Ghost Tap (NFC Relay Fraud)
A contactless-payment fraud in which malware relays a victim's phished or wallet-provisioned card over NFC in real time to a mule standing at a payment terminal anywhere in the world, letting the mule tap-to-pay without the physical card.
Also known as: ghost tap, NFC relay fraud, NFCGate fraud
Last reviewed: 27 July 2026
Ghost Tap is a name for real-time NFC relay fraud. After a criminal has phished a card and enrolled it in a mobile wallet — or compromised a victim's phone — relay software (such as tools derived from NFCGate) forwards the card's contactless signal from the victim's or attacker's device to a second device held by a mule at a checkout terminal. The mule taps to pay as if holding the real card, potentially far from the victim, and across many small transactions that evade some fraud checks.
The technique separates the two things that normally have to be together for a contactless payment — the card credential and the physical presence at the terminal — and relays one to the other over the internet. It typically follows a successful card-phishing or wallet-provisioning attack, so protecting the one-time codes used to add a card to a wallet is a key defence.
Because the transactions look like ordinary in-person taps, victims often notice only when reviewing statements; prompt card locking and transaction alerts limit the damage.