The 13-Minute Swipe: How ‘WindRelay’ Clones Your Contactless Card Remotely

Coffee Time with Tracer | Morning Coffee with Tracer | Friday, August 21, 2026

The rolling chair at FindASpy HQ sank again.

Tracer leaned sharply to one side, trying to keep the chair from tilting beneath him while reviewing the morning dispatch. A cold coffee sat dangerously close to the desk edge. Sticky notes covered the monitor stand. A smartphone, payment card, and security equipment waited nearby.

Then he read the headline.

Thirteen minutes.

That was the reported time it took scammers to move from a convincing bank-support phone call to malware installation, contactless card fraud, and a digital loan application.

Are you being targeted through your phone right now? Could a caller who sounds professional convince you to turn your own Android device into a relay terminal?

Let’s examine the threat and, more importantly, the steps you can take to stay one step ahead.

What Is WindRelay?

According to reporting on Group-IB’s August 2026 research, WindRelay is an Android malware family designed to support NFC relay fraud.

“NFC” is the short-range wireless technology used by contactless payment cards, smartphones, and payment terminals. Normally, the short distance between a card and a terminal is part of the security model.

A relay attack attempts to defeat that assumption.

Instead of using your card directly at a nearby store, criminals use malware and internet-connected devices to pass the live communication between your card and a payment terminal. Your card can remain in your hand while a criminal’s device is somewhere else.

The word “clone” can make this sound like a permanent duplicate has been created. In many relay attacks, the more accurate description is live transaction relaying. The criminal captures and forwards the payment exchange in real time, making a remote device appear to the terminal as if your card were physically present.

That distinction matters. It also makes the attack difficult to notice.

A smartphone, contactless card, payment terminal, and second phone arranged to explain a live NFC relay connection

How the 13-Minute Attack Unfolds

The reported WindRelay operation combines social engineering with two Android-based tools: a personalized remote-access trojan and NFC relay malware.

Here is the general sequence.

1. The bank-helpdesk call

The scam begins with a phone call.

The caller claims to represent your bank, card issuer, fraud department, or another trusted financial service. They may say that suspicious activity has been detected or that your card needs to be secured immediately.

The pressure is intentional.

A caller who keeps you worried and engaged has less time to investigate the story. The goal is to make every next instruction feel like a reasonable step in an emergency.

2. The personalized app installation

The victim is instructed to install an Android application. The app may be presented as a banking tool, security utility, identity-verification app, or customer-support program.

The reported campaign used a personalized label containing the victim’s name. That small detail can make a malicious app appear more legitimate.

But a personal name is not proof of authenticity.

The critical warning sign is the installation method. If someone calling you tells you to install an application from a link, a file, a messaging app, or an unofficial source, stop the conversation.

Do not install apps during an unsolicited bank call.

3. Remote access and excessive permissions

The malicious app may request Accessibility Services and other powerful permissions. Those permissions can allow an attacker to view screens, interact with applications, capture information, or control parts of the device.

The remote-access component can then help deploy additional malware, including the NFC relay tool.

This is why a seemingly simple “security app” can become a full device compromise.

4. The card tap

The victim is told to place a contactless payment card against their own Android phone.

That instruction should immediately end the call.

A legitimate bank representative should not ask you to tap your physical payment card against your phone for “verification.” The caller may also ask for a PIN or direct you through an authentication step. Never provide a PIN, password, one-time code, or banking approval to an unsolicited caller.

WindRelay is designed to use the phone’s NFC capability to capture the live card communication and send it to an attacker-controlled system.

5. Remote payment or loan activity

The captured exchange can then be relayed to another device near a payment terminal or ATM. From the terminal’s perspective, the transaction may look like an ordinary contactless interaction.

Group-IB’s reported case also involved unauthorized access to the victim’s banking application and the creation of a loan in the victim’s name.

The danger is not limited to one tap. Once a phone is compromised, criminals may attempt to access messages, banking applications, contact lists, stored information, and authentication prompts.

Why This Scam Works

WindRelay is not successful because NFC is new or because contactless cards are automatically unsafe.

It works because criminals combine three powerful tactics:

  • Authority: The caller claims to represent a bank or financial institution.
  • Urgency: The victim is told that immediate action is required.
  • Technical confusion: The victim is guided through unfamiliar app permissions, card taps, and security steps.

