In short: NFC payment fraud is theft of money through your phone's contactless-payment chip. Posing as a "banking app" or an "identity check," criminals get the victim to tap a card against the phone and enter a PIN — or to set a malicious app as the default payment method. The card data is relayed to the attacker in real time, who then withdraws cash at an ATM or pays in a store. The core defense is simple: never install APKs from links in messages, keep Google Play Protect on, turn NFC off when you don't need it, and never tap a card or enter a PIN because "support" asked you to.
What NFC is and why it became a target
NFC (Near Field Communication) is a very short-range wireless technology, usually working within a few centimeters. It powers contactless payments: when you hold a card or phone to a terminal, data travels over the ISO/IEC 14443 radio standard. That convenience also created a new attack surface — payment data can now be intercepted or relayed in software without a criminal ever holding your physical card for more than a couple of seconds.
In 2026, contactless payments became a priority target. The reason is a mix of factors: nearly everyone carries an NFC smartphone, banking apps are everywhere, and phone- and messenger-based social engineering runs at industrial scale. A fraudster no longer needs to clone a card in a basement — it's enough to talk the victim into tapping their own card to the phone and reading out a code.
How money is stolen over NFC: three schemes
Attacks on contactless payment come down to three scenarios. The first two rely on social engineering plus a malicious app; the third relies on covert reading in a crowd.
Direct relay. The victim gets a call or message "from the bank," "from the tax office" or "from the police" and is convinced to install an app — supposedly to "verify identity," "protect the account" or "update the card." Once installed, the app asks the person to tap their bank card to the back of the phone and enter the PIN. At that moment the NFC chip reads the card data, and the PIN and details go to the attacker, who then pays for purchases or pulls out cash while the victim believes they are "passing a check."
Reverse relay. A more elaborate scheme: the victim is persuaded to set a supplied malicious app as the default payment method. The phone then emits an NFC signal as if it were the attacker's card. Under a pretext ("deposit money into a safe account," "confirm the payment"), the person is asked to hold the phone to an ATM — and the ATM recognizes it as the criminal's card. Money moves to a stranger's account with the victim's own consent.
Covert reading. In a dense crowd — on transit, at a concert, in a queue — an attacker with a reader or a prepared phone tries to read a card through a bag or pocket. Contactless operations without confirmation have a limit, so the scale of such theft is capped, but with heavy foot traffic it still pays off.
| Scheme | What the victim does | What the attacker gets |
|---|---|---|
| Direct relay | Installs a "banking app," taps the card, enters the PIN | Card data and PIN for payments and withdrawals |
| Reverse relay | Sets a malicious app as the default payment method | The victim's phone acts as the attacker's card at an ATM |
| Covert reading | Nothing — the card is read up close in a crowd | Card data within the contactless limit |
NFCGate and NGate: where these tools came from
Behind the headlines is a very specific technology. NFCGate first appeared in 2015 as a research tool built by students at the Technical University of Darmstadt in Germany — created to analyze and debug NFC traffic and for educational purposes. Over time, cybercriminals reworked the project: they added routing through a malicious server, disguises as legitimate software, and ready-made social-engineering scenarios. According to Kaspersky, by early 2025 analysts had counted more than eighty unique malware samples built on NFCGate.
A separate line is the NGate family, described by ESET researchers. Such malware relays NFC traffic from the victim's phone to the criminal's device and enables ATM cash withdrawals without the physical card. A new variant found in spring 2026 hid inside a legitimate-looking payment app, HandyPay, and part of its code — by researchers' assessment — may have been AI-generated, which makes churning out new versions cheaper and faster. One key detail: almost all of this malware spreads outside the official store — via APK files from links in messages, not through Google Play.
Fake banking and government apps
An NFC theft almost always begins not with technology but with a fake app. In 2026, counterfeits impersonating banking apps — and even a financial-regulator service — spread widely: victims were told their "old app no longer works" or that they must urgently "protect the account." The installed program looks like a real banking client, but its only job is to make you tap a card, coax out the PIN and intercept the NFC signal.
A simple rule helps spot a fake: genuine banking apps are installed only from official stores or the bank's website, and no bank asks you to tap a card to your phone "to verify" it. If an app arrives as a link in a messenger or installs from an .apk file, it's almost certainly a trap. The same tricks power SMS phishing — how to recognize fake texts is covered in our piece on SMS phishing. To check a suspicious site a link points to, see how to spot a scam website.
