NFC-Relay "Ghost Tap" Scams via Contactless Payments
Criminals relay your contactless card or wallet signal live to a mule tapping at a real reader, exploiting no-PIN limits and tap-and-go speed to run many small purchases while your card stays in your pocket.
Part of: NFC-Relay ("Ghost Tap") Fraud
Last reviewed: 24 July 2026
Contactless is built for speed and trust: a tap under a set limit clears in a moment with no PIN, so nobody expects a wait or a challenge. Ghost-tap fraud rides that exact convenience. Once criminals control a card credential, through phishing plus a one-time code or through malware on your phone, relay software carries the tap itself across the internet to a mule holding a phone or device at a genuine reader. The reader sees a normal contactless payment and approves. The distinction that matters most: the contactless rail assumes a card answering at short range means the owner is present, and a relayed answer looks identical to a real one.
How this scam works on contactless payments
The relay presents at an ordinary contactless reader, so the terminal treats it as a legitimate tap-and-go. Criminals deliberately keep each purchase under the contactless no-PIN threshold, because at that level the transaction clears without the one step they cannot fake. They then chain many small taps in quick succession, spreading them across shops, self-checkouts, vending machines, and transit gates where contactless is the default and a lone person tapping repeatedly draws no attention.\n\nBecause contactless limits are per-transaction, not per-day, the mule taps again and again until a cumulative counter forces a PIN, then moves to a fresh terminal or a different merchant to reset the pattern. The same relayed credential can be tapped in several cities, and often several countries, in one spree. On a mobile wallet, the relayed device answers exactly as your phone would at the reader, which is why the charges look like routine in-store taps rather than online fraud.
Common red flags
- A cluster of small contactless purchases just under the no-PIN limit, in quick succession on your statement
- Contactless charges at terminals in a city or country you were not physically in
- A message or call asking you to read back a one-time code to 'verify' or 'protect' your contactless card
- An unexpected notification that a new device or mobile wallet was added to your account
- Charges at transit gates, self-checkouts, or vending machines you never used
- A prompt to install an app or click a link to keep tap-to-pay 'active'
- Repeated identical or near-identical small amounts that stop just short of triggering a PIN
How to protect yourself
- Never read a one-time passcode or card verification code aloud to a caller or into a message — that code is what enrols your card into a stranger's wallet for relaying
- Turn on instant transaction alerts so a burst of small contactless taps surfaces the moment it starts
- Review the devices and mobile wallets linked to your card in your banking app, and remove any you don't recognise
- Lower your contactless spending limit with your bank if the option exists, so fewer taps clear without a PIN
- Install apps only from official app stores, and never from an 'update' or 'redelivery' link sent by text or email
- Keep your card in an RFID-blocking sleeve and be wary of any unsolicited contact about your card's security, however routine it sounds
How to report it
- Freeze or lock the card immediately in your banking app, then call your bank's official number to report ghost-tap fraud and request a reissue
- Ask the bank to remove any unrecognised device or mobile wallet linked to your card
- List every unfamiliar contactless transaction with times, amounts, and locations, and formally dispute them
- Report the fraud to your national fraud or cybercrime service
- On the affected phone, uninstall any recently added app and run a security scan, from a different trusted device if malware is likely
Frequently asked questions
How can a contactless payment go through if my card never left my pocket?
Relay software forwards the tap itself across the internet. One end sits near your card or infected phone, the other with a mule at a real reader. The reader's request travels back to your credential and its answer travels forward, so the terminal sees a normal contactless tap. Nothing physical moves, which is why charges appear while your card sits untouched in your wallet.
Why are the fraudulent charges always small amounts?
Contactless purchases under a set limit clear without a PIN, the one step criminals cannot fake. By keeping every tap below that threshold, they avoid the challenge entirely. They then run many small taps rather than one large one, moving between terminals whenever a cumulative counter threatens to force a PIN, so the spending stays frictionless.
Does lowering my contactless limit actually help?
It can reduce exposure by forcing a PIN on smaller amounts, though it does not stop the underlying phishing or malware that hands criminals the credential in the first place. Treat a lower limit as one layer alongside the essentials: never share one-time codes, act on new-device notifications, and only install apps from official stores.