The attack compresses the victim’s decision-making window. Thirteen minutes is enough time for someone to make several choices they would normally question.

Your best defense is to slow the process down.

A real bank can wait while you independently verify the call.

Tracer’s Protection Checklist

1. Never install an app during an unsolicited call

Hang up. Do not click the link. Do not open the attachment. Do not allow the caller to guide you through Android settings.

If you need your bank’s application, open the official app store yourself or use the bank’s known website.

2. Verify through an official number

Call your bank using the number printed on your physical card or listed inside the official banking application.

Do not call back using a number sent by text message or supplied by the caller.

If the caller says your account is in immediate danger, that is even more reason to verify independently.

3. Never tap your card against your phone because someone tells you to

This is one of the clearest red flags in an NFC relay scheme.

A legitimate app may allow you to scan card information with a camera. That is different from placing your physical contactless card against the phone’s NFC reader at the direction of a stranger.

4. Keep NFC disabled when you are not using it

NIST recommends disabling NFC when the feature is not in use. On Android, review your NFC and contactless-payment settings regularly.

Check the default payment application. Remove anything unfamiliar. Your trusted mobile wallet should remain the default, and any suspicious application with payment or Accessibility permissions deserves immediate attention.

Android phone with NFC turned off beside a contactless card in a plain RFID-blocking sleeve and a security checklist

5. Review permissions and installed applications

Look for applications you do not recognize, especially those with:

  • Accessibility access
  • Notification access
  • SMS access
  • Device administrator privileges
  • NFC or payment permissions
  • Permission to appear over other applications

Do not simply hide a suspicious app. Treat it as a possible compromise.

6. Turn on transaction alerts

Enable push, text, or email alerts for card transactions and banking activity. Small unfamiliar charges can be an early warning.

If you see an unauthorized transaction, contact the bank immediately. Ask about blocking the card, replacing it, disabling contactless payments, and reviewing recent account activity.

If You Already Installed the App

Do not continue communicating with the caller.

Using another trusted device if possible, contact your bank through its official number. Report the suspected fraud and ask whether your accounts, cards, loans, and authentication methods need to be secured.

Then seek qualified device assistance. Removing an icon may not remove remote access or secondary malware. FindASpy provides spyware removal and digital recovery services, including support for suspected unauthorized access to phones, computers, and networks.

For broader privacy and security concerns, review the FindASpy product catalog or learn more about the team’s approach to protection through About Us.

Tracer examining a potentially compromised Android phone and contactless card on a professional security workbench inside the FindASpy van

Tracer’s Pick

The best defense against WindRelay is disciplined verification.

Keep NFC off when you do not need it. Use trusted payment applications. Install software only through official channels. Most importantly, never let an unsolicited caller rush you into handling your card, phone, PIN, or banking app.

Technology changes quickly. The core protection principles remain steady:

Awareness. Knowledge. Protection.

Disclaimer

This article is provided for general privacy, cybersecurity, and fraud-awareness education. It does not replace advice from your bank, card issuer, law enforcement agency, attorney, or a qualified security professional. Product availability, device settings, payment protections, and applicable laws vary. If you believe fraud is occurring, contact your financial institution immediately through an official channel. Do not attempt to investigate or confront suspected criminals yourself.

Community Conversation

Have you ever received a “bank security” call that asked you to install an app, share a code, or tap your card against your phone?

Which state are you reading from? Do you keep NFC enabled all the time, or do you switch it off when you are finished using it? What is the strangest instruction a supposed support representative has ever given you?

Tracer reads all posts. Your experience may help someone else recognize the warning signs before the pressure starts.

Have you found a hidden gadget or suspicious device of your own? Upload it and share the discovery with our community by clicking here.

Reader importance rating

How important was this article?

Your vote helps determine FindASpy Insider’s Readers’ Top Picks. One rating is allowed per reader for each article.

0 reader ratings

Share this article

COFFEE WITH TRACER COMMUNITY

Today’s Coffee Conversation

Tracer shares cybersecurity stories, scam alerts, privacy tips, and investigative insights. Pull up a chair, share your experience, and help shape tomorrow’s discussion.

Pull Up a Chair & Chat with Tracer

Community protection: Comments may be reviewed before appearing to keep the conversation respectful, helpful, and spam-free.

0Conversations
0Community Likes
0Tracer’s Picks