
Fraudsters no longer need to steal your bank card to exploit it. They now use your smartphone as a relay to capture its NFC data and make remote payments without you noticing.
Malicious software turns your phone into a relay reader
A piece of malware called SuperCard X, identified by cybersecurity firm Cleafy in a report published in 2025, allows reading a bank card’s data via its NFC chip directly from an Android smartphone. Once the information is captured, it is transmitted in real time to an accomplice equipped with a payment terminal or an ATM. The terminal then validates the transaction as if the card were physically present.
This technique, known as NFC relay, exploits a design flaw in current cards: they do not verify the logical distance of the exchange, only the physical range. As long as the dialogue between the chip and the reader is valid, the card does not detect that its counterpart is kilometers away. A security protocol, DBP (Distance-Bounding Protocol), could address this issue, but it is not yet widely adopted.
A scam that starts with a fake bank call
The attack often begins with a fraudulent message or call impersonating your bank. The fake advisor pressures the victim into revealing their card PIN, increasing payment limits, and then installing an app presented as a security tool. In reality, it is SuperCard X or a similar piece of software, NGate, detected a year earlier. Once installed, the fake advisor asks the victim to hold their card against the back of the phone for a “verification.” In seconds, the card’s data is extracted and sent to the hackers’ servers.
These malicious apps only require one permission: access to NFC. This makes them almost invisible to traditional antivirus software, unlike conventional banking malware, which requests numerous permissions. SuperCard X is even offered for rent to other criminals as a subscription service.
Fraud already active in Europe, and hard to detect
This method was first spotted in Italy, but it could spread anywhere contactless payments are widely used. Scammers often make multiple small withdrawals to stay under the radar, and victims notice nothing, simply believing they are confirming their card still works. No bank ever asks you to hold your card against your phone on an advisor’s instructions: this is the only way to protect yourself.
RecommendedSamsung Wallet turns smartphones into digital keys for Volkswagen EVs
Fraud industrialization underway
At the same time, tools like the one described by ZATAZ, sold for €500, enable the industrialization of these scams. This “panel” centralizes logs (interaction traces with victims), syncs data with Telegram, and allows multiple operators to coordinate their actions from a single interface. Active victims are prioritized, and information is exploited in real time, reducing the delay between data collection and use.
This system organizes work among different criminals, with limited guest profiles for reading and synchronization that enables rapid response. The goal is clear: turn artisanal fraud into a structured operation capable of processing a large number of victims simultaneously.
Contactless payment remains convenient, but this new method is a reminder that security also depends on vigilance. Storing your card in an RFID-blocking case or monitoring your bank statements limits the risks. Banks, for their part, are required to refund unauthorized transactions. After AI that helps choose a refurbished smartphone, here’s another facet of technology-related risks.


Comments 0
Sign in to join the discussion.
Be the first to comment.