• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

AI CEOs from OpenAI, Anthropic, and Microsoft set aside their rivalry to warn Congress AI is making it too easy to design and create bioweapons

2

Social Security faces a 24% cut in 2032—that's a $345 billion hit to retirees nationwide, watchdog says

3

MacKenzie Scott's approach to her $26 billion giving spree was inspired by a book she read in college about writing

1

AI CEOs from OpenAI, Anthropic, and Microsoft set aside their rivalry to warn Congress AI is making it too easy to design and create bioweapons

2

Social Security faces a 24% cut in 2032—that's a $345 billion hit to retirees nationwide, watchdog says

3

MacKenzie Scott's approach to her $26 billion giving spree was inspired by a book she read in college about writing
TechApple

Mules, banks and Apple Pay

By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
By
Philip Elmer-DeWitt
Philip Elmer-DeWitt
Down Arrow Button Icon
March 3, 2015, 11:00 AM ET
Courtesy of Apple

The elaborate con described by Charles Arthur in Monday’s The Guardian — Apple Pay: A new frontier for scammers — may be the most Apple-centric fraud yet.

Organized crime rings, he reports, are using stolen social security numbers to buy the latest iPhones, “provisioning” them with stolen credit cards, and distributing them to low-level couriers (“mules”) who use the new Apple Pay system accepted at all Apple Stores to buy pricy Apple products that can be quickly resold.

Arthur is careful to point out that the crooks have not broken Apple Pay’s fingerprint-activated wireless payment mechanism. Rather, they have exploited lax security at banks and other financial institutions that issue credit cards

“The soft underbelly [in Apple Pay] proved to be provisioning of cards,” writes Cherian Abraham, a mobile-payments specialist, on his Drop Labs blog.

Abraham’s Feb. 22 post — Rampant: Explaining the current state of Apple Pay fraud — was The Guardian’s main source for Monday’s story, and it’s got some critical details about how Apple interacts with credit card issuers that I hadn’t seen before.

It seems Apple Pay sends requests to authorize a credit card down one of two paths: green or yellow, depending.

Green is for recognized customers with a long history. Not much fraud happening there, according to Abraham.

Requests get kicked to the yellow path if:

  • The Apple ID and card were paired past a specific date threshold
  • The Apple account was recently modified
  • The Apple account has not had any activity for over a year
  • The Apple ID is too new, relative to the Apple Pay launch and to the provisioning request.

.

Some yellow path requests go to the banks’ own apps, which aren’t easy to fool. Others get sent to call centers staffed by notoriously easy targets. As Abraham puts it: “Fraudsters are better at social engineering than call center reps are at sniffing out fraud.”

Abraham faults Apple for not pushing banks harder to shore up their yellow path procedures, as apparently they were advised to do.

And he sees more trouble ahead, as mobile payment systems proliferate.

“Remember folks,” he writes. “Fraud scales. Call centers do not.”

See also: The iPhone, the carriers and the credit mules

Follow Philip Elmer-DeWitt on Twitter at @philiped. Read his Apple AAPL coverage at fortune.com/ped or subscribe via his RSS feed.

About the Author
By Philip Elmer-DeWitt
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

SpaceX and other mega IPOs may wait years to join the S&P 500
InvestingS&P 500
SpaceX and other mega IPOs may wait years to join the S&P 500
By Bailey Lipschultz, Vildana Hajric and BloombergJune 6, 2026
1 hour ago
Former AI czar calls Sanders’ proposal for government equity a ‘stupidity tax’ and warns against nationalization as Trump mulls public stakes
AIregulation
Former AI czar calls Sanders’ proposal for government equity a ‘stupidity tax’ and warns against nationalization as Trump mulls public stakes
By Jason MaJune 6, 2026
2 hours ago
Marvell Technology, Flex to join S&P 500 later this month
InvestingS&P 500
Marvell Technology, Flex to join S&P 500 later this month
By Isabelle Lee and BloombergJune 6, 2026
6 hours ago
bernie
AIWhite House
Bernie Sanders and Sam Altman’s private one-hour meeting about the public ownership of AI
By Joey Cappelletti, Seung Min Kim and The Associated PressJune 6, 2026
7 hours ago
Chinese humanoid robots dominate the market with thousands shipped a year. But most are still performative rather than functional
InnovationRobots
Chinese humanoid robots dominate the market with thousands shipped a year. But most are still performative rather than functional
By Chan Ho-Him and The Associated PressJune 6, 2026
8 hours ago
sa
CommentaryIPOs
When good money goes bad: the question SpaceX and OpenAI investors aren’t asking
By Rory McDonaldJune 6, 2026
11 hours ago

Most Popular

AI CEOs from OpenAI, Anthropic, and Microsoft set aside their rivalry to warn Congress AI is making it too easy to design and create bioweapons
AI
AI CEOs from OpenAI, Anthropic, and Microsoft set aside their rivalry to warn Congress AI is making it too easy to design and create bioweapons
By Marco Quiroz-GutierrezJune 5, 2026
2 days ago
Social Security faces a 24% cut in 2032—that's a $345 billion hit to retirees nationwide, watchdog says
Economy
Social Security faces a 24% cut in 2032—that's a $345 billion hit to retirees nationwide, watchdog says
By Nick LichtenbergJune 5, 2026
2 days ago
MacKenzie Scott's approach to her $26 billion giving spree was inspired by a book she read in college about writing
Success
MacKenzie Scott's approach to her $26 billion giving spree was inspired by a book she read in college about writing
By Sydney LakeJune 5, 2026
2 days ago
Billionaires Elon Musk and Mark Zuckerberg used mortgages to buy multimillion-dollar mansions. Here’s why that’s a savvy financial decision
Real Estate
Billionaires Elon Musk and Mark Zuckerberg used mortgages to buy multimillion-dollar mansions. Here’s why that’s a savvy financial decision
By Sydney LakeJune 6, 2026
11 hours ago
Current price of oil as of June 5, 2026
Personal Finance
Current price of oil as of June 5, 2026
By Joseph HostetlerJune 5, 2026
1 day ago
Ohio city workers are covering automated license plate readers with trash bags as officials sound the alarm on 'egregious violations' of privacy
Cybersecurity
Ohio city workers are covering automated license plate readers with trash bags as officials sound the alarm on 'egregious violations' of privacy
By Sasha RogelbergJune 3, 2026
3 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.