Can Apple Pay get hacked?

I have payments on one of my bank accounts that has been done by apple pay but I dont recognise it


[Re-Titled by Moderator]

iPhone 14 Pro Max

Posted on Jul 13, 2023 1:01 AM

Reply
Question marked as Top-ranking reply

Posted on Aug 23, 2023 1:10 PM

Contact the bank that issued the credit or debit card used for the fraudulent transaction. Apple Pay does not approve or decline charges. Apple Pay only securely transmits the data associated with your card. Your credit card issuer approved the charge and you need to dispute the charge. Please use the phone number on the back of the card and talk to their fraud support team.

99 replies

May 2, 2024 9:45 AM in response to Bborz

The third parties are the bank that issued the card and Payment Network Operator (MasterCard, Visa, American Express, Discover etc.). The weakest part of the system is the user. Talk to any fraud investigator and they’ll tell you the weakest link is the human element, the account holder and the bank support personnel.


People don’t understand the technology, so that must be the issue. Americans are much slower to adopt new technology. Acceptance of Apple Pay, and similar payment services have much wider acceptance in Europe and Asia. Americans fear what they don’t understand.


Everyone wants an explanation of how they were hacked. They can’t explain how the technology was hacked, but they know they’re infallible and the bank told them it’s Apple Pay. Just ask the bank CEO why the bank approved adding stolen credit card credentials to a fraudsters iPhone? What do you think his answer will be?

May 2, 2024 11:01 AM in response to Neurodivercat

I thought you might be interested in the article and YouTube video at the end of the article.


https://www.retaildive.com/ex/mobilecommercedaily/apple-pay-fraud-reflects-weakness-with-credit-cards-not-platform


As, the experts note <“Whenever a new channel is created, an opportunity for fraud is created along with it,” he said. “We have no indication that Apple Pay itself has been breached or its fundamental security technologies such as biometric authentication (TouchID) and tokenization (using one-time payment card information to prevent credit card theft) have been bypassed.”>



May 2, 2024 12:38 PM in response to Bborz

Read the flow chart I posted, again, for the most basic Apple Pay fraud scheme. It’s social engineering that fraudster are using. They are using against you, me and every other credit card holder. It’s the banks failing to require stricter verification of credit/debit cards. It’s bank support people falling victim of social engineering and allowing fraudsters to add your credit card information to their computer or iPhone. At best, this is only marginally an Apple issue. At worst, it’s the bank. You’re willing to fault technology, but why not the bank? Why isn’t anyone in this thread saying, I want the more secure technology and I’ll switch my bank and credit cards to be more secure? Or, is it the fear of technology that drives the consumer to banks just assuming a stone building must be more secure?

May 2, 2024 1:54 PM in response to JDW-Dayton

Standard credit card fraud MO: Use a stolen card (you can buy a working card on the dark web for under $5) for a couple of small purchases. If they clear the card is good, so make a large purchase. I check my card accounts every day or two; a few months ago I saw a small charge, around $18. BUT my bank also sent me a text asking if I had made the purchase. When I said no they canceled the transaction and the card, and sent me a new card. How did the bank know? I suspect it was the “superman test”. The purchase was in a location that I couldn’t have gotten to from my current location unless I was superman. (It’s technically called a “velocity check”). That’s why the bank wants to know if you will be traveling.

May 19, 2024 2:48 PM in response to thamir78

Using the debit card at an ATM, unless it is a bank ATM, or gas station makes it very likely that there was a skimmer in at least one of those spots. If it’s the same card that is where it was compromised. And if you use it at a POS terminal, those are frequently compromised at the corporate level. The transaction has to go from your Apple Wallet to the POS terminal, and the transaction (with your card number) is then sent to a payment processor, who then sends it to the bank. Any of those steps could have intercepted the card number.

Apr 14, 2024 8:33 AM in response to Bborz

Chase told me the transaction showed as being on MY device ID. I checked my ID for unknown devices, nothing. The strange codes in front of the businesses charged, the timing after use in specific grocery store, all point to a technical hack at some point. If the timing was random that’s one thing, but only happening 3 times over 2 months immediately after a grocery store visit and use… too many common denominators. Could it be a bank or store employee? Maybe, doesn’t explain chase telling me transactions have my device ID.

May 2, 2024 11:39 AM in response to Kylemcc10

Kylemcc10 wrote:

So basically Apple Pay is flawless but my card still got leaked magically in the process and it’s my credit cards fault. There is zero point of using it then. I also get notified when my card is linked to a device. So I already know that wasn’t the case.

There is nothing magical about your card getting leaked. Over 150 million credit cards have been leaked through breaches of internet merchants this year alone, many of them from a major AT&T breach, but also a United Health Care subsidiary. And T-Mobile last year. And any time you swipe a credit card there is a chance that the terminal has been compromised.

May 2, 2024 1:38 PM in response to Jeff Donald

Let’s face it, if all this information is generally factual then I would want to go visit those small retailers and see if their audit trail really has those transactions. With the same card number and all with the same device ID it would appear more likely the fraud is within the bank system, even if it is being perpetrated by an outside unauthorized party. Otherwise it’s a clone phone and fast car!

Jan 8, 2024 6:29 AM in response to Jeff Donald

I’ll respectfully disagree with you. If my card was skimmed, shimmed, copied, etc, it still needs to be added to someone’s digital wallet. In order to do that two factor authorization needs to take place and that did not happen. Just because someone has your credit card number does not give them access to adding it to MY digital wallet without me knowing.

Apr 4, 2024 2:00 PM in response to Jeff Donald

False. Just got off phone with Chase. I have about 20 charges on my card that say “Apple Pay” and chase says their system says it was my device. There’s no way. They are from all different businesses on the same day for small amounts $1-$70. Places I’ve never been to. Someone has figured out a hack. There does seem to be a common thread. All happened after I paid with Apple Pay at a certain grocery store.

Apr 13, 2024 12:09 PM in response to kcala2414

I’m defensive against misinformation. Which just so happens to be what people spread when they don’t understand the technology and assume facts that aren’t in evidence. Apple Pay has nothing to do with skimming (compromises the magnetic stripe) or shimming (compromises the chip). People share their personal information all over Facebook, Instagram, TickTock etc. It doesn’t take a genius to combine personal information, financial information (credit/debit card information) and social engineering and people loose billions every year.


Instead, technology companies come up with ways of reducing this threat and helping people use their credit and debit cards in a more secure way. What happens? The first time they lose 1¢ they blame a technology they have no understanding of. Instead of accepting personal responsibility for their actions and asking for help, place unfounded blame and make accusations that drive people away from the very technology that is designed to make their credit and debit card usage more secure.

Apr 14, 2024 10:28 AM in response to Jeff Donald

I can appreciate that you’re looking at it from a complete technical standpoint. When I say common denominator, I’m looking at it from an event standpoint. The fraudulent charges all began almost immediately after I used tap to pay at a specific grocery store. If they just had my number somehow it would be odd to only use it after I came into the store. That’s why I believe this is being done electronically someway. I believe There’s a technical answer for this. I just have no idea at this point. I’m not saying It was a checkout person, could be a manager, could be an IT person in country, could be an IT person back at their global headquarters, I have no idea, no way of knowing. Just looking for hypotheses, I can follow further.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Can Apple Pay get hacked?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.