No, hackers can't drain your Apple Pay account, says Visa

Using Apple Pay to pay for shopping
(Image credit: Apple)

Visa has hit back after cybersecurity researchers claimed possible security issues in its payment mechanisms, specifically concerning Apple Pay, could allow criminals to make fraudulent contactless mobile payments.

Rresearchers from University of Birmingham and University of Surrey used a locked iPhone to make a payment via NFC exploiting an Apple Pay feature called Express Transit that’s designed to work with Visa to help commuters pay quickly at ticket barriers. 

However Visa said that its payments were secure, and that this type of attack couldn’t be replicated outside of the lab in the real-world.

TechRadar needs you!

We're looking at how our readers use VPNs with streaming sites like Netflix so we can improve our content and offer better advice. This survey won't take more than 60 seconds of your time, and we'd hugely appreciate if you'd share your experiences with us.

>> Click here to start the survey in a new window <<

"Visa cards connected to Apple Pay Express Transit are secure and cardholders should continue to use them with confidence," Visa told TechRadar Pro in a statement.

"Variations of contactless fraud schemes have been studied in laboratory settings for more than a decade and have proven to be impractical to execute at scale in the real world. Visa takes all security threats very seriously, and we work tirelessly to strengthen payment security across the ecosystem."

Fooling the phone

The hack involves the use of a small commercially available piece of radio equipment, which is placed near the iPhone to trick it into believing it is dealing with a ticket barrier. At the same time an Android phone running a custom app developed by the researchers is used to relay signals from the iPhone to any contactless payment terminal.

Since the iPhone thinks it is paying a ticket barrier, it does so while still being locked. On the other end, the custom Android app modifies the iPhone’s communications with the payment terminal, which thinks the iPhone has been unlocked and the payment has been authorized legitimately.

In a video, the researchers successfully tricked an iPhone to make a Visa payment of a £1,000 payment without unlocking the phone or explicitly authorizing the payment

Importantly, the researchers share that the Android phone and payment terminal used in the hack don't need to be near the victim's iPhone.

"It can be on another continent from the iPhone as long as there's an internet connection," Dr Ioana Boureanu of the University of Surrey told the BBC.

Apple reportedly added that the matter was an issue with Visa’s payment system.

Via BBC

TOPICS
Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Apple users facing new security risks after critical USB component hacked
Man holding a mobile phone with warning notification and spam message icon
Scammers have a new phishing trick for iPhone users – here’s how to avoid falling victim
Find My app logo displayed on an iPhone 11 screen
This Find My exploit lets hackers track any Bluetooth device – here’s how you can stay safe
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
contactless mobile payments
Best mobile payment app of 2025
An illustration of a hooded hacker with an obscured face holding a large fingerprint against a red background.
ID theft – what happens when someone steals your identity
Latest in Security
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Data leak
Hacked Tata Technologies data leaked by ransomware gang
A close-up photo of an iPhone, with the App Store icon prominent in the center of the image.
Thousands of iOS apps found to expose user data and leak Stripe keys
China
Chinese hackers targeting Juniper Networks routers, so patch now
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Latest in News
Nicole Kidman wears a blue blouse with her arms crossed.
Netflix might be renewing The Perfect Couple and Beauty in Black for season 2, but I don’t get why when it’s canceled shows with poorer ratings
The Russo brothers posing for a photograph and Herman carrying a Volkswagen camper van in The Electric State
'We're optimists': AI enthusiasts Joe and Anthony Russo defend its use in movies and TV shows, but admit there are 'very real dangers' around its application
UK Prime Minister Sir Kier Starmer
UK PM says AI should soon replace civil servants
Xbox Copilot in Minecraft
Microsoft confirms Copilot can be tested by Xbox Insiders next month and shares new details about how the AI sidekick will enhance the player experience: 'It has to be about gameplay, it has to be personalized to you'
Eight Samsung TVs mounted to the wall showing different basketball games
Samsung is offering you 8 new TVs in one bundle for March Madness, in case you want to watch all games at once like a Bond villain’s lair
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com