Ghost-Tapping Scams Target Apple Pay and Google Pay: The Next Frontier in Contactless Fraud
Kabir5 min read

Ghost-Tapping Scams Target Apple Pay and Google Pay: The Next Frontier in Contactless Fraud

Organized cybercriminal syndicates are exploiting ghost-tapping NFC relay scams to defraud Apple Pay and Google Pay users. Stolen cards are loaded into burner devices and used for high-value retail fraud, expanding from Southeast Asia to global markets.

Share:

What's going on

In August 2025, banks and fintech providers started warning about an emerging fraud scheme aimed at Apple Pay and Google Pay. The technique has a name: ghost-tapping.

  • It was first observed in Southeast Asia, and it's since spread globally, run by organized cybercrime syndicates coordinating over encrypted Telegram marketplaces.
  • The method stitches together NFC relay attacks, phishing, SIM swapping, and money mule networks, converting stolen digital credentials into real-world purchases of luxury goods, electronics, jewelry, and even gold.

I've handled the post-mortem on a few payment-fraud cases, and what stands out here is the blend: this is cyber theft monetized through physical-world logistics. That's the next chapter of mobile payment fraud.


So what is ghost-tapping?

Ghost-tapping is a kind of NFC relay fraud. The attackers:

  • Load stolen card data onto burner devices (cheap phones running relay apps, or purpose-built hardware).
  • Tie that data to Apple Pay or Google Pay wallets.
  • Use NFC relay tools to push fraudulent in-person purchases at retail counters or contactless ATMs.

What makes it scale is the professionalization around it: automation, social engineering, and cross-border logistics all working together, which makes detection and takedown genuinely hard.


How the scheme runs end to end

1. Initial Access

  • Phishing campaigns harvest credentials and OTPs.
  • Mobile malware grabs session cookies and payment info.
  • SIM swap fraud abuses compromised telecom databases.

2. Exploitation

  • Stolen card details get loaded into Apple Pay / Google Pay wallets.
  • Attackers try to bypass banking security controls (example: the DBS Bank fraud case).

3. Execution

  • NFC relay fraud using tools like NFCGate (open source) or SuperCard X (commercial/proprietary).
  • Mules buy high-value items in physical stores.
  • Some syndicates also enable contactless ATM withdrawals.

4. Monetization

  • Stolen goods get resold via Telegram, Carousell, eBay, and Mercari.
  • Proceeds are laundered through USDT stablecoins and fiat cash-outs using mule networks.

The criminal supply chain

Telegram Marketplaces:

  • Huione Guarantee – shut down May 2025; resurfaced in decentralized form.
  • Xinbi Guarantee – escrow-driven USDT market.
  • Tudou Guarantee – mule recruitment hub.

Relay Tools:

  • NFCGate – open-source NFC relay app.
  • SuperCard X – proprietary hardware/software sold via @webu8.

Names in the network

  • @webu8 — develops burner phones and proprietary relay software.
  • @xingma888 — handles mule crews in Singapore & Malaysia.
  • 黑猫 (@llan19889) — recruits ATM mule networks.
  • 路飞 (@OPLuffy888) — organizes stolen goods transportation across borders.

The damage

  • Financial Losses: High-value fraudulent purchases, gold/jewelry theft, ATM exploitation.
  • Industries Affected: Retail, banking, fintech, insurance, digital wallet providers.
  • Geographic Spread: Started in Southeast Asia (notably Singapore); now expanding worldwide.
  • Scale: One case alone — between Oct–Dec 2024, 656 stolen cards in Singapore drove nearly $930,000 USD in fraud.

That Singapore figure is the one I'd put in front of any board. A single regional cell, three months, almost a million dollars. This isn't fringe activity.


Reading the bigger picture

Ghost-tapping is a scalable, resilient fraud economy. It:

  • Slips past legacy controls like SMS OTPs.
  • Exploits weak wallet provisioning checks.
  • Turns NFC relay tools plus mule networks into a repeatable fraud pipeline.

➡️ It's no longer niche. Ghost-tapping is the next frontier of financial cybercrime.


What to do about it

For Banks & Payment Providers

  • Enforce stronger KYC checks for wallet provisioning.
  • Replace SMS or email OTPs with secure app-based push authentication.
  • Deploy anomaly detection across device ID, IP, and geolocation.
  • Flag suspicious activity:
    • Same card on multiple devices
    • Single device linked to multiple cards
    • Geo-distribution anomalies (e.g., the same card showing up in distant countries)
  • Add customer approval workflows for high-risk wallet additions.

For Consumers

  • Enable MFA on financial and email accounts.
  • Never share OTPs or PINs. Bank staff will never ask for them via SMS or phone.
  • Watch for phishing apps and fake install links. Download only from official stores.
  • Move fast. Block a compromised card the moment you see a suspicious alert.

Most of this starts with stolen credentials, which is why the infostealer epidemic and MFA bypass is so tightly linked to wallet fraud, and why fast detection of stolen-credential use matters as much as the controls at the till. We covered the detection-first mindset in our PayPal credential leak analysis too.


Wrapping up

The rise of ghost-tapping fraud against Apple Pay and Google Pay is a real escalation in payment system abuse.

By combining NFC relay attacks, burner devices, and cross-border mule networks, these syndicates are monetizing stolen digital credentials at scale and welding cybercrime to physical retail fraud.

The takeaway: banks, retailers, and consumers need to treat mobile wallet fraud with the same urgency as digital banking risk. Stronger authentication, wallet governance, and fraud monitoring are what stop ghost-tapping before it goes mainstream. If you want early warning the moment stolen credentials get used in your environment, book a Mine2 demo and we'll show you how deception surfaces it in seconds.

M2

Kabir

Incident Response Lead, Mine2

Kabir leads incident response work at Mine2, dissecting breaches after the fact to show where earlier detection would have changed the outcome.

Share this article

Secure Your Network Today

Ready to implement advanced cyber deception in your organization? See how MINE2 can transform your threat detection capabilities.