NFC attacks surge 188% in 2026 and trick victims into sending money themselves

Published on 2026-07-23

Attacks exploiting NFC technology to steal money from Android smartphone users have soared 188% during the first four months of 2026. Security experts also warn about the rapid growth of a particularly dangerous technique known as reverse NFC, which convinces victims to transfer money to cybercriminals themselves while believing they are protecting their funds.

Near Field Communication (NFC) technology enables wireless data exchange between devices located close to one another. It is widely used for contactless mobile payments, validating public transport cards and sharing information between compatible devices.

Cybercriminals have found new ways to abuse this technology. Several Android malware families, including SuperCard X, PhantomCard, NGate and modified versions of NFCGate, use NFC-based techniques to carry out financial fraud.

One of the most common methods begins when attackers contact victims through messaging applications and persuade them to install a malicious app disguised as a trusted financial or legitimate application.

Once the smartphone has been infected, victims are instructed to place their bank card against the device and enter the PIN. This allows criminals to capture the necessary banking information and steal money from the account.

However, Kaspersky researchers warn that an even more sophisticated technique is becoming increasingly widespread. According to Sergey Golovanov, the company's Chief Security Researcher, this method is much harder to detect because the transactions appear completely legitimate, as the victims themselves authorize the transfer.

Known as reverse NFC, the attack also relies on social engineering to persuade users to install a malicious application and set it as the smartphone's default contactless payment method.

The malicious app then generates an NFC signal that ATMs interpret as if it belonged to the attackers' own bank card. Victims are subsequently instructed to deposit money into what they believe is a secure account using their infected phone, when in reality the funds are transferred directly to accounts controlled by the cybercriminals.

As a result of the increasing use of these techniques, NFC attacks targeting Android devices rose by 188% during the first four months of 2026 compared with the same period last year.

According to Kaspersky telemetry data included in the Financial Sector Threat Landscape in 2025 report, the company's cybersecurity solutions blocked 35,600 attack attempts involving NFC-related malware, compared with just over 12,300 in 2025.

Although Russia remains the country most affected by this threat, Kaspersky notes that users in Europe and Latin America are also beginning to experience a growing number of NFC-based attacks.

To reduce the risk, the company recommends installing apps only from official stores, avoiding links received through messaging apps, SMS, phone calls or social media, and never following instructions from strangers at ATMs, regardless of who they claim to be.

COMMENTS

No customer comments for the moment.

Add a comment