'Hold your bank card against your phone': how scammers can use a card that never leaves your hand

The call sounds convincing. Someone claiming to be from your bank says there has been suspicious activity on your account and that you need to act quickly. A “security app” will fix the problem, they say. Then comes the request that should make you hang up: switch on Near Field Communication (NFC) and hold your bank card against the back of your smartphone.

It sounds strange, but there is a reason criminals want you to do it. A form of malware can turn an infected Android phone into a remote card reader, passing information between your real bank card and a device controlled by the fraudster, even if your card stays in your hand throughout the scam.

How the call unfolds

The fraudster usually creates a sense of urgency first. There may supposedly be an unauthorized payment, a problem with your bank card, or an account that needs to be secured.

The victim is then instructed to install an app, sometimes through a link or file sent in a message. Recent warnings in Europe describe criminals using malicious Android apps rather than legitimate banking software.

Once the phone is compromised, the caller asks the victim to activate NFC, the short-range wireless technology used for contactless payments, and place the bank card against the phone. A PIN may also be requested.

That combination is the danger sign. A genuine bank employee will never guide you through this process.

Your card doesn't have to be stolen

Cybersecurity company Group-IB investigated an attack in which NFC-relay malware was used alongside remote-access malware.

When the victim held the card against the infected phone, the malware communicated with the card's chip. Instead of keeping that exchange on the phone, it relayed the information over the internet to equipment controlled by the criminals.

This is different from simply copying the number printed on your card. The attackers relay the live communication taking place between the card and what it believes is a payment terminal. Their equipment can then use that connection to make a purchase or, in some circumstances, withdraw money.

That is why the physical card doesn't have to disappear for the fraud to work.

Four requests that should make you hang up

The safest response is to stop following instructions as soon as a supposed bank employee asks you to do any of the following:

  • Install an app they send to you during an unexpected call.
  • Hold your bank card against your smartphone.
  • Tell them your PIN, login details or security codes.
  • Follow a link they send to log into online banking.

Dutch financial regulator AFM also warns that the telephone number shown on your screen cannot prove that the caller is really your bank. Criminals can manipulate caller ID so that a familiar or official-looking number appears.

If you're unsure, hang up. Look up your bank's official telephone number yourself, preferably on its website, banking app, or the back of your card, and call that number.

What if you already followed the instructions?

Contact your bank immediately and explain exactly what happened. Ask them to secure your account and block the card if necessary. Speed matters when fraudulent transactions may still be taking place.

Do not continue using an app installed at the caller's request. If you're unsure whether the phone is still compromised, get help removing the malicious software or have the device checked before using it for banking again.

The most useful rule is also the easiest to remember: if somebody calls claiming to be your bank and asks you to turn your phone into a card reader, end the call. A bank card pressed against your own phone may feel safe because it never leaves your hand. In this scam, that is exactly what makes the trick convincing.

Advertising
Adobe Stock