
If your bank says a card was added to Apple Pay without permission, treat it as possible account compromise or digital-wallet provisioning fraud—even if the card is still in your hand.
This guide explains how criminals can enroll it elsewhere, the warning signs to check, and what to do immediately.
Adding a payment card to a mobile wallet is called provisioning. Apple says the card issuer, or its authorized service provider, decides whether to approve a card for Apple Pay. The full card number is not stored on the device or Apple Pay servers; instead, the issuer creates a unique Device Account Number. Similarly, Google Wallet uses a device-specific token rather than exposing the physical card number during payments.
So, an unauthorized wallet entry does not automatically mean Apple Pay, Google Wallet or NFC was technically breached. The weak point can be the enrollment process: a criminal obtains the card details and defeats or manipulates the issuer's verification step. Apple allows cards to be entered manually using the card number, expiry date and CVV before issuer approval, while Google says verification can involve a bank-issued code, bank app or website, phone call, or another issuer-supported method.
Santander UK is warning that it has seen fraudulent Apple Pay and Google Pay setups. One documented pattern starts with a fake shopping site: the victim enters card and personal information, then receives a genuine one-time passcode. The victim thinks the code confirms the purchase, but it actually authorizes the criminal to register the card in their digital wallet.
A typical sequence is:
Read the full wording of every verification message. A code for adding a card to a digital wallet is not a code for confirming an ordinary purchase.

Treat an unexpected “card added to wallet” alert as serious, but verify it independently. Scam texts can also make up such an alert to trick you into calling a fake fraud department. Santander advises consumers to verify unexpected communications through trusted contact details rather than relying on the readout in the message or caller ID.
Other red flags include a wallet-verification code you didn’t request, a new-device or password-change alert, unfamiliar transactions, or a caller claiming to be your bank who asks for an OTP or approval prompt. Contact the bank through its official app, website or the number printed on your physical card.
Take action even if no fraudulent purchase has appeared. An unauthorized wallet token indicates that something in the enrollment chain may have been compromised.
Do not assume that deleting the card from your own phone solves a token provisioned on somebody else's device. Apple notes that removing a payment card from one device does not automatically remove it from other devices, while issuers can suspend wallet credentials. Contacting the issuer is therefore essential.
If the bank disputes whether the transactions were genuinely unauthorized, the distinction between authorized and unauthorized fraud may become important to the complaint and reimbursement process.

Never share or approve a verification code simply because a caller or website says it is needed to “secure” your account. Read the whole message and make sure it describes an action you personally initiated. Santander specifically recommends reading the full OTP message instead of relying on autofill or entering the code without checking its purpose.
Use transaction and security alerts from your bank, protect email and financial accounts with unique passwords, and verify unfamiliar merchants independently before entering card details. EMV contactless technology generates a one-time security code for each transaction, so this fraud pattern is usually about misusing card information or the wallet-enrollment process, not simply cloning an EMV chip through somebody's wallet.
Bitdefender Scamio can analyze suspicious messages, links, screenshots and QR codes before you act on them, which is useful when a supposed bank or merchant asks you to verify a card or follow an unexpected link.
Bitdefender Ultimate Security includes device security and Scam Protection Pro features to detect phishing, suspicious messages, scam websites and other deceptive online interactions. These protections can reduce exposure to methods used to steal card or account information, but they can’t reverse an unauthorized transaction or guarantee that wallet provisioning will be blocked.
If the incident suggests personal data or credentials were exposed, Bitdefender Digital Identity Protection can monitor for compromised personal information and breaches, while Bitdefender SecurePass can generate and store unique passwords using end-to-end encryption.
Bitdefender Security for Creators is a narrower fit, but it can be relevant when a creator's email, Instagram, Facebook or YouTube presence was part of the compromise. Current plans include anti-scam email protection and monitoring for suspicious activity on supported social accounts.
If you discover a card added to Apple Pay without permission, focus first on the issuer: freeze the card, report the unauthorized provisioning, revoke unrecognized wallet tokens and review transactions. Then secure the accounts that could have enabled the enrollment.
This is one variation of the broader problem of financial scams. Fast reporting matters, but so does explaining precisely that an unauthorized digital-wallet token was created, not merely that your card details may have been stolen.
Yes, in the sense that a device, account or connected credential can be compromised, but an unauthorized card in Apple Pay or Google Wallet doesn’t necessarily mean the wallet platform itself was hacked. Many incidents instead involve stolen card information and manipulation of the issuer's card-enrollment verification process.
They may not need your physical card. Card details stolen through phishing, fake checkout pages, compromised accounts or other fraud can be used for online transactions or to attempt mobile-wallet enrollment. Apple confirms that a card can be entered manually, although the issuer still decides whether the provisioning request is approved.
A fraudster can try to enroll someone else's card if they have the necessary information, but the card issuer controls approval and may require additional verification. Apple documents manual card entry and issuer verification as part of the provisioning process. Using another person's card without authorization is not legitimate and may constitute fraud under applicable law.
A contactless card can communicate with an NFC reader at close range, but a simple scan is not equivalent to cloning the card for future EMV transactions. EMV contactless payments generate a one-time security code for each transaction. Unauthorized wallet provisioning more commonly depends on obtaining usable card information and defeating or manipulating issuer verification.
tags
Vlad's love for technology and writing created rich soil for his interest in cybersecurity to sprout into a full-on passion. Before becoming a Security Analyst, he covered tech and security topics.
View all posts