolen physical cards, ATM skimmers, and other attacks. Monitor your bank and credit card statements regularly for any suspicious activity — even if you primarily use Apple Pay.
Examples of Card Cloning Fraud
Whether you have magnetic stripe cards or you use a contactless card to make payments, be aware that cards can be cloned on a blank card.
There are a few warning signs to watch for if you suspect your wallet might be compromised:
There's no way anyone can access to the important details such as the security code on the back of the card, your name and address, or bank account details.
The 2/3/4 rule is a guideline, primarily used by Bank of America, that limits how many new credit cards you can get: no more than 2 in 30 days, 3 in 12 months, and 4 in 24 months, helping to prevent over-application and manage hard inquiries on your credit report. While not universal, it's a useful benchmark for responsible card application, though other banks have different rules (like Chase's 5/24 rule).
When you tap, your card doesn't need to make contact with potentially compromised card readers. This eliminates the opportunity for skimmers to capture your card's magnetic stripe data or the chip embedded data. Each tap-to-pay transaction generates a one-time code that can't be reused.
If you were scammed on Apple Pay, immediately contact your bank/card issuer to dispute the charge, as they handle fraud for linked cards; for Apple Cash, report it via the Wallet app, but funds are hard to recover as it's like cash, so act fast, report to authorities (FTC, police), and secure your Apple ID, though refunds are difficult for accepted Apple Cash payments.
Return something you bought in a store
Find your store receipt. Bring the receipt and the item to the store. If the merchant asks you to swipe your card, hold the back of your phone to the contactless payment terminal. Tip: The retailer will let you know when you should expect your refund.
Data Theft and Skimming
Another significant risk associated with the contactless payment method is skimming, a type of data theft. Skimming involves fraudsters using illicit devices to capture the data transmitted during a contactless transaction.