You can make a difference in the Apple Support Community!

When you sign up with your Apple Account, you can provide valuable feedback to other community members by upvoting helpful replies and User Tips.

Someone Added my credit card to his iphone using a Phishing site and used it. Apple pay does not requie OTP or PIN Why?

Why there is no Cooling-Off period or OTP or PIN or any Limit on using Apple pay? I reported the scam in just 2 mins but he had already done 5 transactions until my card limit was reached. Why Apple pay does not consider to take authority from the Card owner while doing transactions. Can the Iphone owner and the Card Owner be 2 different people? Why does Apple take the authority from the card owner and give to Iphone owner? How are these secured transaction if the card owner has no role in these transactions?

iPhone 13 Pro

Posted on Nov 26, 2024 12:54 AM

Reply
4 replies

Nov 26, 2024 4:34 AM in response to kaedjhr

The risk that you face with using Apple Pay is infinitesimally smaller than with using your card in person. Apple Pay effectively cannot be hacked. Gaining access to your iCloud would not allow an individual access to your Apple Pay cards; the added biometrics negate use by someone else.


Your card credentials from your bank are less secure. Regardless, your bank must authorize adding a card to Apple Pay. So, if your bank allowed someone to authenticate and add your card, that's on your bank. Most require logging into the bank account before authorizing adding the card. That's how the verification works.

Nov 26, 2024 4:15 AM in response to muguy

You have not answered my questions and my concerns? My concern is risk which we face with Apple Pay. The fraudster can now either add your card to his Iphone or just hack your iCloud account and he becomes the card owner. Initially there should be a cooling off period of may be 8 hrs or limit on first few transactions or OTP/PIN sent to the card owner for first few transaction so the real owner has time to react. Why does not Apple Pay acknowledge that card owner could be different then the Iphone/Icloud owner and give the real card owner some time to react before any major harm is done? I my case in just 2 min. the fraudster emptied my Credit Card account and bank does not take any liability saying Apple Pay is secure. It seem by adding the card to Apple Pay Banks and Visa/Mastercard are not liable for any frauds done. Before they would consider fraud and there were high chances to recover any loss.

Nov 26, 2024 4:54 AM in response to kaedjhr

Why aren’t you asking these questions of your bank? Your bank controls adding the cards. Some banks require additional security measures before a card can be added. Why didn’t your bank? Why doesn’t your bank have a cooling off period? Because they don't want one.


Apple doesn’t approve or deny adding a card to Apple Wallet the bank establishes its requirements. Apple doesn’t approve not approve or decline transactions, only the issuing bank can approve or decline a transaction.


Why doesn’t Apple identify card users. Apple doesn’t have the required information. The card being added, legally belongs to the bank. The bank has all your identification such as current address, drivers license, and background (from credit reports obtained when you applied for the card). Apple has no legal standing to interfere with the bank or you.


What does Apple Pay do? Provides a secure and private encryption of your personal and financial information. Stores it in a separate area of your iPhone (Secure Enclave) that has never been hacked and likely can’t be. Transmits encrypted information to the merchants terminal and receives transaction data after the transaction is complete to display in your Wallet app.


So please explain how Apple is at fault? In regard to liability, I don’t know your banks terms and conditions, that you agreed to, when you added your cards to Apple Wallet. You must have read them and understood them, correct?


Many credit cards offer fraud protection. If yours does not, check with the Payment, Network Operator (Visa, Mastercard etc.). When you talked to the bank did you talk to their fraud department or just their regular tier one support person? Fraud department usually does a better job.


Lastly, credit card information is not stored or backed up to iCloud. Apple does require 2FA to make major iCloud changes, unless you give them your passcode. But even if they have the passcode, there’s no financial information stored or backed up by Apple.

Someone Added my credit card to his iphone using a Phishing site and used it. Apple pay does not requie OTP or PIN Why?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.