An investigation details how Chinese cybercrime groups are turning phished payment card data into new Apple or Google wallets for online and in-store use
https://krebsonsecurity.com/ ...
Context & Ripple Effects
This case extends an abuse path seen when Apple Pay made cards stolen online usable at retail, collapsing the old boundary between online card theft and in-store fraud. The upstream supply of credentials has also remained broad, including malicious Google Play apps that collected bank credentials.
It matters because the reported groups are connecting phishing-derived payment data to wallet provisioning, turning a stolen-data problem into a payment-acceptance problem across more transaction settings.
First-order effects
- Chinese cybercrime groups gain a way to monetize phished card data through newly provisioned Apple or Google wallets, including both online and in-store transactions.
- Apple and Google face more pressure to identify suspicious wallet creation and use, while affected cardholders face fraud that can extend beyond conventional online purchases.
Second-order effects
- The payoff for phishing and payment-data collection rises when stolen details can be converted into a wallet-based payment instrument; earlier payment-data scraping that bypassed site protections illustrates one adjacent source of such data.
- Wallet providers and the broader payments ecosystem will need controls that connect signals across phishing, card enrollment, and subsequent transaction activity, potentially adding friction for questionable provisioning attempts.
Third-order effects
- If this pattern persists, the practical distinction between card-not-present theft and card-present spending will weaken as digital wallets let compromised card data move between channels.
- The broader fraud-control challenge shifts from securing a single checkout or app to detecting the full credential-to-wallet lifecycle; how effectively platforms can do that remains uncertain.
The trend: Cybercrime is increasingly industrializing the conversion of stolen credentials into reusable, cross-channel digital payment access.