Ghost Tapping Scam Targets Contactless Payment Cards

Criminals have developed a remote technique to skim payment data in crowded areas without physical contact.

Updated on Sept. 30, 2026 in Cybersecurity

Isometric editorial illustration of a metallic payment card interacting with an abstract radio wave near a subway turnstile, representing digital security vulnerabilities.
Cybersecurity experts have identified a new method called ghost tapping, which allows criminals to intercept data from contactless payment cards in crowded areas. AI Illustration. Upload story photo >

Live Poll

Do you trust contactless payment systems to protect your financial data from digital theft?

Cybersecurity experts identified a digital theft method called ghost tapping that enables unauthorized access to contactless payment card data. This remote scam allows bad actors to skim sensitive information from consumers in crowded locations.

Why it matters

The rise of ghost tapping highlights a significant vulnerability in contactless payment security, specifically when cards are stored in locations where they can be scanned without consent. This development forces a re-evaluation of how consumers protect their financial data in high-traffic public spaces.

Consumers can mitigate risk using RFID-blocking wallets, which typically cost between $10 and $12. These accessories are designed to prevent the radio frequency signals used by criminals to remotely pull payment data from contactless cards.

The players

Better Business Bureau

A non-profit organization that provides marketplace trust services and alerts consumers to emerging financial fraud schemes.

The details

Ghost tapping operates by leveraging the radio frequency identification (RFID) signals used by modern contactless payment cards. Criminals in crowded spaces employ remote scanning technology to intercept these wireless transmissions, allowing them to skim payment details without ever making physical contact with the victim. This process turns a standard payment protocol into an exploit surface for remote theft.

Timeline

  1. September 30, 2026: Cybersecurity experts issued a formal warning regarding the ghost tapping scam.

The Tech Race

This scam marks a shift in the race between payment security providers and those exploiting radio frequency vulnerabilities. It follows a pattern set by the Better Business Bureau in documenting how criminals adapt to new contactless consumer hardware.

Individuals should monitor their financial statements closely for small, unusual test charges that may indicate an unauthorized card skim. Carrying cards in an RFID-blocking wallet, which generally costs between $10 and $12, serves as the primary defense against this remote scanning method.

The takeaway

Ghost tapping demonstrates that even contactless technology is not immune to remote, non-physical interception. Watch for official updates from the Better Business Bureau, which recommends checking your accounts regularly for signs of test transactions.

Further reading

For more on evolving financial threats, see the latest updates on Cybersecurity.

Source note: This article includes information reported by 25 News KXXV and KRHD.

Live Poll

Do you trust contactless payment systems to protect your financial data from digital theft?