PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Apple Pay Users Could Lose £1,000 per Transaction via MITM Attack

By Tim Sloane
October 1, 2021
in Analysts Coverage, Fraud & Security, Security
0
0
SHARES
0
VIEWS
Share on LinkedIn
Apple Pay Users Could Lose £1,000 per Transaction via MITM Attack

Apple Pay Users Could Lose £1,000 per Transaction via MITM Attack

Mobile wallet security has become increasingly important as contactless payments continue to replace physical cards for millions of consumers worldwide. Features that prioritize speed and convenience, such as transit payment capabilities, have helped drive widespread adoption of digital wallets, but they also create new opportunities for researchers to identify potential vulnerabilities before they can be exploited at scale. As payment ecosystems become more sophisticated, ensuring strong authentication while preserving a seamless customer experience remains a delicate balancing act.

How the Apple Pay Express Transit Vulnerability Works

Recent research highlighting a potential weakness in Apple Pay’s Express Transit mode underscores the importance of continually evaluating mobile wallet security across the payments ecosystem. The demonstrated attack raises broader questions about where responsibility lies when vulnerabilities involve multiple participants—including device manufacturers, payment networks, and EMV specifications. Although there is no evidence that the exploit has been widely used in the real world, the findings reinforce why collaboration among payment stakeholders is essential to maintaining consumer confidence in contactless payments.

The man-in-the-middle attack vulnerability has been demonstrated by Dr Andreea Radu, the lead researcher at the School of Computer Science at the University of Birmingham. The vulnerability requires that the Apple Pay user have express transit mode enabled, a feature that allows the payment to be initiated at a transit terminal without unlocking the phone. Apple deployed this feature in May of 2019.  One noteworthy point: the attack works through most purses and pockets and modifies the transaction so that it appears the user was authenticated using the Apple biometric of PIN.

Who Is Responsible for the Security Flaw?

One important aspect that isn’t clear is who is responsible for this breach in security. The research team indicates that the flaw is specific to a Visa card within Apple Pay and that neither Apple nor Visa are taking action to fix the flaw. It is unclear if the researchers tested other network cards, such as Amex or Mastercard, to determine If this is a problem in the EMV specification itself or just Visa and Apple’s implementation of EMV:

“However, an experiment conducted by the Universities of Birmingham and Surrey found threat actors are able to exploit a flaw to bypass the Apple Pay lock screen and charge the connected card, in some cases up to £1,000 per transaction, without user authorisation. The owner doesn’t have to leave the device unattended or have it stolen – thieves can also exploit the flaw through a bag or coat, thanks to contactless payment technology.

In a demonstration of the exploit, researchers used an iPhone, an NFC-enabled Android phone, a standard EMV reader payment terminal, and a laptop connected to a Proxmark radio-frequency identification (RFID) scanner.

The Android phone is used as a card emulator to communicate with a payment terminal. Meanwhile, the Proxmark device, connected to a laptop, acts as a reader emulator to communicate with the potential victim’s iPhone, which is led to act as if the transaction is happening with a legitimate transport EMV reader.

Researchers first set up a payment for £1,000 on the payment terminal and ran a script on the laptop to alert the Proxmark RFID scanner to receive the transaction, which then passes it to the payment terminal. Meanwhile, the flaw also manipulates the payment terminal to believe that the victim had authorised the transaction by biometric or PIN verification, enabling the transaction to take place.”

Conclusion

The continued growth of contactless payments makes mobile wallet security a shared responsibility among technology providers, payment networks, financial institutions, merchants, and standards organizations. As new payment features are introduced to improve convenience, ongoing security research plays a vital role in identifying weaknesses before they become widespread threats. Independent academic research helps strengthen the overall payments ecosystem by encouraging vendors to evaluate potential risks and improve existing protections.

The Apple Pay Express Transit findings demonstrate that even mature payment technologies require continuous scrutiny. Whether the vulnerability ultimately stems from Apple Pay, Visa’s implementation, or broader EMV specifications, the research highlights the need for coordinated action whenever multiple parties contribute to the payment experience. Preserving consumer trust will depend on addressing vulnerabilities quickly while continuing to balance security, usability, and innovation in digital payments.

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

0
SHARES
0
VIEWS
Share on LinkedIn
Tags: Apple PayBiometric AuthenticationEMVSecurityVisa

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    bots fraud, bank security in data sharing, J.P. Morgan fraud protection TSYS, 3D Secure 2.0

    The Evolution of 3D Secure Puts it at the Center of Fraud Prevention

    September 18, 2026
    fraud detection signals

    Why Fraudsters Look Trustworthy and Good Customers Look Suspicious

    September 17, 2026
    Fraud Monitoring, Nacha ACH Rules, Same Day ACH

    10 Years Running, Same Day ACH Continues to Break New Ground

    September 16, 2026
    stablecoin infrastructure

    To Unlock Stablecoins’ Potential, Infrastructure Gaps Must Be Resolved

    September 15, 2026
    Latin America payment orchestration

    Navigating Latin America’s Complex Payment Ecosystem

    September 14, 2026
    upi biometric

    Beyond Authentication: Rethinking Digital Identity Security

    September 11, 2026
    Fraud Monitoring, Nacha ACH Rules, Same Day ACH

    Nacha’s Upcoming Rules Refresh Is All About Improving Clarity

    September 10, 2026
    instant payments for financial institutions

    Why Haven’t More Financial Institutions Adopted Instant Payments?

    September 9, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result