Mobile Wallet Push-Provisioning Scam via Apple Pay
Scammers phish your card number, then start adding it to Apple Pay on their own iPhone. When your bank's Apple Pay verification code arrives, a fake "fraud team" call pressures you to read it back — enrolling your card on their device.
Part of: Mobile Wallet Push-Provisioning Scams
Last reviewed: 24 July 2026
Apple Pay is built so a card can only be added to a device after the issuing bank confirms the real cardholder approved it — normally by sending a one-time verification code. That safeguard is precisely what this scam weaponizes. Because most people have added their own card to their own iPhone but never approved an enrollment for someone else, the code feels routine and its true purpose goes unnoticed. The scammer already has your card number; the only missing piece is that Apple Pay verification code, and a well-timed "fraud department" call is engineered to make you hand it over. The distinction that matters most: that code approves a wallet on their phone, it never cancels anything.
How this scam works on Apple Pay
The scammer opens the Wallet app on their own iPhone, taps to add a card, and types in the number, expiry, and security code harvested from an earlier phishing page. Apple hands verification to your bank, which — on its "yellow path" — sends you a one-time code to approve the enrollment, and that message usually names Apple Pay directly. Timed to the second, a call or text posing as your bank's fraud team (sometimes as "Apple Pay support") says an Apple Pay setup must be denied by reading the code back. Reciting it instead completes the enrollment. Your card now lives as a tokenized Device Account Number on their device — and can be added to their Apple Watch, iPad, and Mac too — so they tap-to-pay in stores and check out with the Apple Pay button online and in apps. Statements show contactless Apple Pay charges from hardware you've never owned, while your physical card never left your pocket.
Common red flags
- A one-time code whose own text says "verification code for Apple Pay" or "to add your card to Apple Pay"
- A caller claiming to be your bank — or "Apple Pay support" — asking you to read the code back to deny an Apple Pay setup
- The Apple Pay code arriving at almost the same moment as an unexpected "security" call
- Charges showing as Apple Pay or contactless from a device you don't recognize while your card is still in your pocket
- A caller who already has your card number and only needs the Apple Pay code to "verify identity"
- Being told that reading the code back will block or reverse the Apple Pay enrollment
- Pressure to act within minutes because the "Apple Pay request will expire"
How to protect yourself
- Read any code message in full — if it names Apple Pay or a mobile wallet, never recite it to a caller
- Remember that an Apple Pay code is only ever typed into your own Wallet app, never read aloud to anyone who contacts you
- Hang up and call your bank on the number printed on your card to ask whether an Apple Pay provisioning attempt is on your account
- In your banking app, review the list of devices your card is enrolled on for Apple Pay and remove any you don't recognize
- Ask the bank to de-provision the Device Account Number and reissue the card if a code was shared
- Turn on transaction alerts so tap-to-pay and Apple Pay web or in-app charges surface immediately
How to report it
- Call your card issuer immediately, report that an Apple Pay provisioning code was shared, and have them remove the wallet enrollment and reissue the card
- Dispute any Apple Pay contactless, in-app, or web charges you didn't make
- Report the impersonation to the bank being spoofed, and if the caller claimed to be Apple, to Apple Support
- File a report with your national fraud service (reportfraud.ftc.gov in the US, or Action Fraud in the UK)
- Preserve the code message with its full wording and timestamp, the caller's number, and any earlier phishing links
Frequently asked questions
How is this Apple Pay code different from a normal bank login code?
It's a provisioning code — it authorizes adding your card to a device's Wallet, not logging in or cancelling a charge. Its own message text usually names Apple Pay. Reading it to a caller completes the enrollment on their iPhone rather than stopping anything, which is why the scammer needs you to recite it within minutes.
The scammer never had my physical card, so how are they paying?
Apple Pay stores a tokenized Device Account Number, not your actual card number, so a digital copy on their iPhone, Apple Watch, iPad, or Mac can tap-to-pay in stores or check out with the Apple Pay button online and in apps. Your plastic staying in your pocket is exactly why the theft goes unnoticed until charges appear.
How do I check whether my card is on someone else's Apple Pay?
Your banking app or the bank's phone line lists the devices your card is provisioned to for Apple Pay; remove any you don't recognize. Apple can't see or remove it for you — the issuer controls the token, so call them to de-provision the Device Account Number and reissue the card.