Home / Uncategorized / NFC cyberattacks surge 188%: this is how your card gets stolen through your phone

NFC cyberattacks surge 188%: this is how your card gets stolen through your phone

NFC malware now empties accounts through the phone: attacks grow 188% in 2026

Attacks based on NFC (Near Field Communication) targeting Android smartphones to steal money have surged 188% during the first four months of 2026 compared with the same period last year. This is reflected in Kaspersky’s telemetry collected in its report “Financial sector threat landscape in 2025”, which also confirms the arrival of a more sophisticated modality, the so-called “reverse NFC”, much harder to detect because it is the victims themselves who transfer the money to the criminals.

The figures: from 12,300 to 35,600 blocked attacks

Between January and April 2026, Kaspersky’s security solutions blocked 35,600 attacks linked to different families of Android malware that use NFC techniques, including SuperCard X, PhantomCard, NGate and other malicious modifications of the NFCGate tool. In the same period of 2025 the figure was just over 12,300, which explains that 188% growth.

The company already anticipated this trend in late 2025 in its report on the financial sector threat landscape, and the data confirm that users in Russia are right now the most affected. The experts warn, however, that the threat is expanding its geography: Europe and Latin America are beginning to record this type of attack too.

Two modalities: direct NFC and reverse NFC

Direct NFC: your card, against an infected phone

In the classic scheme, cybercriminals contact the victim through messaging apps and, under the pretext of verifying their identity, convince them to download malware disguised, for example, as a financial app. Then they ask them to bring their bank card close to the infected smartphone and enter the PIN. The result: the attackers obtain all the card’s data and can use them to buy or withdraw money.

Reverse NFC: the ATM that charges for the criminal

The new variant is more twisted. The attacker sends a malicious app and, through social engineering techniques, convinces the victim to configure it as the main contactless payment method on their phone. That app generates an NFC signal that ATMs interpret as if it were the criminals’ card. Then, the scammers persuade the victim to deposit money into a supposed “secure account” using their own infected phone; in reality, the money ends up directly in the attackers’ hands.

“Whereas before cybercriminals mainly resorted to the direct NFC scheme, now reverse NFC is becoming more common,” explains Sergey Golovanov, chief security expert at Kaspersky. “The danger of this new modality is that it is much harder to detect and fight, because it is the victims themselves who voluntarily transfer the money and these operations can look completely legitimate.”

A growing business: NFC malware as a service

The first public attacks that used a modified version of a legitimate NFC tool were detected in late 2023 and mainly affected Europe. Then they reached Russia and other regions through mobile malware. Dmitry Kalinin, cybersecurity expert at Kaspersky, points out that “it was subsequently discovered that cybercriminals were commercializing this NFC malware under a malware-as-a-service (MaaS) model, providing other attackers easier access to these tools”.

That business model is what explains the accelerated growth: the malware is rented or sold, and any group with intent to steal can launch its own campaign without needing to develop anything from scratch. Golovanov does not rule out that “NFC-based malware will keep evolving and that the geography of the attacks will continue to expand”, so he recommends monitoring the threat very closely.

How to protect yourself from NFC malware

The good news is that the defenses remain simple and, above all, a matter of habit. Kaspersky analysts summarize the recommendations in three points.

First, avoid installing apps from unofficial sources, including links received by messaging, social networks, SMS or during phone calls. Second, do not follow instructions from strangers at an ATM, no matter who they say they are. And third, use a complete security solution on your Android smartphone, capable of blocking malware before it is installed and preventing access to phishing pages from the browser or the messaging apps.

The conclusion is clear: contactless payment is here to stay, but so are those who try to abuse it. Distrusting any app that promises to “verify” your identity, checking which payment method you have configured by default and never bringing your card near a device you do not control are gestures that can save you more than one scare at the ATM.