Credit card used in Apple Pay compromised

Is there any way this could happen without Apple Pay being vulnerable?


Situation:

  • Family member 1 (FM1) received Apple Pay notice that charge was declined / rejected at a business 800 miles from their physical location.
  • Bank (Chase) reports
    • that FM1's device / digital wallet was used for the transaction.
    • the card is registered with 3 phones, as expected


My understanding of Apple Wallet is that it is tied to the hardware, so cloning isn't possible.


What else could have happened? My first thought was that the maybe someone social engineered getting the card registered to their phone but that would have resulted in a 4th device being registered with Chase.


This has me fairly concerned....this should not be possible.



[Re-Titled by Moderator]

Posted on Dec 6, 2024 8:32 AM

Reply
Question marked as Top-ranking reply

Posted on Dec 7, 2024 10:09 AM

Jeff,


I contacted my CC fraud department and they indicated there was no SEID attached to the transaction. They also clarified that it was an online transaction and a MANUAL ENTRY. They also indicated that the CC number used was the number issued to my device’s Apple Pay which is different than my actual physical card number. The reason it was declined was because the address and CVV entered manually did not match.


I have recently made at least 3 online purchased for Christmas on reputable sites using the APPLE PAY Option. My guess that someone can access the CC number on their end or in transit and attempted a manual entry.


I will not be using APPLE pay for now. Sticking to PayPal. Never had issues with that.

Similar questions

49 replies

Dec 7, 2024 10:44 AM in response to Saegzz

I don't think this is correct, at least with Chase.


Transactions made with my card, or card number, are shown in the apple wallet. Furthermore, 3 people have linked my card to their phone (me, and two children). In the Apple wallet each of us see our own apple pay transactions and no one elses.


This behavior could be different with the Apple credit card, or maybe even other banks.

Dec 16, 2024 12:21 PM in response to atrocktop

I recently had several Apple Pay charges (total 775.00). Hacked my Apple ID and my debit card was linked to my wallet. 7 different charges for funds to my apple account then charges for games. I have been denied twice by Apple for refund. I requested the data from my phone and the charges reflect a phone that is not on my account. However, when I contact Apple to discuss I am told that the denial is final. How can that be? Its Fraud. My debit card was linked to my wallet and that is how they were able to add funds to my account and then purchase games however the funds never are reflected on my phone...The transactions are all in minutes of each other.


I have had an Iphone since Iphone 6.


[Edited by Moderator]

Dec 17, 2024 6:28 AM in response to Saegzz

@Saegzz - If that is directed to the OP (me) I don't think the facts support your conclusion, but I'd be happy to hear how your explanation fits the facts below:


The bank declined the charge on a non-apple linked card. It is not apple pay cash. The rejection was displayed in Apple Pay only. It is not visible at the bank site. If someone stole card information and tried to order online or skimmed a card and tried to use a cloned card it at the point of sale it would show as rejected on my bank's site (Chase). This has happened before.


The card is linked to multiple Apple wallets (mine, son, and daughter). The rejection only shows on my son's phone.


The Apple Pay wallet ONLY shows card transactions made by the specific phone's Apple Pay wallet. My son cannot see anyone else's transactions by Apple Pay or any transaction made on a traditional way by anyone with a physical card (my wife and me).

Dec 17, 2024 6:32 AM in response to Jeff Donald

@Jeff - if this is directed to me, please see my other comments. There is no suggestion that Apple declined the card.


Apple Pay shows the decline and only shows transactions made via Apple Pay on that phone (in Apple Pay each user sees just their transactions and cannot see physical card transactions or Apple Pay transactions by other family members.


This suggests that they attempted charge (declined by the bank) was initiated via Apple Pay, otherwise the declined charge would not be displayed in the Apple Wallet.

Dec 7, 2024 9:36 AM in response to Jeff Donald

@Jeff Donald

The bank fraud department said:

1) there are 3 devices with digital wallets (3 family members)

2) Family member 1's device / digital wallet (I questioned this point extensively) at a location 800 mile from his physical location.

3) The transaction was made at 5:45AM and I was told of the transaction being delined by the bank 45 minutes later and confirmed family members location.


This does not seem technially possible without something we all thought / were led to believe was 'impossible'



Dec 7, 2024 9:38 AM in response to Saegzz

@Saegzz

Yes, this was the bank declining the transaction. The bank says the transaction was from the digital wallet associated with a phone I *know* was 800 miles from the point of sale.


We all think that means the phone needed to be presented at the point of sale terminal for near field communication of encrypted data. This doesn't seem possible BUT it happend.

Dec 7, 2024 10:06 AM in response to Jeff Donald

I have not been able to explicitly get the SEID from the bank. The were able to confirm:

1) that there were three distinct devices (presumably distinct SEIDs) associated with the card.

2) the device/wallet ids they were able to see were associated with the phone 800 miles from the pont of sale.


There are 3 authorized users. I *think* this functinally achieves the same outcome as explicitly getting the SEID, assuming competence of the bank rep. I asked a lot of questions and I have no reason to think they were not seeing what they told me.

There is nothing to support that an unauthorized third party has added this card to their phone which would be an easy explination.

Dec 7, 2024 10:04 AM in response to Jeff Donald

I appreciate your questions and understand you're trying to help. Thank you.


They told me it was classified as a 'manual transaction'. When asked if that means the card was manually keyed, or somthing else, they said no, it was a digital wallet (their generic term for Apple Pay or Android equivalent). Multiple people at the bank gave the same explination.


Also, the digital wallet was the same one that is associate with known valid transactions made by my son using his phone wich was not at the point of sale.


I'll take another run at the bank on Monday to see if I can get an SEID for the transaction. Any chance you have an escalation point at Chase?

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Credit card used in Apple Pay compromised

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.