TAP and You're Broke: The Wireless Skimming Scam Spreading Everywhere

Ward Lockhart

Ward Lockhart

870 views

You have heard that somebody can walk past you in a store and charge your contactless card through your coat. That is not true, and I explain exactly why in this video — the range on these cards is inches, not rooms, and it is short by design. But something IS emptying accounts, it does involve a tap, and the theft happens long before anybody taps anything. Here is where it actually takes place, and the free two-minute setting that catches it in sixty seconds instead of at the end of the month.

What we cover:

The number — where your card details are really taken, and why none of it is wireless

The code — the one-time text message, and the four seconds that install your card in a stranger's phone

The wallet — how a card sitting in your back pocket gets tapped on another continent

The spend — why it always starts with a charge small enough that nobody looks

THE ZERO-DOLLAR RULE: set your bank alerts so every transaction pings you regardless of amount. Not $50. Not $25. Zero. Every threshold that feels sensible is above the size of the test charge — that is exactly why the test works.

Also in this video: why paying with your phone is genuinely safer than paying with the plastic card, which gas pump to use and why, the exact sentence to say to your bank if you have already read a code out to someone, and an honest answer about whether blocking wallets and sleeves are doing anything for you.

THE FACTS ON RANGE

Contactless cards operate at 13.56 MHz under the ISO/IEC 14443 standard. The theoretical maximum read range is roughly 10 cm (about 4 inches), and payment specifications deliberately restrict the working distance further, typically to about 1–4 cm. Demonstrated relay and eavesdropping attacks have still required the attacker to be within inches. Each tap also generates one-time cryptographic data, so captured information is not reusable the way an old magnetic-stripe number was.

SOURCES

Group-IB threat profile on NFC relay fraud ("ghost tap"): https://www.group-ib.com/masked-actors/tx-...

Recorded Future research on ghost-tapping: https://www.recordedfuture.com/research/gh...

FTC 2025 reporting on losses by payment method (credit cards and payment apps: $736.9 million)

WHERE TO REPORT

Federal Trade Commission: https://reportfraud.ftc.gov

FBI Internet Crime Complaint Center: https://www.ic3.gov

For anything about your own account: the phone number printed on the back of your own card.

Ward Lockhart is a composite educational character, voiced and rendered with AI. He is not a lawyer, law-enforcement officer, government employee, banker, or financial adviser, and nothing in this channel is legal or financial advice. Everything here is general information drawn from public sources such as the FTC, the FBI's IC3, and state attorney-general advisories. If you believe you have been targeted, contact your own bank using the number printed on your card, and report it at reportfraud.ftc.gov.

© Ward Lockhart. All rights reserved. Do not reupload or reuse this video, its audio, or its artwork.

#TapToPay #GhostTap #ContactlessCard #ScamAlert #NFCScam #CardSkimming #FraudPrevention #DebitCard #ScamAwareness #RFID #DigitalWallet #BankAlerts #ProtectYourMoney #ScamWarning #GasPumpSkimmer #FTC #IC3 #SeniorSafety #ConsumerProtection #FraudAlert #MoneySafety #ScamsExposed #WardLockhart