In 2026, PrivatBank recorded a sustained increase in one of the most technically complex schemes for stealing funds — NFC Relay attacks. According to Natalia Figol, head of the bank's fraud management department, criminals remotely read payment data from customers' cards by getting the victim to tap their physical card against their own smartphone. The scheme, which the bank first identified in 2025, reached a new level of spread this year and has become a priority area for the anti-fraud service.
Attack mechanics: from messenger to ATM
The NFC Relay attack scenario is built on a classic social engineering model. The criminal contacts the victim under the pretext of an "app update" or a "security check." The victim is then offered to download a third-party program — malware — from a messenger or an unknown website. After the app is installed, the victim is asked to perform the key manipulation: tap their physical bank card against the smartphone and enter their PIN code. At that moment, specialized software remotely reads the payment data through the phone's NFC module, after which the fraudsters instantly withdraw cash at an ATM or make payments in stores. The entire chain from the first call to the theft of funds takes only a few minutes.
Bank's comment and security rules
"It is very important to be able to recognize such attempts. The bank never asks you to download third-party files from messengers or to tap your card against a smartphone for a 'security check' or 'scanning.' We also recommend installing software only from official sources — App Store/Google Play," Natalia Figol emphasized. PrivatBank specifically reminds customers: employees of financial institutions never ask clients to tap their card against a smartphone for "scanning" or demand the installation of third-party files. The only safe channels for downloading apps remain the official stores — App Store and Google Play.
Statistics: fewer attacks, but greater damage
The macro indicators published by the National Bank of Ukraine for the end of 2025 confirm a strategic shift in cybercriminals' tactics. The number of illegal operations with payment cards in the country fell by 5% — to 256 thousand cases. However, the total damage from them rose by 24% — to 1.4 billion UAH, and the average "check" of a single fraudulent operation increased by 30% — to 5,536 UAH. These figures show that criminals are betting not on the volume of attacks, but on their technological complexity and effectiveness. The NFC Relay scheme fits exactly this logic, allowing large sums to be withdrawn in a single operation without attracting the attention of monitoring systems.
Context: NFC fraud as a global trend
Attacks using NFC technology are not limited to the Ukrainian market. In parallel, law enforcement agencies in other jurisdictions are recording similar schemes: in particular, the Russian Ministry of Internal Affairs identified the theft of online bank data via the NFC module of someone else's phone, and Russian media in July 2026 reported on new ways of stealing funds via a smartphone. This indicates that NFC Relay attacks have become part of a global trend of escalating technological complexity in financial fraud, in which artificial intelligence and specialized malware allow criminals to automate even the most complex stages of an attack.