Signs someone is trying to trick you
NFC fraud always comes with pressure and unusual requests. Be on guard if, during a call or chat, any of the following happens:
- you're rushed, scared with an "account block" or a "suspicious transaction" and told to act right now;
- you're asked to install an app from a link or a supplied file rather than from an official store;
- you're told to tap a bank card to the back of the phone "to verify" or "activate" it;
- you're asked to read out or enter a PIN, full card number, CVV or an SMS code;
- you're urged to set a new app as the default payment method;
- you're asked to walk up to an ATM and "confirm" something by holding the phone to it.
Any one of these is a stop signal. A real bank never calls with such demands; at the slightest doubt, hang up and call back using the number on the back of your card. If you suspect the phone is already compromised, cross-check the guide on signs your phone was hacked.
What to do: a protection checklist
You don't need to give up contactless payment — it's safe as long as your card and phone stay under your control. It's enough to close off the typical attack paths:
- install apps only from official stores or the bank's website — never from an .apk link;
- keep Google Play Protect on: it checks apps at install time and periodically scans the device for known malware;
- turn NFC off in the quick-settings shade when you're not paying, and switch it on only for the purchase;
- never tap a card to the phone or enter a PIN because "support," "the bank" or a "government body" asked you to — no real service does this;
- don't set an unfamiliar app as the default payment method;
- pay by phone through built-in wallets (Apple Pay, Google Wallet): they use a token instead of the real card number, so there's essentially nothing to intercept;
- set a contactless-transaction limit in your banking app and enable alerts for every transaction;
- review the permissions of installed apps and remove anything unnecessary — which rights are dangerous is covered in the guide on dangerous app permissions.
It's worth remembering the root of the threat: a malicious "banking app" is a special case of the broader fake-software problem. How to tell dangerous programs apart in general is shown in the breakdown of malicious VPN apps — the same principles apply to any mobile app.
Does a VPN protect against NFC fraud?
The honest answer: not directly. A VPN encrypts your internet traffic and hides your real IP address, but it physically cannot stop you from tapping a card to a rogue app and entering a PIN. NFC relay and reverse payment are social engineering plus malicious code on the device, not interception of a network connection. So in this specific attack, what matters is your vigilance and app hygiene, not a VPN.
But a VPN has its own adjacent responsibility — the network layer where the rest of online banking happens. On open, unencrypted Wi-Fi in a cafe or airport, an attacker can slip you a fake login page or intercept data — a classic man-in-the-middle attack. A VPN closes exactly this vector: it raises an encrypted tunnel and prevents traffic tampering on someone else's network. So the sensible strategy is layered: tokenized phone wallets and caution against NFC schemes, plus a VPN on your smartphone to protect the connection. What a VPN does and does not cover is laid out in our piece on what a VPN protects against, and LiMP VPN plans with no-logs servers are on the pricing page.
FAQ
Can money be stolen just by walking past me with a phone?
Practically no. NFC works within a few centimeters, and covert reading requires holding a device right up to the card. Contactless operations without confirmation also have a limit, and phone wallets transmit a token rather than the card number. The real threat is schemes that install a malicious app, not "walking past."
Is paying by phone safer than by card?
Generally yes. Apple Pay, Google Wallet and similar services use tokenization: the terminal receives a one-time cryptographic token rather than real card details. Even if that exchange is intercepted, the data can't be reused. So paying by phone is usually safer than tapping a physical card.
Do I need an RFID wallet or shielding foil?
It only protects against covert close-range reading and does nothing against the main 2026 schemes, which rely on malicious apps and social engineering. A shielding sleeve won't hurt, but don't treat it as your primary defense — not installing dubious apps matters far more.
I installed a suspicious app — what should I do?
Turn off the internet and NFC, uninstall the app, revoke any device-administrator rights it was granted, run a Google Play Protect scan, contact your bank on the official number, and if needed block and reissue the card and change passwords.
Does antivirus protect against NFC fraud?
Partly. Antivirus and Google Play Protect catch known malware, but fresh APKs distributed outside the store can go unnoticed for a while. Technical tools reduce risk but don't replace the main rule — don't install apps from links and don't tap a card because someone asked.
Does this happen on iPhone too?
The risk is lower. iOS heavily restricts third-party apps' access to NFC for payment operations, so most of these schemes target Android, where an APK can be installed from an unverified source. Still, phishing and code-coaxing work on any platform, so basic caution matters on iPhone as well.
Should I turn NFC off entirely?
Keeping NFC off by default and switching it on before paying is a sensible habit that closes off covert reading and accidental triggers. It doesn't affect your ability to pay by phone: enabling NFC is a single tap in the quick-settings shade.
