The 13-Minute Gap: How NFC Relay Fraud Exposes the Fragility of Bank Fraud Detection

AI-generated image · US National Wire
While cybersecurity experts focus on the malware, the real systemic risk lies in payment rails that allow high-speed, card-present fraud to bypass bank defenses before a human can even blink.
In the world of fintech, speed is usually the primary selling point. But for the victims of a sophisticated new fraud campaign known as WindRelay, speed is the weapon. As first reported by The Register, attackers are now utilizing a combination of social engineering and malware to clone contactless cards and authorize fraudulent payments in as little as 13 minutes.
From a technical perspective, the attack is a marvel of coordination. But from a markets-and-money perspective, it reveals a glaring systemic failure: the window between transaction authorization and fraud detection is wide enough for a criminal to drive a truck through. When the payment rails remain open and the 'handshake' is validated, the consumer is left holding the bag while the money vanishes in real-time.
### The Mechanics of the Heist
As detailed by The Register, the WindRelay campaign—discovered by the security firm Group-IB—does not rely on a single exploit. Instead, it weaves together three distinct capabilities into a single, high-pressure session.
It begins with a social engineering call. An attacker poses as a bank helpdesk employee, convincing the victim that there is a problem with their payment card. While the victim is on the line, the attacker directs them to install a version of SpyNote, a remote access trojan (RAT) that has been circulating on cybercrime forums since 2016. Group-IB noted that the file names of these RATs often include the target's name, suggesting a level of prior reconnaissance and a tailored approach for each victim.
Once the RAT is active, the attacker silently installs the WindRelay NFC relay malware on their own device. The victim is then instructed to tap their physical payment card against their NFC-enabled Android smartphone and enter their PIN.
This is where the systemic failure occurs. WindRelay captures the live EMV APDU exchange—the same data used by genuine point-of-sale (POS) machines to authorize contactless payments. The fraudster then uses a second device to transmit this captured data to an attacker-controlled POS terminal linked to a fraudulent merchant bank account, or to an ATM.
### The 'Invisible Relay' Problem
The danger of this method is that it mimics legitimate behavior so perfectly that the bank's automated defenses are effectively neutralized. Group-IB explained that the fraudster's setup acts as an "invisible relay," passing the exchange back and forth across a distance. Because the terminal is completing a live handshake with a real card, the transaction is processed as a normal, authorized purchase or withdrawal.
For the financial institutions involved, the transaction looks valid because, technically, it is. The card is real, the PIN is correct, and the NFC handshake is completed. The failure is not in the encryption of the card, but in the inability of the bank to distinguish a legitimate local transaction from one being relayed across a network by a criminal in real-time.
### Diversifying the Payout
The WindRelay attackers aren't stopping at card-present fraud. Group-IB reported that in at least one instance, attackers used their RAT access to enter the victim's banking app directly to take out loans in the victim's name.
By hitting two separate payout channels—digital loans and card-present purchases—the attackers ensure they maximize the theft before the bank or the victim can react. The efficiency is staggering; the entire process, from the initial phone call to the final authorization, can be completed in under a quarter of an hour.
### A Pattern of Systemic Vulnerability
WindRelay is not an isolated incident, but rather part of a growing trend of NFC relay attacks. The Register notes that this campaign shares similarities with NGate (discovered in 2024 and seen again in 2026) and Ghost Tap.
Ghost Tap, also discovered in 2024, utilized Chinese malware sold through Telegram cybercrime communities. Group-IB estimates that Ghost Tap caused more than $355,000 in losses during the period between November 2024 and August 2025.
Researchers identified 23 samples associated with WindRelay on VirusTotal between November 2025 and July 2026. These samples pointed toward victims located in Slovenia, Slovakia, and Czechia. Group-IB observed that the malware samples contained unique UI elements, including the victims' names, which suggests the threat actors can dynamically build malicious applications tailored to specific individuals.
### Opinion: The Fraud Detection Gap
*Opinion: The industry's obsession with 'frictionless' payments has created a security vacuum. When banks prioritize the speed of the transaction over the verification of the context, they shift the entire risk profile onto the consumer. The WindRelay campaign proves that the current fraud-detection windows are far too slow. If a criminal can execute a full-scale theft—including loans and physical cash-outs—in 13 minutes, the 'security' provided by a PIN is an illusion. The payment rails are functioning exactly as designed; the problem is that the design assumes the person initiating the handshake is the person owning the account.*

