๐ณ Contactless payment has made our lives easier, but did you know hackers exploit it to steal your money? Hereโs how the Ghost Tap technique works and how to protect yourself.
โ ๐๐๐๐ ๐๐ ๐๐๐๐๐ ๐๐๐?
Hackers use a mix of technologies to carry out fraudulent contactless payments without your knowledge. Hereโs the technical breakdown:
1๏ธโฃ Bank data theft:
๐ฉ Using phishing emails or malware, hackers steal your banking info or card details.
2๏ธโฃ Virtual card cloning:
They use this data to create a virtual card, which they load onto a smartphone or NFC (Near Field Communication) device.
3๏ธโฃ Remote payments:
โAccomplices use the virtual card on their phone in airplane mode, making it untraceable.
โThey make small payments in physical stores, usually below the contactless payment limit (โฌ50 or โฌ100 depending on the region).
4๏ธโฃ Evading detection systems:
โณ Low-value transactions mimic your typical purchases, making them undetectable by banks.
๐๐๐ ๐๐๐๐๐๐๐๐๐๐ ๐๐๐๐๐๐ ๐๐๐๐๐ ๐๐๐
โณ NFC (Near Field Communication): The key enabler of this scam, as it allows wireless payments.
๐๐๐๐ค๐๐ซ๐ฌ ๐๐ฑ๐ฉ๐ฅ๐จ๐ข๐ญ:
โก๏ธThe proximity requirement for payments (just a few centimeters), but with a virtual card.
โก๏ธAirplane mode: No network connection means fewer traces for banks or mobile operators.
The following picture shows the scheme of interactions:
๐ ๏ธ ๐๐ญ๐๐๐ฅ๐ญ๐ก๐ฒ ๐๐ซ๐๐ฎ๐:
โ๏ธPayments are designed to appear normal: small amounts, spread out over time.
โ๏ธPayment terminals donโt always verify identities, making it easier for hackers to succeed.
โ ๏ธ ๐๐๐ ๐๐ ๐๐๐๐ ๐ ๐๐๐ ๐๐๐๐?
โ Current banking security measures arenโt always fast or robust enough to detect this kind of fraud.
โ Hackers can operate internationally, with stolen data often sold on the dark web.
๐ก ๐๐๐ ๐๐ ๐๐๐๐๐๐๐ ๐๐๐๐๐๐๐๐
1๏ธโฃ Regularly check your accounts: Small, unusual transactions can be red flags.
2๏ธโฃ Enable real-time notifications for every transaction.
3๏ธโฃ Disable NFC services on your card if youโre not using them.
4๏ธโฃ Report any suspicious activity to your bank immediately.