Apple Pay fraud?

My wife used her iWatch with Apple Pay to purchase drinks several times at a concert (they were cashless and only took electronic payments). During the concert two fraudulent transactions occurred, one for Disneyland tickets and one for tickets to a Disney concert hall (the concert was in San Diego). Could someone have lifted the credit card information while she processed it using Apply Pay? Could the beer attendant have processed multiple transactions at once? She rarely uses her physical card, so it's unlikely that someone wrote the numbers down a long time ago and just happened to process a transaction while she was at the concert.

Apple Watch Series 5

Posted on Sep 6, 2024 6:37 AM

Reply
Question marked as Top-ranking reply

Posted on Sep 6, 2024 7:04 AM

All the data is encrypted transmitted is encrypted. All the data stored on your Apple Watch is encrypted. The full card number is not stored on your card.


When a transaction is started on her Apple Watch the Secure Enclave generates a token that is only valid for one transaction. So, even if a man in the middle attack was attempted they would only have a token, which is already used.


Apple Pay has never been hacked. There is not even a proof of concept proposed by researchers.


The more likely scenario is your spouse swiped or inserted the chip into a transaction terminal and the data was skimmed. The data is then bundled with personal information from the internet/social media and sold on the Dark Web.


Did the bank indicate if Apple Pay was used?

Similar questions

3 replies
Question marked as Top-ranking reply

Sep 6, 2024 7:04 AM in response to Rynak

All the data is encrypted transmitted is encrypted. All the data stored on your Apple Watch is encrypted. The full card number is not stored on your card.


When a transaction is started on her Apple Watch the Secure Enclave generates a token that is only valid for one transaction. So, even if a man in the middle attack was attempted they would only have a token, which is already used.


Apple Pay has never been hacked. There is not even a proof of concept proposed by researchers.


The more likely scenario is your spouse swiped or inserted the chip into a transaction terminal and the data was skimmed. The data is then bundled with personal information from the internet/social media and sold on the Dark Web.


Did the bank indicate if Apple Pay was used?

Sep 6, 2024 7:41 AM in response to Jeff Donald

Ah, thank-you. It's my wife's card, so I didn't look beyond what was reported to me. The two transactions were via a computer, but it wasn't displayed if it was through Apple Pay, but when I dug through her app, it looks like someone also went in person to Lowes in North Carolina a day later. All three transactions are already flagged by our credit card company as being fraudulent.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Apple Pay fraud?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.