Mobile Wallet Push-Provisioning Scams
After phishing your card number, scammers pose as your bank's fraud team and get you to read back a one-time code — but that code enrols your card in a digital wallet on their own phone, letting them tap-to-pay with your money.
Last reviewed: 24 July 2026
What this scam is
A mobile-wallet push-provisioning scam is a card-fraud technique that ends with your card living inside a digital wallet — Apple Pay or Google Pay — on a criminal's phone, spending your money by tap-to-pay. It has two stages. First the scammer obtains your card number, usually through an earlier phishing message, a fake retailer checkout, or breach data. Adding a card to a wallet then triggers your bank to send a one-time provisioning code to confirm the cardholder approved it — and that code is the whole game. So the scammer calls or texts posing as your bank's fraud department, claims suspicious activity, and asks you to "confirm your identity" by reading back the code that just arrived. The distinction that matters most is what that code actually authorises: it is not a login code or a transaction you are cancelling, it is your explicit permission to enrol your card in someone else's wallet. Once you read it out, the card is provisioned on the scammer's device, and every tap they make is treated by your bank as a genuine, cardholder-approved payment.
How it works
The attack chains two frauds. In the setup phase the scammer harvests card details — long number, expiry, and often the security code — from a phishing site, a spoofed delivery or bank text, or purchased breach data. They then begin adding the card to a wallet on their own phone. At that moment the bank generates a provisioning one-time code and sends it to you, the real cardholder, by SMS, email, or in-app message, to verify the enrolment. The scammer needs that code within minutes, so a call or text arrives almost simultaneously, timed to the code's delivery. Posing as the bank's fraud team, they describe an alarming but fake problem — a blocked transaction, or an attempted wallet setup "we need you to deny" — and instruct you to read back the number to verify your identity or cancel the charge. The framing inverts reality: reading it back completes the enrolment rather than stopping it. With the card now provisioned, they spend contactlessly in stores or online, often quickly and across several purchases, before you notice charges you never made on a card still physically in your pocket.
Why this scam works
The scam exploits a genuine but unfamiliar security step. Most people have never added someone else's card to a wallet and don't know that a provisioning code even exists, so they can't recognise what they are approving. The code arrives from the bank's real number and carries real bank wording, which makes the follow-up "fraud department" call feel corroborated rather than suspicious. Urgency does the rest: a warning that your account is under attack pushes you to cooperate fast, and reading a number back feels harmless — passive, not like sending money. Crucially, the victim's own card never leaves their wallet, so nothing looks stolen, and the eventual charges are authorised transactions the bank initially treats as legitimate, which delays detection and complicates the dispute.
Common red flags
- An inbound call or text claiming to be your bank's fraud department that asks you to read back a code
- A one-time code whose own message text mentions Apple Pay, Google Pay, or adding a card to a wallet
- A code arriving at almost the same moment as an unexpected 'security' call
- Pressure to act within minutes to 'cancel' or 'deny' a transaction by reciting a number
- A caller who already knows your card number and asks only for the code to 'verify identity'
- Being told that reading the code back will stop or reverse fraud
- Any request to confirm, verify, or approve something using a code that was sent to you
Sanitized example messages
Illustrative, sanitized examples. Personal details are replaced with placeholders such as [phone number] and [fake link].
This is the fraud team at your bank. We've blocked an attempt to add your card to a wallet. To deny it, please read back the 6-digit code we just sent.
Security alert: a mobile wallet setup was requested on your card. Reply with the verification code now to cancel this request.
To confirm your identity and release the hold on your account, read me the code that arrived on your phone in the last minute.
We're seeing suspicious activity. Do not ignore the code we sent — read it to the agent now to protect your account.
How to verify before you act
Read the code's own message before you speak. Bank provisioning texts state plainly what they authorise — usually something like "use this code to add your card to Apple Pay / Google Pay" or "to set up a mobile wallet". If a caller is asking you to read back a code whose own text describes adding a card to a wallet, that caller is enrolling your card on their device, full stop. No genuine bank ever needs you to read a code back to them; codes are for you to enter yourself, never to recite to an inbound caller. Hang up on anyone pressuring you, then call your bank on the number printed on your card and ask directly whether any wallet-provisioning attempt is on your account. Treat the coincidence of a code and a simultaneous "fraud department" call as the scam itself, not two unrelated events.
Payment methods used
- Mobile wallet tap-to-pay
- Contactless in-store purchases
- Online card purchases
Who is usually targeted
- Bank cardholders
- Online shoppers
- People already targeted by phishing
- Less tech-familiar cardholders
What to do immediately
- Contact your bank immediately on the number printed on your card and tell them a wallet-provisioning code was shared
- Ask the bank to freeze or reissue the card and remove any mobile-wallet enrolment tied to your account
- Check your statement and alerts for tap-to-pay or online charges you didn't make, and dispute them
- Change your online banking password if you entered it on any linked phishing page
- Report the fraud to your national fraud service and to the bank being impersonated
- Preserve the code message, the caller's number, and any phishing links before deleting anything
How to prevent it
- Never read any one-time code back to someone who called or messaged you — codes are only ever entered by you, never recited aloud
- Read the full text of any code message: if it mentions adding your card to Apple Pay, Google Pay, or a mobile wallet, do not share or act on it
- Hang up on 'fraud department' calls and call back on the number printed on your card
- Treat a code arriving at the same moment as an unexpected bank call as a red flag, not a coincidence
- Guard your card number as carefully as the code — the scam needs both, and phishing supplies the number
- Turn on transaction alerts so wallet and tap-to-pay charges surface immediately
Evidence to preserve
- The one-time code message showing its full wording and the time it arrived
- The caller's phone number or the sender ID of the text, with call logs and timestamps
- Any phishing message or website used to capture your card number earlier
- Statements and transaction records showing the unauthorised wallet purchases
Where to report it
- Action Fraud (UK) — UK national fraud & cybercrime reporting centre
- FTC ReportFraud (US) — US Federal Trade Commission fraud reports
- FBI IC3 (US) — US Internet Crime Complaint Center
- Scamwatch (Australia) — Australian competition & consumer reporting
- Your bank's fraud line — Use the number on the back of your card or in your banking app — never a number the caller gives you
Always verify reporting routes and emergency contacts on the official government or agency website for your country.
Frequently asked questions
How can a scammer spend my money when my card is still in my pocket?
Because they added a digital copy of your card to a wallet on their own phone. A mobile wallet doesn't need the physical card — it needs your card number plus the one-time provisioning code the bank sends to approve the enrolment. Once you read that code back, their phone can tap-to-pay or check out online as if it were yours. The plastic never moves, which is exactly why the theft stays invisible until charges appear.
The code came from my bank's real number. Doesn't that mean the call is genuine too?
No. The code genuinely came from your bank — because the scammer triggered it by trying to add your card to a wallet. The call or text asking you to read it back is separate and fake, timed to land alongside the real code so it feels corroborated. Banks send codes for you to enter yourself; they never call and ask you to recite one. A real code plus an inbound request for it is the signature of this scam.
What should I do if I already read the code out loud?
Act fast. Call your bank on the number printed on your card, say a wallet-provisioning code was shared, and ask them to remove the wallet enrolment, freeze the card, and reissue it. Review recent transactions for contactless or online charges you didn't make and dispute them — these are often recoverable when reported quickly. Then change any banking password you may have entered on a linked phishing page and report the incident.