A Kaspersky report has documented a sharp rise in NFC-based attacks targeting Android smartphones in the first four months of 2026. The cybersecurity firm blocked 35,600 such attacks between January and April — up 188% compared to the 12,300 it stopped during the same period in 2025.
The spike is largely tied to a shift in attack methodology. Criminals have moved away from "direct NFC" interception toward a more sophisticated "reverse NFC" scheme. In this approach, victims are tricked into installing a malicious application and setting it as their default contactless payment method. The app then emits an NFC signal that causes ATMs to read the victim's phone as though it belongs to the attacker. The victim is subsequently pressured — through social engineering — to deposit funds into a purported "secure account" via an ATM, at which point the money flows directly to the fraudster.
The scheme is particularly dangerous because the victim initiates the transaction themselves, making it difficult for banks and security systems to flag it as unauthorized.






