الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Smartphone users should be aware of the threats posed by malicious NFC tags

MOSCOW, RUSSIA - FEBRUARY 1, 2017: A view of the Kaspersky Lab headquarters. Kaspersky Lab is a Russian cybersecurity and anti-virus provider founded in 1997 by Eugene Kaspersky, its current CEO. Vyacherslav Prokofyev/TASS (Photo by Vyacheslav ProkofyevTASS via Getty Images)

The festive shopping season is just over. Whereas once cash was king, now more shoppers than ever use their mobile phone’s electronic wallet as a contactless payment system when buying items, replacing credit cards or electronic ticket smart cards.

Smartphones increasingly rely on Near Field Communication (NFC) technology for convenience and connectivity, but cybersecurity experts warn about a rising threat: NFC tag tampering. This tactic, often overlooked, can expose users to phishing attacks, malware, and data theft with a simple tap of their phone.

“NFC technology is incredibly convenient, but it’s also a vector for malicious activity if users aren’t cautious,” warns Marc Rivero, Lead Security Researcher at Kaspersky. “Innocent-looking tags in public spaces can be reprogrammed or replaced to carry out harmful actions. As the adoption of NFC continues to grow in areas like payments, public transport, and marketing, we anticipate that malicious actors will become increasingly sophisticated in their tactics. In the next few years, NFC-related attacks could potentially target thousands of users globally, particularly in urban areas where NFC usage is widespread. Awareness and proactive measures are key to mitigating these risks.”

How NFC tag tampering works

NFC tags are widely used in marketing campaigns, public transport systems, and smart home setups to enable quick, touch-free interactions. However, this same convenience makes them susceptible to tampering by malicious actors.

One method involves reprogramming legitimate NFC tags. These tags, when left unlocked, can be altered to redirect users to phishing sites, initiate unintended actions on their devices, or even deliver harmful software payloads. Another method is the physical replacement of original NFC tags. For example, attackers might swap out a genuine tag on a public poster or kiosk, in high-traffic areas like transportation hubs, cafes, or retail stores, with one that triggers harmful behaviors.

The dangers of malicious NFC tags

The consequences of interacting with a malicious NFC tag can be severe. Phishing attacks are among the most common outcomes, where users are redirected to fraudulent websites designed to steal personal information or login credentials. It’s possible that vulnerabilities in a smartphone’s NFC reader can be exploited to execute harmful code, compromising the device’s security. Malicious NFC tags can also prompt users to download apps or files containing malware, which may steal data, track activity, or damage the device. The seemingly small act of scanning a tampered NFC tag can thus lead to significant financial and privacy repercussions.

Protect yourself against NFC tag tampering

To stay safe, users are encouraged to adopt these simple but effective measures:

  1. Inspect NFC tags. Avoid scanning tags in untrusted or suspicious locations and look for signs of tampering.
  2. Verify actions. Always carefully explore the URL or action triggered by a tag before proceeding.
  3. Disable automatic actions. Configure your smartphone to require confirmation before executing NFC-related commands. Install a reliable security solution on the device to reduce the risks.
  4. Stay updated. Ensure your smartphone’s software is up to date to protect against known vulnerabilities.

Advice for businesses

Organizations using NFC technology should take proactive steps to secure their systems and protect their users:

  • Use locked or “read-only” NFC tags to prevent tampering.
  • Regularly inspect their tags in public spaces for alterations.
  • Educate customers and employees about safe NFC practices.

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection, specialized security products and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help over 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

 

 

 

Related Posts

AD Ports Group Closes 2024 with Strong Growth, Solidifying its Position as a Leading, Integrated Trade and Logistics Group

AIM Global Manufacturing Awards 2025: Honoring Excellence in Innovation, Sustainability, and Global Reach

FUTURE SPORTS STARS START THE JOURNEY TO THE GAMES OF THE FUTURE

EFG Hermes Concludes Advisory on Badr University’s EGP 500 MillionFuture Cash Flow Securitization

Kaspersky warns local businesses of active Docusign-themed phishing scams

HUAWEI AppGallery and Emirates Esports Federation join forces to shape the future of esports and gaming in the UAE and Middle East & Africa region

لكزس توقع اتفاقية تعاون مع أكاديمية NABA  للفنون الجميلة في إيطاليا 

EFG Hermes Concludes Advisory on Premium’sNinthSecuritization Issuance Worth EGP 400Million

آخر الأخبار
جهاز حماية المستهلك يكشف حقيقة إعادة تعبئة زيت طعام متداول بالأسواق زلزال بقوة 2.7 درجة يضرب الضفة الغربية فى فلسطين وزيرا الاتصالات والخارجية يدشنان طوابع بريدية بمناسبة مرور أكثر من قرن على الدبلوماسية المصرية الأرصاد: توقعات بسقوط أمطار خفيفة على القاهرة غدا قرار جمهورى بإنشاء جامعة خاصة باسم جامعة الجيزة الجديدة نقيب الفلاحين: إرتفاع اسعار الاعلاف يهدد الثروة الحيوانية مى فاروق.. تطرح أحدث أغنياتها.. "باركوا" الجوريزا تعقد الملتقى السنوي الثاني لاستعراض إنجازاتها وتعزيز رؤيتها المستقبلية جائزة ساويرس الثقافية تكشف عن برنامج حفل دورتها العشرين «مصرف أبو ظبي الإسلامي- مصر» يفتتح الفرع الـ 72 داخل "مول مصر" بالإنفوجراف.. الشباب والرياضة تصدر حصادها الأسبوعي لأهم أنشطة وبرامج وفعاليات الوزارة «آي صاغة»: بيانات سوق العمل تحدد توجهات سياسة الفيدرالي الأمريكي وتحركات الذهب "البروچ مصر" تلبي تطلعات عملائها وتستعد لتسليم 100 ألف متر تجاري وإداري بمشروعيها 6ixty walk one و... وزير الدفاع يتفقد قاعدة الإسكندرية البحرية ويلتقى بعدد من المقاتلين "الشربيني" يوجه بوضع خطة عاجلة لسرعة الانتهاء من الطرق والمحاور بالمدينة ووقفة جادة مع الشركات المنف... وزيرة التضامن الاجتماعي تزور البابا تواضروس الثانى للتهنئة بعيد الميلاد المجيد وزير التربية والتعليم يعقد لقاءً موسعًا مع رؤساء لجان امتحانات الشهادة الإعدادية على مستوى الجمهورية أحمد بدير يشيع جثمان شقيقته والدفن فى الدويقة الزمالك بالزي الأسود في مواجهة المصري بالكونفدرالية وزير قطاع الأعمال يجتمع برؤساء شركات القابضة للسياحة والفنادق لمتابعة مؤشرات الأداء وموقف المشروعات