• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

Here’s why fraudsters love Apple Pay

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
March 6, 2015, 11:29 AM ET
Courtesy of Apple

Apple’s (AAPL) mobile payment system Apple Pay has been hit by a wave of fraudulent transactions by fraudsters using stolen credit card information from a series of big data breaches at retailers, according to The Wall Street Journal.

The transactions came from breaches at retail giants such as Home Depot (HD) and Target (TGT), the Journal said. These scammers are using stolen credit card information to create unauthorized Apple Pay accounts, and they’re using them, ironically, to make big purchases at Apple stores, reports The Guardian. They then resell the items for cash. (Apple did not respond to a request for comment.)

Although the identity swindlers have not, it seems, broken the security and strong encryption protecting Apple’s transaction technology, which has quickly become one of the most popular forms of mobile payment with more than two million Americans using it, they are taking advantage of weaknesses in the authentication schemes employed by participating banks. In other words, when checking to make sure a new Apple Pay registree is who she says she is, some banks are getting duped.

Here’s how it’s done. Typically, when a user begins to create an account — by snapping a picture of a card, or entering information by hand — that data is encrypted and sent to Apple’s servers “along with other information about your iTunes account activity and device (such as the name of your device, its current location, or if you have a long history of transactions within iTunes),” as Apple’s security and privacy overview states. That data, in turn, is decrypted, checked, re-encrypted and passed to banks to verify a cardholder’s identity. This is the so-called green path authentication protocol, and it seems to work fine.

The “yellow path” is where things get problematic. In this alternate process, some banks perform backup checks that have loopholes. For instance, they will ask a user to confirm his or her identity via e-mail, text message or phone call, and scammers have had an easier time circumventing some of these security measures. Sometimes, for example, a bank’s call center may ask for the last four digits of a user’s social security number — a popular target in identity theft schemes — and if they have the right information, potentially obtained in one of the many recent data breaches, or purchased in underground markets where such information is sold, the fraudster is set.
[fortune-brightcove videoid=4080084565001]

Since Apple Pay precludes the use of a physical card, scammers don’t have to bother forging a plastic copy with a magnetic stripe (or EMV chip, for that matter). According to the Guardian, banks have already lost millions in such ID fraud.

Apple, reached for comment by the newspaper, seems to be passing the blame on to its banking partners:

“Apple Pay is designed to be extremely secure and protect a user’s personal information,” a spokesman told the Guardian. “During setup Apple Pay requires banks to verify each and every card and the bank then determines and approves whether a card can be added to Apple Pay. Banks are always reviewing and improving their approval process, which varies by bank.”

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

Electrician apprentices at work.
Future of WorkCareers
A dire electrician shortage is a ‘life-or-death’ threat to the AI data center boom—and an opportunity for Gen Z
By Preston ForeMarch 2, 2026
2 hours ago
A veiled Iranian woman holds her cellphone displaying a portrait of Iran's Supreme Leader, Ayatollah Ali Khamenei,
CybersecuritySecurity
Cyber retaliation from Iran is a problem for U.S. companies — ‘It’s in the hands of a 19-year-old hacker in a Telegram room,’ ex-NSA operative says
By Amanda GerutMarch 1, 2026
12 hours ago
Two girls look at a white laptop placed on a desk.
AIEducation
American schools weren’t broken until Silicon Valley used a lie to convince them they were—now reading and math scores are plummeting
By Sasha RogelbergMarch 1, 2026
14 hours ago
Big TechSocial Media
YouTube’s cofounder and former tech boss doesn’t want his kids to watch short videos, warning short-form content ‘equates to shorter attention spans’
By Marco Quiroz-GutierrezMarch 1, 2026
18 hours ago
Slack cofounder Stewart Butterfield
SuccessProductivity
Slack cofounder says workers and CEOs can get stuck doing ‘fake’ work like pre-meetings and slide shows
By Emma BurleighMarch 1, 2026
18 hours ago
heitmann
CommentaryEntrepreneurship
Here’s how to build something that lasts, from the founder of a $300 million bootstrapped company that’s been growing for 28 years straight
By Tim HeitmannMarch 1, 2026
1 day ago

Most Popular

placeholder alt text
Economy
Your grandparents are the reason the U.S. isn't in a recession right now. That won't last forever
By Eleanor PringleMarch 1, 2026
1 day ago
placeholder alt text
Success
MacKenzie Scott's close relationship with Toni Morrison long before Amazon put her on the path give more than $1 billion to HBCUs
By Sasha RogelbergMarch 1, 2026
18 hours ago
placeholder alt text
Middle East
As Iran attacks Dubai, the tax-free haven for the global elite could see 'catastrophic' fallout — 'this can also send shockwaves globally'
By Jason MaMarch 1, 2026
16 hours ago
placeholder alt text
Personal Finance
Trump's universal 401(k) architect on why lower-income people distrust retirement accounts: 'they want to know what the catch is'
By Jacqueline MunisFebruary 28, 2026
2 days ago
placeholder alt text
Health
Gen Z men are eating ‘boy kibble,’ the human equivalent to dog food, to load up on protein cheaply
By Jake AngeloMarch 1, 2026
21 hours ago
placeholder alt text
Middle East
U.S. military gives Iran a taste of its own medicine with cheap copycat Shahed drones, while concern shifts to munitions supply in extended conflict
By Jason MaMarch 1, 2026
14 hours ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.