ELS-0022Scams · Spain

Digital Wallet Scams: How One Telephone Call Can Give Criminals Access to Your Money

  • Official sources checked
  • Written by Sue Berry
  • Practical guidance

Criminals can add your bank card to their own digital wallet without taking the physical card. Here is how the scam works and what expats should do to protect their UK and Spanish accounts.

The Quick Answer

Digital-wallet fraud can allow criminals to spend money through Apple Pay, Google Pay or another mobile wallet even though the victim still has their physical bank card.

In one case reported by Which?, a 25-year-old man lost more than £18,000 after criminals telephoned him while pretending to be from his bank’s fraud department. They persuaded him to transfer money and reveal a one-time passcode. The code was then used to add his card to the criminals’ Apple Pay wallet. Within hours, they had made high-value contactless and online purchases.

The most important rule is:

Never share a one-time passcode with anyone who telephones or messages you—even when they appear to know genuine information about your account.

A one-time code may not simply confirm your identity. It may authorise a new device, digital wallet, payment or account change.

Why This Matters

Digital wallets are now part of everyday life.

Many expats use them for:

shopping in Spain;

shopping in Spain;

paying in restaurants;

paying in restaurants;

booking flights;

booking flights;

using public transport;

using public transport;

making contactless payments;

making contactless payments;

managing UK and Spanish cards on one telephone;

managing UK and Spanish cards on one telephone;

paying for travel and family expenses.

paying for travel and family expenses.

They are convenient, but they can also be targeted by criminals.

The victim in the Which?

case was contacted by people claiming to work for Lloyds Bank. The callers knew his exact account balances and card information, making the telephone call appear convincing. They persuaded him to move money from Lloyds to Revolut and later reveal a one-time code that allowed his Revolut card to be added to their Apple Pay wallet.

This is particularly relevant to expats because we may have:

more than one bank;

more than one bank;

accounts in different currencies;

accounts in different currencies;

both UK and Spanish telephone numbers;

both UK and Spanish telephone numbers;

pension payments;

pension payments;

currency transfers;

currency transfers;

travel cards;

travel cards;

unfamiliar banking apps;

unfamiliar banking apps;

regular contact with financial organisations in two countries.

regular contact with financial organisations in two countries.

A scammer who appears to understand these arrangements may seem genuine.

Frequently asked questions

Can someone use my card without stealing it? Yes. A criminal may use stolen card information and a security code to add the card to a digital wallet on their own device.

What is a one-time passcode? It is a temporary security code used to approve an action such as a payment, new device, password change or digital-wallet registration.

Will my bank ever ask me to read out a one-time code? Treat any such request as suspicious. End the call and contact the bank independently.

What should I do when a code arrives that I did not request? Do not use or share it. Freeze the card if appropriate and contact the bank through an official channel.

Can criminals add my card to Apple Pay or Google Pay? They may be able to do so when they have sufficient card information and obtain the security approval needed to register the card.

Does knowing my account balance prove the caller is genuine? No. Financial and personal information can be obtained through phishing, hacked accounts, malicious websites or data breaches.

What should I do when my bank app asks me to confirm my identity? Only approve the request when you personally initiated the action described. Do not approve it because someone on the telephone tells you to.

Can I see every digital wallet linked to my card? This depends on the bank. Some providers offer device and wallet controls, while others provide more limited information.

Will switching off contactless payments stop digital-wallet use? Some banks say it will, but controls vary. Check directly with your card provider.

What should I do first after finding an unauthorised payment? Freeze the card immediately, contact the provider, check all recent activity and preserve the evidence.

Will the bank refund digital-wallet fraud? Not always. The decision may depend on how the card was registered, whether codes were shared and whether security warnings were approved.

Where can I obtain cybersecurity help in Spain? INCIBE offers free and confidential cybersecurity guidance through its 017 helpline.

Important — Read Before You Act

Never read a security code aloud to a caller.

Never enter a code into a website reached through an unexpected message.

Never approve an app notification simply because someone on the telephone tells you to do so.

The message accompanying the code may explain that it is being used to:

add a card to Apple Pay or Google Pay;

add a card to Apple Pay or Google Pay;

register a new device;

register a new device;

approve a payment;

approve a payment;

reset a password;

reset a password;

change account information.

change account information.

Read the full message before taking any action.

When in doubt:

End the call.

End the call.

Freeze the affected card.

Freeze the affected card.

Contact the bank through its official app or a trusted telephone number.

Contact the bank through its official app or a trusted telephone number.

Check recent transactions and connected devices.

Check recent transactions and connected devices.

In Spain, INCIBE provides free and confidential cybersecurity guidance through its 017 helpline.

What To Do — Step by Step

  1. Understand what a digital wallet is A digital wallet allows a bank card to be stored on a telephone, watch or other device. Common examples include: Apple Pay; Google Pay; Samsung Wallet; bank-operated mobile wallets. Once a card is successfully added, the device may be used for contactless or online payments without the physical card being present.

  2. Recognise the fake bank-fraud call A caller may claim: your account is under attack; suspicious payments have been detected; your card has been cloned; money must be transferred for security; your banking app needs to be protected; you must follow instructions immediately. The caller may know genuine information about you. In the Which? case, the criminals knew the victim’s account balances and card details before persuading him to move money.

  3. Never move money for a caller A fraudster may ask you to: transfer money between your own accounts; send money to another bank; move savings into a “secure” account; top up a financial app; convert money into cryptocurrency; make several smaller transfers. They may say this is necessary to protect the money.

