Gazdaság
NFC banking scam: how the new method works and how to protect yourself
Scammers call the victim, persuade them to install an app, then ask them to tap their bank card against the phone. The danger does not come from contactless technology itself, but from the app installed through manipulation. We explain how the scam works, what the latest figures show, and what to watch for during a suspicious call.
2026-10-09 · 5 min read
In October, the latest ranking of domestic banking scams was published, and experts say a new method has appeared on it: phishing that exploits contactless NFC technology. The essence of the trick is that scammers obtain card details without taking the bank card itself. To do this, they need the victim’s cooperation. Below, we show how such an attack unfolds, why contactless payment itself is not the weak point, and what someone should do if they receive a suspicious call.
What is NFC, and how does fraud come into the picture?
NFC (Near Field Communication) is a short-range wireless connection that works only over a distance of a few centimetres. This is what allows us to pay by tapping a bank card or phone against a terminal. Most modern smartphones can read NFC chips, so they can also communicate with a card tapped against them.
According to an analysis by FinTechRadar, the new method is a hybrid form of attack: it combines psychological pressure over the phone with technological data theft. So the scammers do not simply hack something; first, they persuade the victim to take the crucial steps themselves.
Step by step: how the attack unfolds
Based on Erste Bank’s security guidance and a report by Rakéta.hu, the scam typically follows the following scenario:
- Phone call: the scammer calls the victim and promises them a prize or some kind of credit.
- App installation: during the conversation, they persuade them to download and install an application on their phone.
- Tapping the card: they then ask them to tap their bank card against the phone, for example to “credit the prize” or for “identification”.
- Data transmission: the installed application reads the card’s details, which are then passed on to the criminals, while the physical card remains with the victim throughout.
The method is particularly insidious because the victim has no reason to think they have lost anything. The card is still in their pocket, the phone appears to be working normally, and the caller came with a plausible story.
Contactless payment is not the weak point
It is important to make clear that the risk does not come from NFC technology itself. According to warnings from Erste Bank and the National Cyber Security Centre, tapping the card in itself is safe. The source of the danger is the malicious or remote-access application installed on the phone through persuasion, which transmits the scanned data to the scammers.
In practice, this means there is no need to give up contactless payment in shops. The real focus should be on what application is being installed on the phone, who is asking for it to be installed, and in what situation. The National Cyber Security Centre publishes guidance on protecting mobile devices, as well as on how to defend against attacks aimed at taking over accounts. The institute also specifically warns about the dangers of psychological manipulation.
What do the latest figures show?
A summary by BiztosDöntés.hu cites data from the second quarter of 2026 from the Hungarian National Bank. According to the site, around 52,000 card fraud cases occurred during this period, causing total losses of 1.74 billion forints. At the same time, according to the report, losses from transfer fraud rose to 5.37 billion forints.
The difference between the two categories is significant. According to BiztosDöntés.hu, the increase in losses from transfer fraud came almost entirely from attacks against corporate accounts. Card fraud — including the new NFC-based method — directly affects everyday card users, which is why this area is particularly important for retail customers.
Who bears the loss?
According to Rakéta.hu, roughly two-thirds of the losses caused by card fraud, around 66 per cent, ultimately have to be borne by cardholders themselves. This clearly shows that recovering the money after a successful scam is far from guaranteed.
Who is responsible for the loss in a specific case, and to what extent, depends on the circumstances and the bank’s terms. It is therefore worth checking in advance the terms of your own bank account and card agreement, and, if necessary, contacting your bank or a specialist. Prevention is certainly simpler than that.
What should you do if “the bank” or a caller promising a prize phones you?
Bank security warnings, including Erste Bank’s guidance, caution that no one should install an application during a phone call at someone else’s request. A few general points that may help recognise and avoid the trap:
- Be suspicious if the caller asks you to install an application. A request like this made during a call is a serious warning sign.
- Do not tap your card against your phone at a stranger’s request. A bank card should be tapped against a terminal when making a payment, not against an application named by a caller.
- Be cautious about unexpected prizes and credits. Scammers often use these to create trust and a sense of urgency.
- End the call and call the bank back. It is worth using the number shown on the back of the card or on the bank’s official website, not the one from which the call came.
- Only install apps from an official app store. Even then, it is worth checking the developer’s name and the permissions requested.
- Do not let them rush you. Time pressure is one of the tools of manipulation; a genuine case can withstand you taking time to check.
If it has already happened: the first steps
If someone suspects that, after being talked into it by a caller, they used their phone to scan their card details through a suspicious application, it is worth contacting their bank as soon as possible on the official customer service number and asking for the card to be blocked. It is advisable to remove the unknown application installed on the phone and review the account history to see whether any unknown transactions have taken place.
Quick action matters because the sooner the bank becomes aware of the suspicious situation, the greater the chance of preventing further abuse. If fraud is suspected, it is also possible to contact the police.
In summary: the new NFC scam does not rely on a flaw in the technology, but on human trust and haste. Anyone who never installs an application during a call at a stranger’s request, and does not tap their card against their phone on the instruction of an unknown person, has already done a great deal to protect themselves. This article provides general information and does not constitute financial or legal advice; in a specific case, it is worth consulting your bank or a specialist.
Sources used
- 1.Erste Bank Biztonsági Központerstebank.huverified
- 2.Nemzeti Kiberbiztonsági Intézetnki.gov.huverified
- 3.Itt a banki csalások toplistája: új módszerrel verik át az ügyfeleketbiztosdontes.huverified
- 4.Érdemes figyelni: új NFC-s módszerrel húzzák le a magyarokatraketa.huverified
- 5.Új banki csalás terjed Magyarországonfintechradar.huverified
These sources were used during our editorial fact check.