{"id":85,"date":"2026-08-15T10:32:48","date_gmt":"2026-08-15T10:32:48","guid":{"rendered":"https:\/\/tapcontact.ai\/blog\/are-nfc-cards-secure\/"},"modified":"2026-08-15T10:32:48","modified_gmt":"2026-08-15T10:32:48","slug":"are-nfc-cards-secure","status":"publish","type":"post","link":"https:\/\/tapcontact.ai\/blog\/are-nfc-cards-secure\/","title":{"rendered":"Are NFC cards secure? What the research actually says"},"content":{"rendered":"<p>&#8220;NFC? That&#8217;s not secure.&#8221; It&#8217;s probably the most common objection we hear \u2014 and it comes from somewhere real: headlines about contactless payment fraud. The prejudice deserves a serious answer, not a salesman&#8217;s shrug. So we went to the studies. The short conclusion: <strong>the documented NFC attacks target payments and access cards \u2014 things with money or doors on the other side. An NFC business card has neither.<\/strong> The risk that remains is a different one, it is small, and it is mitigated by design. Let&#8217;s go step by step.<\/p>\n<h2>What researchers actually attack<\/h2>\n<p>NFC security research concentrates on two targets, and it&#8217;s worth seeing why.<\/p>\n<p><strong>Relay attacks on payments.<\/strong> The <a href=\"https:\/\/arxiv.org\/pdf\/2001.08143\" rel=\"noopener\" target=\"_blank\">ReCoil study (arXiv, 2020)<\/a> showed that, with carefully built passive coils, the read range of a <em>payment<\/em> card can be extended from the nominal ~5 cm to about 49 cm \u2014 enough to &#8220;brush against&#8221; someone&#8217;s pocket in a queue. The target is the bank card&#8217;s authentication protocol, because there is money on the other side.<\/p>\n<p><strong>Malware that relays through the phone.<\/strong> In 2024, <a href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/ngate-android-malware-relays-nfc-traffic-to-steal-cash\/\" rel=\"noopener\" target=\"_blank\">ESET documented NGate<\/a>, Android malware that relays the victim&#8217;s bank card NFC traffic to the attacker&#8217;s phone next to an ATM. Note what the attack requires: the victim has to be phished into <em>installing a malicious app<\/em>, entering bank credentials and tapping their own payment card against the infected phone. It&#8217;s sophisticated social engineering against <em>payments<\/em> \u2014 not a weakness of the chip.<\/p>\n<p>As for the classic man-in-the-middle, the <a href=\"https:\/\/www.ecma-international.org\/wp-content\/uploads\/NFC-SEC-whitepaper.pdf\" rel=\"noopener\" target=\"_blank\">NFC-SEC whitepaper by Ecma International<\/a> \u2014 the standards body \u2014 rates the practical risk as low in typical use cases, precisely because of NFC&#8217;s very short operating distance and radio characteristics.<\/p>\n<h2>Why none of this applies to your business card<\/h2>\n<p>An NFC business card is a <strong>passive tag<\/strong>: no battery, no processor running code, no secrets inside. It stores exactly one thing \u2014 a public link. The same link that&#8217;s in your email signature, on your LinkedIn and on the back of any paper card with a QR code.<\/p>\n<p>No relay attack is possible because there is no transaction to relay. There is no &#8220;cloning&#8221; worth anything because the content is public by definition \u2014 cloning your business card gets you&#8230; your business card, which is its purpose. And reading the tag requires physical proximity of centimetres: nobody &#8220;sniffs&#8221; your card from across the room. <a href=\"\/en\/blog\/nfc-business-cards-how-they-work\/\">We explained the physics of the tap here<\/a>.<\/p>\n<h2>The risk that DOES exist \u2014 and how design kills it<\/h2>\n<p>Let&#8217;s be honest: there is one real vector, documented in a <a href=\"https:\/\/securitymea.com\/2025\/01\/02\/kaspersky-warns-smartphone-users-about-malicious-nfc-tags\/\" rel=\"noopener\" target=\"_blank\">Kaspersky advisory on malicious tags<\/a> \u2014 aimed mostly at tags in public spaces (posters, caf\u00e9 tables): an <em>unlocked<\/em> tag can be rewritten to point at a phishing site, or physically swapped for another. It&#8217;s the NFC equivalent of sticking a fake QR sticker over a real one.