NFC-Relay ("Ghost Tap") Fraud
Criminals relay your card's contactless signal in real time to a mule standing at a payment terminal somewhere else in the world, letting them tap to pay with your card while it never leaves your pocket.
Last reviewed: 24 July 2026
What this scam is
NFC-relay fraud, often nicknamed "Ghost Tap," is a technique for spending your card at a physical terminal without holding the card. Contactless payments work through a very short-range radio conversation between a card or phone and a reader; relay software hijacks that conversation and stretches it across the internet. One device sits with the victim's card credential or infected phone, another sits with a mule at a real terminal somewhere in the world, and the tap that should happen over a couple of centimetres is instead forwarded live between them. The mule holds their phone to the reader, the relayed signal answers as though your card were present, and the purchase completes. The distinction that matters most is this: relay is not the same as card provisioning. Provisioning enrols a stolen card into a criminal's own mobile wallet so they can spend from it later; relay forwards the tap itself, in real time, so the fraud rides on your live card or wallet rather than on a static copy of it. That live quality is exactly what makes a ghost tap so hard to catch.
How it works
The setup begins with access to a card, obtained one of two ways. In the first, criminals phish your card number and a one-time verification code, usually through a fake bank message and a follow-up call, and enrol the card into a mobile wallet on their own device, so the credential they relay is one they now control. In the second, malware on your own phone, installed after a fraudulent app download or a message posing as your bank or a delivery service, quietly reads the contactless interface and forwards its signal while the physical card never leaves your possession. Either way, relay software links two ends over the internet: one near the card or wallet, and one with a mule at a genuine terminal. When the mule presents their phone, the reader's request is carried back to the card in real time and the card's answer is carried forward, so the terminal sees a normal tap. Because contactless purchases often clear without a PIN up to a threshold, the mules move fast, splitting spending across many small transactions in shops, transit gates, and cash-equivalent purchases before the account is frozen. The same relayed credential can be tapped repeatedly at terminals in different cities, and often different countries, in a single spree.
Why this scam works
The fraud borrows the trust the payment system places in a physical tap. A contactless terminal is built to assume that if a card can answer over such a short range, the cardholder is standing right there, so a relayed answer looks entirely legitimate. Sub-threshold amounts skip the PIN, removing the one step the criminal cannot fake. The geography works against detection too: a card tapped abroad minutes after being phished does not always trip a rule, and by the time it does, dozens of small purchases have gone through. Victims are disarmed earlier, in the phishing stage, because the fake bank message and the code request feel like routine security, not the enrolment of their card onto a stranger's phone. And with the malware variant, nothing is ever missing to notice.
Common red flags
- A message or call asking you to read back a one-time code to 'verify' or 'protect' your card
- A prompt to install an app or click a link to keep your card or account active
- An unexpected notification that a new device or mobile wallet was added to your account
- A cluster of small contactless purchases in quick succession on your statement
- Charges appearing at terminals in a city or country you were not in
- An app requesting broad permissions after being installed from outside an official store
- Pressure and urgency in any communication about your card's security
Sanitized example messages
Illustrative, sanitized examples. Personal details are replaced with placeholders such as [phone number] and [fake link].
Your bank: unusual activity detected. To secure your card, verify the 6-digit code we just sent. Do not share it with anyone except our agent.
Parcel could not be delivered. Install our redelivery app to reschedule and confirm your card details.
Alert: a new device was added to your mobile wallet. Tap-to-pay is now active on ANDROID-PHONE. If this was not you, call the number on the back of your card.
Card notification: purchase approved — GBP 38.50 at a store 300 miles away, one of several small taps in minutes.
How to verify before you act
The defining tell comes before the tap: legitimate banks and wallets never ask you to read back a one-time passcode to a caller, and no genuine "verification" enrols your card onto someone else's device. Treat any message or call that pushes you to approve a wallet, share a code, or install an app to "secure" your card as the attack itself. If you are told a wallet or device has been added to your account, that notification is worth acting on, not dismissing. Check your banking app for authorised devices and linked wallets, and remove any you do not recognise. Watch statements for a burst of small contactless purchases, especially in places you have not been. On your phone, install apps only from official stores, refuse "update" links sent by message, and review which apps you have granted broad permissions.
Payment methods used
- Contactless card
- Mobile wallet
- Debit card
- Credit card
Who is usually targeted
- Contactless card users
- Mobile wallet users
- Smartphone owners
- Online banking customers
What to do immediately
- Freeze or lock the card immediately in your banking app, and call your bank's official number to report ghost-tap fraud
- Ask the bank to remove any unrecognised device or wallet linked to your card and to reissue the card
- Change your online banking password and, if malware is suspected, from a different trusted device
- On the affected phone, uninstall any recently added app and run a security scan; consider a full reset if malware is likely
- List every unfamiliar transaction and formally dispute them with your bank
- Report the fraud to your national fraud or cybercrime service
How to prevent it
- Never read a one-time passcode or card verification code aloud to anyone who calls or messages you — that code is what enrols your card onto their phone
- Treat any message urging you to install an app or 'reverify' your card to keep it active as a phishing attempt, and go to your bank's official app instead
- Act on notifications that a new device or wallet has been added to your account rather than ignoring them
- Install apps only from official app stores, and never from links in texts, emails, or ads
- Turn on transaction alerts so a burst of small contactless purchases surfaces immediately
- Review the devices and mobile wallets linked to your card in your banking app and remove any you don't recognise
Evidence to preserve
- The phishing text, email, or call details, including sender numbers and any links
- Screenshots of the fraudulent transactions with times, amounts, and locations
- Notifications about new devices or wallets added to your account
- The name of any app you were told to install and where the link came from
Where to report it
- Action Fraud (UK) — UK national fraud & cybercrime reporting centre
- FTC ReportFraud (US) — US Federal Trade Commission fraud reports
- FBI IC3 (US) — US Internet Crime Complaint Center
- Scamwatch (Australia) — Australian competition & consumer reporting
- Your bank's fraud line — Use the number on the back of your card or in your banking app — never a number the caller gives you
Always verify reporting routes and emergency contacts on the official government or agency website for your country.
Frequently asked questions
How is a ghost tap different from someone stealing my card number?
A stolen number is typically used for online purchases, where the card is not physically present. A ghost tap is used at a real, in-person terminal: relay software carries the contactless conversation between your card or wallet and a mule standing at the reader, so the terminal believes a genuine tap happened. That is also what separates it from provisioning, where a stolen card is loaded into a criminal's wallet to spend later. Relay forwards the live tap itself, which is why the charges look like ordinary in-store purchases.
Can criminals really tap my card from the other side of the world?
Yes, in effect. The contactless radio link only works over a couple of centimetres, but relay software forwards that exchange over the internet, so the two ends can be far apart. What actually travels the distance is the data of the tap, not the card. The mule still needs a physical terminal and a card credential to relay, which is why the fraud depends on first phishing your card and code, or infecting your phone. The relay is the second half of the scheme, not the whole of it.
I never lost my card, so how could this happen to me?
That is the unsettling part of the malware version. If a fraudulent app gains access to your phone's contactless function, it can read and forward your card's signal while the card sits untouched in your wallet. Nothing goes missing, so there is nothing to notice until charges appear. This is why the protective habits matter even when your card is safely with you: install apps only from official stores, ignore links pushing urgent updates, and take new-device notifications seriously.