RFID News

News and knowledge for the RFID industry

Can someone skim your card by standing next to you?

The crowded train is where the fear lives. The physics says otherwise.

Almost certainly not, and the reason is physics rather than luck. For someone to take money off your contactless card while standing behind you on a packed Northern line train, they would need to hold a reader within a few centimetres of the card, hold it square on, hold it still, and hope no other card in your wallet answers at the same time. Then they would need somewhere to send the money that is not traceable back to a real bank account, which does not exist. Then they would need you not to notice, which is not how bank refunds work.

The scale of it tells the same story. British shoppers made 19.2 billion contactless card payments in 2025, worth £311 billion. Total contactless fraud that year came to £46.8 million, according to UK Finance, the banking trade body. That is about one and a half pence lost in every hundred pounds tapped, and the overwhelming majority of it was not radio theft at all. It was cards that had been physically lost or stolen and then tapped in shops by whoever picked them up. The crowded train fear is real, but the thief in it has hands, not antennas.

Why distance kills the attack

A contactless card contains an RFID tag, which is short for radio frequency identification: a chip with no battery, attached to an antenna loop running around the inside edge of the plastic. The specific version banks use is near field communication, or NFC, running at 13.56 megahertz.

Here is the bit that matters. At that frequency the radio wavelength is about 22 metres, which means a card sitting a few centimetres from a reader is nowhere near far enough away to be receiving a radio wave in the way a radio receives Radio 4. It is sitting inside the reader’s magnetic field and disturbing it, a bit like a hand in a stream changing the ripples downstream. The reader detects its own field wobbling.

Fields like that weaken astonishingly fast. Double the distance and the coupling does not halve, it falls by roughly a factor of eight, because near field magnetic strength drops with the cube of distance. Triple the distance and you have lost around ninety-six per cent of it. That is why a shop terminal wants your card practically touching the glass, and why the standard the whole industry is built on, ISO 14443, specifies an operating range measured in centimetres rather than metres.

Security researchers have built long range readers to push past this, and the good ones manage reads at a few tens of centimetres. What they need is instructive: an antenna the size of a briefcase or a doorframe, a serious power supply, a card held stationary and correctly oriented, and no competing metal nearby. Every one of those conditions fails on public transport, where your card sits at a random angle inside a wallet next to three other cards that all answer at once and jam each other, on a moving train, surrounded by steel.

What they would get even if it worked

Suppose all of that lined up. What comes off the card?

Not your PIN, which is never stored readably. Not the three digit code from the back, which is not in the contactless part of the chip at all. On some cards a determined reader can retrieve the long number and expiry date, and on a few older ones a short list of recent transactions. That was a genuine scandal a decade ago and it is why the wallet industry exists.

Two things have since made that haul close to worthless. The first is that every genuine tap generates a cryptogram, a one time scrambled code unique to that transaction, calculated using a key that never leaves the chip. Capturing one is like photographing a used train ticket. It will not get you through the barrier again.

The second is regulatory. Since 2021 the UK has enforced strong customer authentication, which means most online card payments require a second check, typically a code or a tap in your banking app. Someone holding only a card number and expiry date cannot get far past a checkout page. Our explainer on how NFC works covers the underlying handshake if you want the detail.

The problem with stealing money you cannot keep

Even a perfect wireless read does not produce cash. A card authorises a payment to a merchant, and a merchant is a registered business with a bank account and a named human behind it. To convert your tap into money, the thief has to run it through their own merchant account, wait for settlement, then sit still while the chargebacks arrive and the bank freezes the account.

Meanwhile, the sums are trivial. Contactless carried a £100 per transaction cap for years. In March 2026 the Financial Conduct Authority lifted that fixed industry limit and allowed banks to set their own, though most kept familiar thresholds while they reviewed their fraud controls. Cards also carry a cumulative limit, a running total after which the terminal insists on a PIN. So the theoretical yield is a handful of small payments before the card locks itself.

And you are not out of pocket. Under UK rules, payments you did not authorise are refunded by your bank. The loss lands on the bank and the merchant, not the cardholder. A criminal doing all of this has performed a technically demanding attack, in public, using a traceable business account, for less than a few hundred pounds, which the victim gets back. It is a rubbish job. There is a reason nobody has been prosecuted for it in Britain.

