Smooth-talking fraudsters clone contactless cards, authorize payments in just 13 minutes
A fraud campaign known as WindRelay has targeted Android users by combining persuasive phone calls with malware to steal card data and authorise fraudulent payments or cash withdrawals. Researchers at Group-IB said some European victims were compromised during calls lasting only 13 minutes, illustrating how quickly social engineering can bypass normal fraud-prevention responses.
Attackers pose as bank helpdesk staff, persuade victims to install the SpyNote remote-access trojan, then use it to install WindRelay and instruct them to tap their card against an NFC-enabled phone and enter their PIN. The malware relays a live card-to-terminal exchange to a second device or fraudulent payment terminal, allowing transactions to appear legitimate; in one case, criminals also accessed a victim’s banking app and took out loans. Group-IB identified 23 related samples uploaded between November 2025 and July 2026, with evidence of victims in Czechia, Slovakia and Slovenia.
- Fraudsters combine phone scams, malware and NFC card relays.
- Some attacks succeeded within 13 minutes.
- Victims may face payments, withdrawals and fraudulent loans.