Credit card used in Apple Pay compromised

Is there any way this could happen without Apple Pay being vulnerable?


Situation:

  • Family member 1 (FM1) received Apple Pay notice that charge was declined / rejected at a business 800 miles from their physical location.
  • Bank (Chase) reports
    • that FM1's device / digital wallet was used for the transaction.
    • the card is registered with 3 phones, as expected


My understanding of Apple Wallet is that it is tied to the hardware, so cloning isn't possible.


What else could have happened? My first thought was that the maybe someone social engineered getting the card registered to their phone but that would have resulted in a 4th device being registered with Chase.


This has me fairly concerned....this should not be possible.



[Re-Titled by Moderator]

Posted on Dec 6, 2024 8:32 AM

Reply
Question marked as Top-ranking reply

Posted on Dec 7, 2024 10:09 AM

Jeff,


I contacted my CC fraud department and they indicated there was no SEID attached to the transaction. They also clarified that it was an online transaction and a MANUAL ENTRY. They also indicated that the CC number used was the number issued to my device’s Apple Pay which is different than my actual physical card number. The reason it was declined was because the address and CVV entered manually did not match.


I have recently made at least 3 online purchased for Christmas on reputable sites using the APPLE PAY Option. My guess that someone can access the CC number on their end or in transit and attempted a manual entry.


I will not be using APPLE pay for now. Sticking to PayPal. Never had issues with that.

Similar questions

49 replies

Dec 7, 2024 10:39 AM in response to Jeff Donald

Yes, read your question and I understand the banking sector's confidence in the transaction security.


Mulitple representitives said the transaction was classified (manual, digital wallet). I think this is a terminology difference rather than a functional difference.


Isn't this moot? We see the transaction in the wallet. It was done at a POS, through the Apple payment infrastructure. If all apple pay transactions are considered card present, and we see the transaction rejected as shown below, then it follows that it should be classified as card presnet, in your terms, right?


FYI: just so you know where I'm coming from, I have 25 years experience (15 as an executive) in operations, technology, and cybersecurity at an NYSE listed finanical services firm (not a payments processor).



Dec 7, 2024 10:55 AM in response to atrocktop

How many POS terminals do they manually enter a transaction? You really thinks Buc-Ee does a manual transaction at a POS? What does a manual transaction require? It requires a physical card? Show me on your iPhone the Apple Pay data your bank encrypted.


If what you’re saying is true, consider the ramifications, your bank’s encryption was broken. The Secure Element on your iPhone was compromised. The SE uses ISO standards developed by your former industry.

https://en.wikipedia.org/wiki/Secure_element


Is this what you’re really saying? If so, you just single-handedly threw out decades of security. You’re basically saying your banks encryption is compromised. Is that right?


I too have a background in financial industry. I know what PNO’s have for data and what banks have. I’ve never seen an Apple Pay manual transaction. It’s never happened.


This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Credit card used in Apple Pay compromised

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.