Samsung Pay can be hacked, but it's 'extremely unlikely'

Samsung Pay

Samsung has confirmed its Pay service has a security issue that means hackers could spend money from your account, but it's "extremely unlikely" to ever happen.

Samsung Pay translates your credit card information into a "token" to ensure your details won't be stolen in the transaction process, but hackers are theoretically able to take it in a skimming attack and use it themselves.

However, the Samsung Security Blog has admitted while it would be possible, the conditions to achieve this would be rare: "In order for this "token skimming" to work, multiple difficult conditions must be met. First the user must permit the token and cryptogram generation with his or her own authentication method.

"This pair of token and cryptogram (also known as a "payment signal") must be transmitted to the POS for each transaction and cannot be used for multiple transactions.

"Then the fraudster needs to capture the signal on a device that is within very close proximity to the Samsung phone."

Magnetic Secure Transmission – one of the pieces of tech used by Samsung Pay to make payments – only works at short ranges, much like NFC.

What would it take?

Salvador Mendoza - who pointed out the Samsung Pay vulnerability - notes someone would be able to pose as a Samsung employee and pretend to teach customers how the service works, all the while carrying out the skimming attack.

The hacker would also need to block the transmission between the phone and the card issuer though, or use the token very quickly afterward before the details go through.

The blog post finishes, "In summary, Samsung Pay's multiple layers of security make it extremely difficult to make a purchase by skimming a token."

It also highlighted that the user's phone would be sent an alert of any payment, so anyone exposed to the fraud would instantly be able to see an erroneous transaction.

Even though there is a security risk here, Samsung is certain its security is high enough to make the scenario almost impossible to recreate.

TOPICS
James Peckham

James is the Editor-in-Chief at Android Police. Previously, he was Senior Phones Editor for TechRadar, and he has covered smartphones and the mobile space for the best part of a decade bringing you news on all the big announcements from top manufacturers making mobile phones and other portable gadgets. James is often testing out and reviewing the latest and greatest mobile phones, smartwatches, tablets, virtual reality headsets, fitness trackers and more. He once fell over.

Latest in Samsung Phones
Samsung Galaxy S25 Ultra
The Samsung Galaxy S26 Ultra could have even smaller bezels - and that could mean an even bigger display
Samsung Galaxy S24 Ultra on an orange background
The Samsung Galaxy S24 Ultra is still full price and I don't know what Samsung's playing at
An image of the Samsung Galaxy S25 Ultra from a hands-on event
Will Samsung's new Galaxy AI features come to older devices? Here's what we know
'Circle to Search' on a Galaxy S25 Ultra can now identify a song you sing, hum, or play.
Samsung’s clever new ‘Circle to Search’ trick could help you figure out that song that is stuck in your head
An image of the Samsung Galaxy S25 Ultra from a hands-on event
We celebrate the Samsung Galaxy S25 launch event with a special episode of our podcast
Samsung Galaxy S24 hands on handheld back straight white
Samsung Galaxy S25 AI leak teases major Gemini upgrades and new morning briefings
Latest in News
DeepSeek
Deepseek’s new AI is smarter, faster, cheaper, and a real rival to OpenAI's models
Open AI
OpenAI unveiled image generation for 4o – here's everything you need to know about the ChatGPT upgrade
Apple WWDC 2025 announced
Apple just announced WWDC 2025 starts on June 9, and we'll all be watching the opening event
Hornet swings their weapon in mid air
Hollow Knight: Silksong gets new Steam metadata changes, convincing everyone and their mother that the game is finally releasing this year
OpenAI logo
OpenAI just launched a free ChatGPT bible that will help you master the AI chatbot and Sora
An aerial view of an Instavolt Superhub for charging electric vehicles
Forget gas stations – EV charging Superhubs are using solar power to solve the most annoying thing about electric motoring