Coming soon The Briev app is almost here. Leave your email and be first in on launch day.

Briev
Live
Crime & Justice

Fraudsters clone NFC cards and cash out in under 15 minutes via phone scam

A new scheme blends social-engineering calls with two Android malware tools to steal contactless card data and complete payments within a 13-minute call.

Group-IB uncovered a sophisticated fraud operation that combines a live phone scam with two pieces of Android malware to clone contactless payment cards in real time. The attacker calls the victim posing as a bank help-desk employee, persuades them to install the SpyNote remote-access trojan, and then uses it to silently install the WindRelay NFC-relay tool. While the victim taps their card and enters their PIN, WindRelay records the live EMV exchange and forwards it to a second device that completes unauthorized purchases or ATM withdrawals, even exploiting the victim’s banking app to take out loans.

The entire process can be finished within a 13-minute call. Researchers saw 23 WindRelay samples uploaded to VirusTotal from November 2025 to July 2026, with activity focused on victims in Czechia, Slovakia and Slovenia. The campaign resembles earlier NFC-relay attacks such as NGate and Ghost Tap, which have caused hundreds of thousands of dollars in losses. Group-IB noted the malware is custom-built for each target, indicating a high level of attacker sophistication.

Why it matters

The technique lets criminals steal card data and cash out instantly, exposing a new, fast-moving threat to mobile banking users.

In this story

NFC relaySpyNoteWindRelaysocial engineeringcontactless fraudEMV dataAndroid malwarebanking app theftEuropean victims