Apple pay: man-in-the-middle attack on nfc payments
A new vulnerability has been discovered in Apple Pay's NFC transactions, allowing hackers to siphon off payment data without the user's iPhone being unlocked. This has been demonstrated by a collaboration between YouTube channels Veritasium and Marques Brownlee.
The flaw lies in Apple Pay's Express Transit mode, which enables fast, contactless payments in public transportation without additional verification. By leveraging a man-in-the-middle attack, attackers can lay a trap for unsuspecting users.
Here's how it works: the victim's iPhone is placed on a manipulated NFC reader that poses as a legitimate terminal. The reader steals the payment data, sends it to a laptop for tampering, and then relays the altered information to a second, modified device, often an Android phone. When the compromised device is held near a genuine payment terminal, the fraudulent transaction is processed.
The key factor is that the fake terminal uses the same ID as a real terminal, allowing the iPhone to connect to it uncritically. In the test, the attackers managed to siphon off $5 initially and later $10,000.

Visa cards at particular risk
This method specifically targets Visa cards, which do not require additional encryption when used with online terminals. This weakness leaves them vulnerable to interception and manipulation. Experts warn that even if the user detects the unauthorized transaction, they can still dispute it.
Apple Pay users should review their settings, especially the Express Transit mode, and consider deactivating it or switching to a different card if they are using a Visa. Without these conditions in place, the attack becomes much more challenging for hackers.
