Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      Strait of Hormuz closed over ceasefire violations, says Iran

      Aerial view of ships navigating the strategic Strait of Hormuz, highlighting its importance to global maritime trade routes

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Platitudes in women’s sport are empty, patronising and offensive

      Business professionals in a conference room discussing strategy with a presentation screen displaying key market trends.

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      Fogo de Chao nominated for Best Casual Dining Toast award

      Fogo de Chão restaurant exterior with vibrant signage and bustling entrance at popular city location

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Thursday 30 September 2021 8:33 am  |  Updated:  Saturday 30 October 2021 3:09 pm

iPhone users urged to remove Visa from Apple Pay due to dangerous contactless payments flaw

By: Michiel Willems

Add as a preferred source on Google
Apple Pay Launches in the UAE
The issue could be exploited to make transactions from an iPhone inside someone’s bag, without their knowledge, experts from the University of Birmingham and the University of Surrey warned today.

Visa as a transport card via Apple Pay should be removed urgently by iPhone users after researchers said they uncovered a flaw that lets fraudsters bypass security and make unlimited contactless payments.

The issue could be exploited to make transactions from an iPhone inside someone’s bag, without their knowledge, experts from the University of Birmingham and the University of Surrey warned today.

They claim the vulnerability only happens on Apple Pay when a Visa card is set up as an Express Travel Card, also known as Express Transit mode., a feature intended for owners to tap in and out of public transport without needing to unlock their phone.

Using simple radio equipment, the team were able to trick the iPhone into thinking it was communicating with a transit gate when it was actually a payment reader used by shops, known among cyber experts as a “man-in-the-middle” attack.

This was done by identifying a unique code broadcast by transit gates or turnstiles, which was then used to interfere with the signals between the iPhone and a shop card reader.

“iPhone owners should check if they have a Visa card set up for transit payments and if so they should disable it,” said Dr Tom Chothia, co-author of the study, from the University of Birmingham.

“There is no need for Apple Pay users to be in danger, but until Apple or Visa fix this, they are.”

Back-end fraud detection checks were also unable to stop any payments going through in tests carried out by the group.

Researchers said they shared details of the problem with Apple and Visa, claiming both companies acknowledged the seriousness of the vulnerability but have not come to an agreement on who should implement a fix.

Response from Visa

Visa responded by saying its cards are secure with the feature, and that cardholders should continue to use them “with confidence”.

“Variations of contactless fraud schemes have been studied in laboratory settings for more than a decade and have proven to be impractical to execute at scale in the real world,” a spokeswoman said.

Read more

City watchdog probes Mastercard, Visa, Paypal for alleged anti-competitive conduct

Mastercard logo prominently displayed on a sleek office building, symbolizing global financial services and innovation.

“Visa takes all security threats very seriously, and we work tirelessly to strengthen payment security across the ecosystem.”

Response from Apple

An Apple spokesperson said: “We take any threat to users’ security very seriously. This is a concern with a Visa system but Visa does not believe this kind of fraud is likely to take place in the real world given the multiple layers of security in place.

“In the unlikely event that an unauthorised payment does occur, Visa has made it clear that their cardholders are protected by Visa’s zero liability policy.”

“Our work shows a clear example of a feature, meant to incrementally make life easier, backfiring and negatively impacting security, with potentially serious financial consequences for users,” said University of Birmingham’s Dr Andreea Radu, who led the study.

“Our discussions with Apple and Visa revealed that when two industry parties each have partial blame, neither are willing to accept responsibility and implement a fix, leaving users vulnerable indefinitely.”

The weakness does not affect other combinations, such as Mastercard in iPhones or Visa on Samsung Pay.

Full results of the study will be presented in a paper at the 2022 IEEE Symposium on Security and Privacy.

Co-author Dr Ioana Boureanu, from the University of Surrey, added: “We show how a usability feature in contactless mobile payments can lower security.

“But, we also uncovered contactless mobile-payment designs, such as Samsung Pay, which is both usable and secure.

“Apple Pay users should not have to trade-off security for usability, but at the moment some of them do.”

Read more

Top-rated casino apps displayed on a smartphone screen, highlighting user-friendly interfaces and popular gaming options

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business

Related Topics

  • Apple

Trending Articles

  • As it happened: Stocks sink after Fed and Bank of England opt for hawkish hold; Oil price tumbles

  • FTSE 100 Live: Pound dips and stocks slip as Andy Burnham victory triggers political uncertainty

  • City investors raise alarm on Burnham’s Chancellor pick

  • Inheritance tax enquiries surge to six-year high after HMRC clampdown

  • More Big Four blues as Deloitte plans to slash UK audit roles

More from CityAM

  • City watchdog probes Mastercard, Visa, Paypal for alleged anti-competitive conduct

    Regulation
    Mastercard logo prominently displayed on a sleek office building, symbolizing global financial services and innovation.
  • Casino
    Top-rated casino apps displayed on a smartphone screen, highlighting user-friendly interfaces and popular gaming options
  • Visa data leak piles pressure on Britain’s digital ID push

    Tech
    UK work and study visas have fallen as Labour faces pressure to reduce immigration.
  • Casino
    Online casinos offering low deposit options with various games displayed on a digital interface, suitable for budget players.
  • Casino
    Best Payout Online Casino UK
  • Betfair Sportsbook Offer 2026: Bet £10 Get £50 in Free Bet Builders

    Betting
    Betfair Sportsbook promotional offer banner displaying betting odds and bonuses for new customers on a sleek digital inter...
  • Chargebacks911, acceptcards Partner to Strengthen Chargeback Prevention for UK Merchants

    Business Wire
  • Klarna Partners With Arrive for Parking in 15 Markets

    Business Wire

CityAM Canada — business, markets and opinion for Canadian readers.

Sections

  • Business
  • Markets
  • Tech
  • AI
  • Economics
  • Opinion
  • Cities

Company

  • About
  • Contact

Legal

  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 CityAM Canada. All rights reserved.
Terms · Privacy · Cookies