Apple Pay enables hackers to use credit cards stolen online in retail stores, which were previously only useful for online fraud
Apple Pay: Bridging Online and Big Box Fraud — Lost amid the media firestorm these past few weeks about fraudsters turning to Apple Pay is this stark …
Context & Ripple Effects
Krebs on Security is reporting that Apple Pay has collapsed a long-standing boundary in card fraud: payment cards stolen online, once useful only for card-not-present attacks, can now be spent at physical retail terminals. The related coverage frames where the weakness actually sits — an earlier investigation found the fraud wave traces to loopholes in banks' verification procedures during wallet provisioning, not any breach of Apple's encryption.
The pattern has proven durable rather than episodic: a decade later, investigators documented [[a:882799|Chinese cybercrime groups industrially converting phished card data into new Apple and Google wallets]] for both online and in-store use, and researchers separately showed a locked iPhone could push a Visa payment through Apple Pay in Express Transit mode. This article is the earliest marker of that arc.
First-order effects
- Card-issuing banks immediately absorb the losses: stolen-card fraud that used to hit their online-fraud models now arrives as in-store transactions, where chargeback liability and detection heuristics differ.
- Brick-and-mortar retailers face counterfeit-present fraud they had largely priced out, since the wallet's device-level legitimacy masks a stolen card number behind it.
Second-order effects
- Banks respond by tightening the identity checks used when a card is provisioned into a mobile wallet — exactly the verification gap the earlier reporting identified — shifting friction back onto legitimate customers at enrollment.
- Apple and Google come under issuer and network pressure to strengthen wallet-onboarding authentication, since their platforms are now the conversion mechanism between stolen data and usable spending power.
Third-order effects
- If the pattern holds, the industry's core risk model — separate controls and liability regimes for card-not-present versus point-of-sale fraud — erodes, because tokenized wallets make every channel presentment from the same stolen credential.
- That structural blur pushes regulators and card networks toward treating wallet provisioning as the critical control point, making identity verification at enrollment a compliance question rather than a per-bank choice.
The trend: Mobile wallets are dissolving the historical split between online and in-store card fraud, relocating the security battleground from transaction channels to how identities are verified when a card enters a wallet.