Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes

Fraudsters using social engineering and malware can clone contactless cards and authorize payments in just 13 minutes, outpacing banks' ability to intervene.

Fraudsters are cloning contactless cards and authorizing payments in just 13 minutes by combining social engineering with malware. This rapid attack outpaces banks' ability to detect and block fraudulent transactions. The criminals use smooth-talking phone calls to trick victims into revealing card details or installing malware, which then enables cloning and immediate unauthorized use. The speed of the scheme—from initial contact to completed payment—leaves little time for financial institutions to intervene.