Ghost touch: this is the new fraud in Mexico

54

Paying with a card or cellphone is becoming increasingly simple: you only need to bring the device close to a terminal and, within seconds, the purchase is completed. But that same convenience is also being exploited by criminals. In Mexico, authorities have warned about the so-called “ghost tap,” a type of fraud related to contactless payments.

The technology behind these payments is NFC (Near Field Communication), which allows short-range wireless communication between a compatible card, phone, or device and a terminal. CONDUSEF explains that this technology allows users to pay without inserting the card and, depending on the amount and conditions of the transaction, without entering a PIN.

The problem arises when criminals attempt to exploit this communication to make unauthorized charges.

How does “ghost tap” work?

According to the Secretariat of Security and Citizen Protection (SSPC), the fraud can be carried out when a person brings a portable terminal close to a card or NFC-enabled device in an attempt to process a transaction without the owner noticing. Crowded places, such as markets, mass events, or transportation systems, can become risk scenarios due to the proximity between people.

A more sophisticated method has also been described in which criminals use devices to intercept and relay information associated with a contactless transaction. Security investigations cited by Mexican media indicate that this mechanism may involve the use of two devices and operate in real time.

However, this does not mean that anyone can simply approach a cellphone and automatically drain a bank account. Contactless payments incorporate different security mechanisms. The risk lies in specific techniques that seek to exploit these technologies and, in some cases, combine them with deception or malicious applications.

How can you avoid becoming a victim?

The simplest recommendation is to maintain control over your cards and frequently review your bank transactions. CONDUSEF advises activating transaction alerts, setting limits when the bank allows it, and immediately reporting any charge you do not recognize.

It is also advisable to avoid installing applications from unknown websites or providing banking information to people claiming to represent financial institutions. CONDUSEF reminds users that they should not share passwords, security codes, or dynamic keys through calls, messages, or emails.

This article was written with the help of artificial intelligence and reviewed by an editor with information from the SAT.

Source: informador