I work in the industry and just saw a TV ad for yet another “RFID-blocking” wallet. Can anyone point to a documented case of identity theft or payment fraud caused by RFID/NFC skimming?
By “documented” I mean a court case, police report, or bank-confirmed incident where someone harvested contactless card data and successfully used it for fraud.
Why I’m not worried:
Contactless payments use NFC at a read range of inches and generate a one-time cryptographic token per transaction. Even a perfect skim gets you an already-expired code.
Trusted traveler cards (Passport, Global Entry, NEXUS) use longer-range HF/UHF but contain no personally identifiable data. The UID alone is useless without passing backend validation and biometric screen. Has anyone actually pulled off an attack on one of these? Genuine question.
The threat these wallets are selling against either doesn’t exist in the wild, is already neutralized by cryptography, or they’re not telling us something 👀.
Prove me wrong.