<\/p>\n<p>The mitigations are well known \u2014 Kaspersky recommends them and we build with them:<\/p>\n<ul>\n<li><strong>Locked (read-only) tags.<\/strong> Our chips are written and then locked: third-party rewriting is physically disabled. It&#8217;s the number-one recommendation for organizations, and it&#8217;s our factory default, not an extra.<\/li>\n<li><strong>Own domain, always visible.<\/strong> The tap opens the browser with the URL in plain sight \u2014 the same check you give any link. A tapcontact page lives on a recognizable HTTPS domain, not behind an anonymous shortener.<\/li>\n<li><strong>The page executes nothing.<\/strong> Our contact pages are <a href=\"\/en\/privacy\/\">static HTML with zero JavaScript<\/a> \u2014 no code runs on the phone of whoever taps, so there is no surface for &#8220;payloads&#8221;. The vCard downloads through iOS&#8217;s and Android&#8217;s native mechanism, no app.<\/li>\n<li><strong>No permission requests.<\/strong> Tapping a card never asks for an install, contact access or credentials. If a tag ever asks you for those, that is exactly the alarm signal Kaspersky describes \u2014 on another platform.<\/li>\n<\/ul>\n<h2>The comparison nobody makes: what about paper?<\/h2>\n<p>The paper card has always been &#8220;forgeable&#8221; too \u2014 any print shop will print a card with your name and a wrong number. We never treated that as a security crisis because the social context of the handshake validates the exchange. The NFC card inherits that validation and adds something paper doesn&#8217;t have: a verifiable destination, on an HTTPS domain, controlled by your organization \u2014 which can <a href=\"\/en\/blog\/employee-offboarding-contacts\/\">revoke or forward it<\/a> when it should no longer speak for it.<\/p>\n<h2>A security checklist for anyone buying NFC cards<\/h2>\n<p>Take these questions to any vendor, including us: do the tags ship locked from the factory? Does the URL open on an own domain with HTTPS, visible to whoever taps? Does the page run JavaScript or ask for permissions? What data about the people who tap is stored \u2014 and where? The right answers are: yes, yes, no, and <a href=\"\/en\/privacy\/\">almost none, in the EU<\/a>.<\/p>\n<p><em>Still have a concrete security question? <a href=\"\/en\/contact\/\">Write to us<\/a> \u2014 a person who knows what an NDEF tag is will answer, not a chatbot.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Relay attacks, NGate malware, malicious tags: what security research has actually demonstrated, why it targets payments rather than business cards, and the mitigations we apply by design.<\/p>\n","protected":false},"author":0,"featured_media":36,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[6],"tags":[],"class_list":["post-85","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-seguranca"],"acf":[],"_links":{"self":[{"href":"https:\/\/tapcontact.ai\/wp-json\/wp\/v2\/posts\/85","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tapcontact.ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tapcontact.ai\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/tapcontact.ai\/wp-json\/wp\/v2\/comments?post=85"}],"version-history":[{"count":0,"href":"https:\/\/tapcontact.ai\/wp-json\/wp\/v2\/posts\/85\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tapcontact.ai\/wp-json\/wp\/v2\/media\/36"}],"wp:attachment":[{"href":"https:\/\/tapcontact.ai\/wp-json\/wp\/v2\/media?parent=85"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tapcontact.ai\/wp-json\/wp\/v2\/categories?post=85"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tapcontact.ai\/wp-json\/wp\/v2\/tags?post=85"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}