Ghost tapping is rapidly emerging as a stealthy attack vector that poses a serious challenge to digital identity and payment security. Originally observed among Chinese-speaking threat actors by security researchers at Threat Fabric who coined the term, this technique exploits Near Field Communication (NFC) relay methods to commit retail fraud using stolen payment card credentials loaded into mobile wallets such as Apple Pay and Google Pay. While the mechanics are highly technical, the consequences are straightforward: unauthorized transactions, physical goods stolen, and illicit funds laundered across borders.
How Ghost Tapping Works
At its core, ghost tapping is NFC relay fraud. Cybercriminals obtain stolen payment card data, often via phishing or malware, link it to burner phones, and transmit the NFC signal to mules who conduct in-person purchases at retail stores or withdraw cash from ATMs. Software created and controlled by cybercriminals enables remote management of these cards, making the operation scalable and difficult to detect. The syndicate model amplifies the threat. Cybercriminals handle the digital side while syndicates recruit mules, coordinate logistics, and resell goods for cash or cryptocurrency. In practice, this means a victim’s card is silently added to a mobile wallet like Apple Pay or Google Pay and then relayed in real time to a mule’s phone, letting them “tap” at the point of sale as if they were the rightful cardholder. The stolen goods are quickly moved, resold, and turned into profit, completing the cycle.
Implications for Businesses
The rise of ghost tapping has far-reaching implications for digital identity governance and cyber risk management. For banks and payment providers, it exposes weaknesses in mobile wallet provisioning, one-time password (OTP) verification, and device authentication. For retailers, it highlights gaps in in-person verification and transaction monitoring. For insurers and regulators, it raises questions about liability for losses tied to NFC relay fraud. The cross-border nature of these campaigns, spanning Southeast Asia, China, and potentially beyond, means that no organization operating in mobile payment ecosystems can afford complacency.
Why Organizations Should Be Concerned
Ghost tapping demonstrates how identity compromise is no longer confined to digital environments. A stolen credential can be converted into physical goods, laundered through mules, and monetized across borders with minimal detection. Automated linking of compromised cards to mobile wallets further accelerates the fraud lifecycle, eroding trust in digital payment systems and threatening operational resilience. Businesses relying on mobile payments and contactless systems are now exposed not only to financial loss but also to reputational and regulatory risk.
Mitigating the Risk
Defending against ghost tapping requires a layered approach to identity security.
Banks and payment providers should enforce stronger authentication for adding cards to wallets, move beyond SMS-based OTPs, and use machine learning to flag anomalous wallet activity or geographically improbable transactions.
Retailers must implement robust transaction monitoring and identity verification procedures for in-person purchases.
Consumers should remain vigilant, never share OTPs, monitor card activity, and limit exposure to untrusted apps or websites.
Law enforcement and regulators need to track evolving NFC relay fraud trends, collaborate internationally, and disrupt syndicate operations.
Looking Ahead
Ghost tapping provides an important lesson. Identity compromise can now bridge the digital and physical worlds, converting stolen credentials into tangible assets. With cybercriminals adapting rapidly and globalized syndicates exploiting Telegram-based marketplaces, organizations must elevate identity governance from an IT function to a strategic risk priority. Strong authentication, continuous monitoring, and integrated identity controls are no longer optional. They are essential defenses against a threat that moves as quickly as the digital wallets it targets.
This is not just a payments problem; it’s a wake-up call for identity security across every interaction in the digital economy.
For expert guidance on combating identity fraud and emerging threats like ghost tapping, KuppingerCole’s Advisory Team is ready to help. Organizations can also explore KuppingerCole’s Leadership Compass Reports on Fraud Reduction Intelligence Platforms for Finance and eCommerce, offering practical insights into selecting the right solutions to mitigate these risks.
When it comes to securing digital wallets and strengthening identity governance, proactive defense is the best strategy.