US National WireUS NATIONAL WIRE
TechOpinion

The 13-Minute Gap: Why Bank Authorization Windows are a Systemic Liability

Portrait of Alicia Ferro
Alicia Ferrofintech & paymentsAug 14AI
The 13-Minute Gap: Why Bank Authorization Windows are a Systemic Liability

AI-generated image · US National Wire

Opinion: The WindRelay fraud campaign proves that the real danger isn't just the malware, but a banking infrastructure that allows high-value fraud to clear before a victim can even hang up the phone.

In the world of payments, speed is usually marketed as a feature. But for the victims of the WindRelay fraud campaign, speed is the primary weapon.

As first reported by The Register, cybersecurity firm Group-IB has uncovered a sophisticated attack targeting Android users in Czechia, Slovakia, and Slovenia. The mechanics are a textbook example of modern social engineering: a fraudster poses as a bank helpdesk employee, tricks the victim into installing a remote access trojan (RAT) called SpyNote, and then deploys an NFC relay malware known as WindRelay. By instructing the victim to tap their card and enter a PIN during a phone call, the attacker captures a live EMV APDU exchange—essentially a digital clone of the card's authorization handshake.

From a technical standpoint, the malware is impressive. Group-IB notes that the attackers can dynamically build malicious applications tailored to individual victims, combining a live call, a personalized RAT, and NFC relay malware into a single session. They can then route this data to a fraudulent merchant bank account or an ATM to execute card-present purchases.

But as a fintech columnist, I argue that focusing on the 'cleverness' of the malware misses the systemic failure. The real story here is the authorization window. According to The Register, these attacks can be carried out in as little as 13 minutes. In that tiny sliver of time, the fraudster can execute fraudulent charges and, in some cases, use RAT access to enter a banking app and take out loans in the victim's name.

This is a liability gap of staggering proportions. When a transaction is processed as a 'live handshake' with a real card, the banking system treats it as a legitimate, authenticated event. Because the terminal is genuinely completing the exchange, the transaction processes as normal. The system is designed to trust the chip and the PIN; it is not designed to question why a 'card-present' transaction is happening in real-time while the account holder is simultaneously engaged in a suspicious helpdesk call.

By the time the bank or the victim realizes something is wrong, the money is gone. The fact that attackers can hit two separate payout channels—digital loans and physical purchases—before the bank can react suggests that our current authorization windows are far too wide and our fraud detection far too reactive.

We are seeing a pattern of these NFC relay attacks. Group-IB previously identified NGate and Ghost Tap (the latter causing over $355,000 in losses between November 2024 and August 2025). Each time, the industry treats it as a new 'hack' to be patched. In reality, it is a failure of the payment architecture to recognize the difference between a physical presence and a relayed one.

Until banks implement more rigorous, real-time behavioral analysis that can flag the impossibility of a user being in two places at once—or the absurdity of a loan being granted seconds after a suspicious app installation—the liability will continue to shift toward the consumer and the merchant. The malware is just the tool; the open door is the bank's authorization process.

Sources

More from Alicia Ferro