Why experts say tap-to-pay scams are becoming harder to spot
Fraudsters are using stolen card information, digital wallets, and familiar phishing texts to make unauthorized purchases that can look completely
Fraudsters are using stolen card information, digital wallets, and familiar phishing texts to make unauthorized purchases that can look completely legitimate at checkout.
Tap-to-pay has made checking out almost effortless. Instead of digging for a credit card or entering a PIN, shoppers can hold a phone or smartwatch near a payment terminal and keep moving.
That convenience is not going anywhere. But a growing form of retail fraud shows how scammers can exploit the accounts and financial information connected to digital wallets, sometimes without drawing attention until the real cardholder checks their statement.
Fraudsters are using stolen credit card information to make purchases through digital wallets such as Apple Pay and Google Wallet, according to a recent CNBC investigation. Because the payment is processed through a phone at an ordinary checkout terminal, the person making the purchase may look like any other shopper.
The scam does not typically begin with someone intercepting a card number while its owner taps at a store. Instead, criminals may obtain card information through phishing messages, compromised online accounts, data breaches or other forms of identity theft. They then attempt to add the stolen card to a digital wallet or gain access to a retail account that already has a payment method saved.
That distinction matters. Tap-to-pay technology is designed to protect a shopper’s actual card number during a transaction. The weakness scammers are exploiting often appears earlier, when they trick someone into surrendering financial information or a security code.
The Federal Trade Commission has repeatedly warned consumers about unexpected texts that imitate banks, delivery companies, and toll agencies. Those messages often claim that a payment is overdue, a package cannot be delivered or suspicious activity has been detected. The goal is to create urgency and persuade the recipient to click a link before stopping to question it.
Once a person enters card details on a fake website, scammers may try to register that card in a digital wallet. A victim could then receive a legitimate verification code from their bank without realizing someone else initiated the request.
Consumers should never share that code with anyone who calls or texts asking for it. The FTC advises contacting a financial institution directly through its official app, website or the number printed on the back of the card rather than using contact information supplied in an unexpected message.
CNBC found that stolen cards are often used to purchase gift cards or expensive merchandise that can quickly be resold. In one case reviewed by the outlet, a man allegedly used tap-to-pay at a Louisiana Lowe’s to buy multiple $95 gift cards. Similar schemes have involved stores operated by TJX Companies, which owns TJ Maxx, Marshalls, and HomeGoods.
Gift cards are attractive to fraudsters because they can be transferred, resold or used to purchase other products. Smaller individual transactions may also attract less attention than one unusually large purchase.
The emerging crime is especially difficult for retailers to detect because nothing necessarily looks wrong at the register. The shopper is not presenting an obviously altered card. The payment terminal may approve the digital transaction, and the person can leave with both merchandise and a receipt.
Consumers may not know anything happened until an alert appears on their phone or they review their bank statement.
That delay can be particularly disruptive for families already stretching their income across rent, food, transportation and other necessities. Even when a bank eventually restores stolen funds, losing access to money for several days can create late fees, missed payments and additional stress.
Shoppers can reduce their risk by enabling instant alerts for every card transaction, using different passwords for email and retail accounts, and protecting those accounts with multifactor authentication. Email security is especially important because a compromised inbox can expose password-reset links and financial notifications.
Apple also advises users not to follow instructions from unsolicited messages that claim to be from the company and provides a dedicated process for reporting suspected phishing.
Anyone who sees a transaction they do not recognize should immediately lock the affected card, contact the card issuer and dispute the charge. Consumers should also change passwords for any related email, banking or shopping accounts. The FTC says federal law provides protections against unauthorized credit card use, although the reporting rules and potential losses can differ for debit cards.
Digital wallets remain a convenient way to pay, and the existence of these schemes does not mean shoppers need to stop using them. But convenience works best when it is paired with closer attention.
The safest tap may be the one followed by an instant alert confirming that the purchase was actually yours.
Share
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0