logo

How Phished Data Turns into Apple & Google Wallets

ID: b6ba12f7-5cba-5d42-850a-c08edc31dff0

STIX ID: report--b6ba12f7-5cba-5d42-850a-c08edc31dff0

Feed Name: Krebs on Security

Threat Score
75/100

Date Published: 2025-02-18

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Security research documents an active, large-scale carding campaign operated by China-based phishing groups that send mobile-targeted phishing via iMessage/RCS, capture card data (including keystroke capture), programmatically convert card details into card-image files for easy mobile wallet enrollment, and use techniques such as live operators and NFC-relay (“ghost tap”) apps to cash out. The criminals mass-create Apple/Google accounts, load multiple tokenized wallets onto phones sold in bulk or used to transact online and in stores, and researchers estimate substantial financial losses (researchers extrapolated ~33,000 domains and a possible ~$15 billion of fraudulent charges over a year under conservative assumptions).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.