Contactless payment fraud known as “ghost touch” fraud is targeting digital wallets, mobile devices, and bank cards by exploiting Near Field Communication (NFC) technology without requiring a PIN or signature, according to cybersecurity specialists. Cybersecurity expert Raúl León told Animal Político’s verification unit, El Sabueso, that the method takes advantage of short-range wireless systems designed to speed up transactions at grocery stores, cafes, and transit systems.
How NFC Technology Enables Contactless Transactions
Near Field Communication uses very low-power radio waves to transmit data between compatible devices held just centimeters apart, according to ESET security researcher Mario Micucci. When users tap a physical credit card or a mobile phone against a point-of-sale terminal, an instant wireless link authorizes the purchase. While this infrastructure eliminates the need to insert plastic or enter a security code, it creates an operational window that malicious actors target through proximity and digital interception.
Mechanics of Ghost Touch Fraud: Presential and Remote Methods
Global cybersecurity firm Kaspersky reports that ghost touch fraud operates through two primary avenues: a physical, presential method using relay devices, and a remote method relying on social engineering. In the presential approach, a criminal uses one mobile phone in a crowded space like a transit queue or cafe to intercept an active payment token via NFC. That unique transaction code is instantly relayed to a second criminal device held near a separate payment terminal to finalize an unauthorized purchase before the token expires.
In the remote variant, attackers use social engineering by calling victims while posing as bank employees. According to Kaspersky and Mario Micucci, the fraudsters convince the target to install a fraudulent mobile application designed to validate a bank card, then prompt the user to hold their physical card against their own phone, allowing the malicious software to capture and siphon the NFC token.
Global Hotspots and Transaction Limits
Geographic data compiled by Kaspersky shows that Brazil accounts for nearly half—47 percent—of all global blocks against this specific fraud attempt, followed by India, China, and Spain. Despite the sophistication of relay attacks, security analysts emphasize that attackers cannot completely drain a bank account via ghost touch. Raúl León and Mario Micucci note that contactless limits and built-in transaction ceilings restrict unauthorized charges to minimal amounts, meaning the attack hijacks the wireless payment handshake rather than cloning the physical card or stealing full banking credentials.
Prevention Strategies and Reporting Channels
The Cybernetic Intelligence, Investigation, and Technological Operations Unit of the Secretariat of Security and Citizen Protection (SSPC) advises users to deploy physical countermeasures, such as signal-blocking wallets, RFID-blocking cardholders, and protective sleeves. Additional defenses include turning off device NFC settings when not in use, verifying terminal display amounts prior to tapping, enabling instant push notifications for every transaction, and maintaining strict control over mobile device application installations, particularly on Android systems that permit sideloading apps outside official stores.
Victims who spot unauthorized charges should immediately block the affected card and file a formal dispute with their issuing financial institution. Raúl León notes that while users can escalate unresolved claims to consumer protection agencies like CONDUSEF, many minor fraudulent charges go unreported due to administrative friction, underlining the necessity of shared vigilance between account holders and banking institutions.
Worth a look