The attack that does work, and why it does not scale

There is one wireless technique that genuinely functions: the relay attack. Two devices work together. One sits close to your card, the other close to a payment terminal somewhere else, and the two are connected over the internet so the card and terminal appear to be next to each other when they are streets apart.

Researchers have demonstrated it repeatedly, and it defeats the distance problem entirely because the card is only ever read from a normal, close range. What it does not defeat is the rest of the chain. It needs two criminals acting in real time, one physically adjacent to your pocket, a live terminal at the other end, and the same merchant account problem as before. It is a lot of coordination for a payment under the limit. Card networks also fight it with timing checks, because the extra milliseconds of internet round trip are detectable.

The same broad principle is what makes keyless car theft workable, incidentally, and there the prize is a £40,000 vehicle rather than a supermarket meal deal, which explains where the criminals actually spend their effort.

What is actually taking your money

If you want to reduce your real risk, look away from the radio.

Lost and stolen card fraud cost £109.8 million in the UK in 2025. That is the wallet on the pub table, the bag on the back of a chair, the card lifted from a communal hallway before the post is collected. It is the single most likely way your contactless card gets used by someone else.

Bigger still is remote purchase fraud, where your card details are used online without the card. That took £423.5 million in 2025 across 3.2 million cases. Those details do not come from your pocket. They come from data breaches, fake websites, phishing texts pretending to be a delivery firm, and calls from people claiming to be your bank.

Biggest of all, and growing fast, is authorised push payment fraud, where someone talks you into sending the money yourself. That accounted for £576.4 million in 2025, up 19 per cent. No wallet, no shielding and no chip design protects against a convincing conversation.

So the sensible defences are unglamorous. Turn on instant payment notifications so you see a transaction the second it happens. Report a missing card immediately rather than hoping it turns up. Pay with a phone or a watch where you can, because those demand your face or fingerprint before releasing anything. Treat any message asking you to move money or confirm details as false until proven otherwise. And on the Tube, keep one card presented on its own, not because of thieves but because two cards at a gate can mean two fares.

If you would still like to read the case against blocking wallets in full, we took that apart in do RFID-blocking wallets actually do anything.

Frequently asked questions

Can someone scan my card while it is in my pocket?

In laboratory conditions, with a large purpose built reader and a card held still and correctly aligned, a read at a few tens of centimetres is possible. In a real pocket, at a real angle, alongside other cards, it reliably fails. And a successful read yields a one time code that cannot be reused.

How much money can be taken from a contactless card?

Very little. Cards carry a cumulative spend limit after which a PIN is demanded, and any single payment sits within a limit set by your bank. More to the point, unauthorised payments are refunded, so the loss is not yours.

Is tap to pay safe compared with chip and PIN?

Yes, and in some ways safer. Both generate a unique cryptogram per transaction. Contactless also keeps your card in your own hand, which removes the classic risk of handing the card over or having your PIN observed at a terminal.

Are phone payments safer than card payments?

Generally yes. Phone and watch payments replace your real card number with a token, a substitute number useless outside that device, and require your face, fingerprint or passcode before they will release anything. A stolen phone is far less useful to a thief than a stolen card.

What is a relay attack and should I worry about it?

It is a real technique where two linked devices make a card and a distant terminal appear adjacent. It works, but it needs two coordinated criminals, live timing and a traceable merchant account, for a payment under the limit. It is not a meaningful everyday risk for cardholders.

What actually causes most card fraud in the UK?

Card details used online without the card, at £423.5 million in 2025, and people persuaded to transfer money themselves, at £576.4 million. Lost and stolen cards account for £109.8 million. Wireless skimming does not appear as a category at all.

Plain English explanations of the technology you use without thinking. Sign up to the RFID News newsletter, or read more about how contactless payment works.

Newsletter

Get the week in RFID, every Thursday

One email: implementations, hardware and tag launches, case studies and analysis. Free, and you can leave whenever you like.

We send one digest a week and nothing else. Unsubscribe in one click. See our privacy policy.

By Matt Houldsworth

Over 3 decades of experience in RFID, High Risk/Value Asset Management, Inspection Systems, Brand Protection Technology, Customer engagement technology, WIP management, Logistics tracking, Digital Product Passports (DPP), and Digital Twinning linked to physical products with RFID. My Veribli Tech Makes Circular Economies Work!