Can Scammers Use My Credit Card in Apple Pay?
Criminals may try to add your card to Apple Pay, Google Pay, or another wallet on their phone—not because the wallet was hacked, but because they target the verification step.
Never share a verification code or approve a wallet activation you did not request.
Apple Pay and other wallets use strong security, but scammers often target the human verification step.
What is this scam?
You may receive a text, push notification, or email from your bank about adding your card to Apple Pay, Google Pay, Samsung Wallet, or another digital wallet—even though you did not start that process.
In most cases, criminals already have enough card details—from phishing, a data leak, or an earlier scam. They then try to trick you into completing the bank’s verification step through a convincing call, text, or message—not by breaking Apple Pay itself.
The weak point is usually not the wallet technology itself, but the moment your card issuer asks you to confirm that the card is really yours.
How this scam works
- Criminals obtain card details through phishing, data leaks, fake webshops, malware, skimming, or earlier fraud.
- They attempt to add the stolen card to Apple Pay, Google Pay, Samsung Wallet, or another digital wallet on their own device.
- Your bank or card issuer may send a one-time verification code, push approval, or activation request to verify the cardholder.
- The scammer contacts you pretending to be your bank, fraud department, Apple Support, or a payment provider.
- You are pressured to read out the code, approve the activation, or confirm you “requested” the wallet setup.
- Once the card is active in their wallet, they may use contactless payments in stores or online payments where wallets are accepted.
Why Apple Pay itself is not the problem
Apple Pay and similar wallets do not store your full card number on the device in a way that criminals can simply copy from a breach of Apple’s systems. Tokenisation and device security are designed to keep payments safer than many traditional card uses.
Public warnings about “Apple Pay fraud” usually refer to stolen card data plus social engineering at the verification step—not a hack of Apple Pay as a product.
That is why the most effective protection is scepticism toward unexpected verification messages and anyone who asks you to share or approve a code.
Warning signs
- An Apple Pay, Google Pay, or wallet activation message when you did not add a card yourself
- A call, text, or chat claiming to be your bank, Apple, or “fraud prevention” about wallet setup
- Pressure to act immediately or keep the conversation secret
- A request to read aloud a one-time code or tap Approve on a notification you did not start
- Someone saying your card will be blocked unless you verify wallet activation right now
- Messages with links to “confirm” wallet setup on an unfamiliar website
What to do if this happens to you
- Never share one-time verification codes—not by phone, text, chat, or email.
- Never approve a wallet activation or card-on-file request you did not initiate yourself.
- Remember: a real bank will not ask you to read out a wallet activation code to a caller.
- Open your banking app directly (not via a link in a message) and review notifications carefully.
- Enable transaction alerts and push notifications for card activity if your bank offers them.
- Contact your bank immediately using the number on your card or official website if you receive an unexpected wallet message.
- Ask your bank to freeze or block the card if anything looks wrong.
- Report suspicious calls and messages to your bank and national fraud reporting channels.
How Fraudly can help
- Use Fraudly to check suspicious shop, payment, or login links before you enter card details—many scams start with phishing or fake webshops.
- Read Scam Help guides on bank impersonation and phishing to recognise social-engineering scripts.
- Browse Scam Alerts for current fraud patterns affecting consumers in your region.
- Learn how Fraudly assesses trust signals in our Trust Methodology—useful context before you pay unfamiliar sites.
- If a seller or payment page feels rushed or unusual, pause and verify the website before sharing any card data.
Check a website before you pay
Paste a shop or payment link into Fraudly's free checker—get trust signals before you share card details or log in.
Check a website before you payFrequently asked questions
- Can someone add my card to Apple Pay without my phone?
- They need a device and your card details, but they do not need your physical phone. The scam targets the verification step your bank sends to you—often a code or approval on your phone or banking app.
- Is Apple Pay unsafe?
- Apple Pay is designed with strong security. The risk in this scam is usually stolen card data plus tricking you into completing verification—not a flaw that makes the wallet inherently unsafe.
- What if I shared a verification code?
- Contact your bank immediately, ask them to block the card and review recent wallet and card activity. Change banking app passwords if advised and monitor alerts closely.
- Why did my bank send me an Apple Pay activation message?
- Legitimate messages appear when you—or someone with your card details—attempt to add the card to a wallet. If you did not start that, treat it as suspicious and call your bank using official contact details.
- Can this also happen with Google Pay or other wallets?
- Yes. The same pattern appears with Google Pay, Samsung Wallet, Garmin Pay, and other digital wallets that require issuer verification. The advice is the same: never share codes and never approve activations you did not request.
Related scam guides
Bank Impersonation Scams
Fraudsters pretend to be your bank to authorise transfers or steal login codes.
Read guidePhishing Emails
Fake emails that steal passwords, payment details, or install malware.
Read guideFake Webshops
Copycat stores that take your money and never ship—or steal card details.
Read guideWhatsApp Scams
Messages from “family,” “bosses,” or strangers pushing urgent payments or codes.
Read guide
Fraudly is not a law enforcement agency. We provide informational guidance and links to official reporting organisations.
Related Fraudly resources
- Website scam checkerRun a free URL check for trust signals, scam patterns, and plain-language risk context.
- Scam awareness certificateTest your scam detection skills and earn a shareable Fraudly certificate.
- Download Fraudly appGet the iOS app or Chrome extension for on-the-go website trust checks.
- Fraudly PremiumDeep Scan and Live Protection in Chrome—website scans stay free.
- Scam alertsPublished threat alerts with context on emerging phishing and scam campaigns.
- Intelligence HubEditorial guides on fake webshops, phishing, and warning signs before you pay or log in.