The NYC subway's OMNY contactless payments system has a privacy issue that lets anyone view a rider's seven-day trip history using just credit card details
In the mid-afternoon one Saturday earlier this month, the target got on the New York subway. I knew what station they entered the subway at and at what specific time.
404 MediaJoseph Cox
Context & Ripple Effects
OMNY extends a contactless-payment modernization path that included the subway's rollout of Apple Pay support. The reported lookup weakness shows that the convenience layer can also become a record of where and when a payment credential was used.
The disclosure lands shortly after the MTA's use of AI surveillance to pursue fare evasion was reported. Together, the coverage highlights how payment and surveillance systems can create separate, potentially complementary sources of rider movement data.
First-order effects
Riders whose card details are available to another person can have their recent subway entries and times exposed through OMNY's trip-history lookup.
OMNY's payment credential becomes a practical locator for a seven-day window, rather than functioning only as a fare-payment token.
Second-order effects
The finding puts pressure on the MTA and OMNY's payment-system operators to tighten who can retrieve trip records and how card details are used for verification.
Riders may reassess contactless fare payment where the same credential can connect transactions to granular travel history, raising the privacy cost of a faster payment flow.
Third-order effects
If such designs persist, transit payment systems may increasingly function as mobility-identity infrastructure, creating tracking exposure without the need for dedicated location apps or cameras.
The combination of transaction logs and transit surveillance increases the importance of access controls and data-minimization rules; whether agencies adopt those safeguards will determine how broadly this pattern spreads.
The trend: Contactless transit payments are turning payment credentials into durable mobility identifiers, bringing consumer-finance privacy concerns into public infrastructure.
Here is what that looks like. Precise timestamps of when people get on the subway, and at what station. It is very easy to imagine a stalker seeing what time someone visits a station each morning on the way to or from work. This is perfect for abusers https://www.404media.co/... …
You can track anyone's movements on the NYC subway if you have their credit card number. Easily open to abuse. Somehow works with Apple Pay, too. MTA calls it a “feature” https://www.404media.co/...
This was all possible because of OMNY's “Check trip history” feature. On the main site, you have to enter the details shown here. But there is no auth beyond that. No PIN, anything. As EFF told me, “Credit card info is not a goddamn unique identifier.” https://www.404media.co/...…
New: I tracked the precise movements of an NYC subway rider. Saw what specific time they got on and at what station. It became obvious which station was nearest to their home. This was all because of a ‘feature’ on the MTA website Wide open to abuse https://www.404media.co/...
Very interestingly, I found this tracking feature still works with Apple Pay. For one of the tests, I had a rider take trips and pay with Apple Pay. This means MTA should not learn the rider's card info. But when I entered into MTA site, I got trip history https://www.404media.co…
“Obviously this is a great fit for abusers who live with their victims or have physical access, however brief, to their wallets,” EFF's @Evacide told @404mediaco. “Credit card info is not a goddamn unique identifier.” https://www.404media.co/...
I exclusively use Apple Pay for OMNY and I was under the impression that AP transactions were encrypted, but when I put my CC number into the MTA OMNY website all my recent transactions come up https://www.404media.co/...