  4. Never share a one-time passcode A one-time passcode may be sent by text message or appear inside a banking app. It may authorise: adding a card to a digital wallet; logging in from a new device; approving a payment; changing account details; resetting security information. The Which? case shows how one code was used to add the victim’s card to a criminal’s Apple Pay wallet.

  5. Read the complete security message Do not focus only on the numbers. Read the words around the code. The message may say: “Use this code to add your card to Apple Pay.” “A new device is being registered.” “Do not share this code.” “Contact us if you did not request this.” If the action described is not something you are doing yourself, stop immediately.

  6. Do not approve unfamiliar app notifications Your banking app may ask you to confirm: your identity; a new device; a card registration; an online purchase; a large transaction. Do not approve it because a caller tells you it is part of a security check. In the reported case, the bank initially blocked several suspicious purchases, but the victim was persuaded to confirm his identity through the app because he believed he was protecting his account.

  7. End the call and verify independently Use: the telephone number printed on the card; the number inside the official banking app; the bank’s independently located website; secure in-app chat; a branch you know. Do not telephone a number sent by the caller or included in a suspicious text message. A caller may also manipulate the number displayed on your screen, so caller identification should not be treated as proof.

  8. Check cards connected to your digital wallets Open Apple Pay, Google Pay or your bank’s card-management section. Check: which cards are present; which devices are authorised; whether an unfamiliar device appears; whether there are cards you no longer use; whether old telephones or watches remain connected. Remove devices and cards you no longer recognise or use.

  9. Consider switching off features you do not use Depending on your bank, the app may allow you to: switch off contactless payments; disable online transactions; disable cash withdrawals; temporarily freeze the card; block transactions outside certain regions; set spending limits. Some banks say disabling contactless functionality can also prevent the card from being used in a linked digital wallet. Available controls vary between providers.

  10. Set useful transaction alerts Enable immediate notifications for: card purchases; digital-wallet activity; online payments; cash withdrawals; bank transfers; international transactions; large payments. Check that notifications appear on the telephone you currently use.

  11. Protect your telephone and email Use: a secure screen lock; biometric protection where appropriate; a unique email password; two-step verification; current recovery information; automatic software updates. Your email may contain: bank messages; card information; password-reset links; travel plans; copies of identification; correspondence with financial providers.

  12. Keep UK and Spanish banking information organised Record safely: the banks you use; genuine fraud telephone numbers; which account receives each pension; which cards are connected to digital wallets; whether the card is UK or Spanish; which telephone number receives security codes; how to freeze each card; how your partner can contact the bank.

  13. Make sure both partners understand the warning signs One partner may normally manage: the banking apps; pension payments; currency transfers; household bills; digital wallets. The other partner should still know: which banks are used; how to freeze a card; where genuine contact details are kept; never to share a security code; how to check recent transactions; who to contact for help. This can be especially important if the person who usually manages the finances becomes ill or unavailable.

  14. Freeze the card immediately if something looks wrong Use the official banking app or telephone number to: freeze the card; report it compromised; block digital-wallet payments; cancel the card; request a replacement. Then check: recent payments; pending transactions; transfers; linked devices; new payees; changed personal details. Do not wait for further purchases to appear.

  15. Contact every bank involved A scam may move money between several accounts before it is spent. Contact: the bank where the money began; the bank or financial app receiving the transfer; the card provider; any currency or payment service involved. Explain the complete sequence, not only the final card purchase.

  16. Preserve the evidence Keep: telephone numbers; dates and times; text messages; security-code messages; app notifications; screenshots; bank statements; payment details; names used by the callers; emails; notes of what was said.

  17. Report the fraud In Spain, suspected digital fraud can be reported to: Policía Nacional; Guardia Civil; your bank; the relevant financial provider. INCIBE’s 017 service offers free, confidential and personalised cybersecurity guidance.

  18. Do not assume reimbursement is guaranteed The outcome may depend on: how the transaction was authorised; whether a code was shared; whether warnings were approved; which bank or card provider was involved; the type of payment; the applicable rules; the evidence available. In the Which? case, only £1,582 was recovered through chargeback, while the providers declined to refund the remaining loss because the victim had shared the one-time code and confirmed security prompts.

  19. Complain formally when necessary When a provider refuses reimbursement: request its final written decision; ask for the reason; preserve all records; follow its complaints procedure; consider the appropriate financial complaints body. The process will depend on whether the provider and account are based in the UK, Spain or another jurisdiction. Seek independent advice where necessary.

  20. Beware of follow-up recovery scams After a financial loss, another caller may claim they can recover the money. They may pretend to be: a bank investigator; a police officer; a lawyer; a regulator; a cybersecurity expert; a recovery company.

Common Mistakes to Avoid

  • Trusting the caller because they know your balance - Account information can be stolen. Knowledge does not prove identity.
  • Believing the telephone display - The number shown on your screen may be manipulated or spoofed.
  • Reading a one-time code aloud - The code may register your card on a criminal’s device.
  • Ignoring the wording around the code - The message may clearly explain that a digital wallet or new device is being authorised.
  • Approving an app notification while on the telephone - The approval may allow a payment or card registration to proceed.
  • Moving money for “security purposes” - Do not transfer money because an unexpected caller says your account is at risk.
  • Assuming the physical card must be stolen - Digital-wallet fraud can occur while the card remains in your purse or wallet.
  • Leaving old devices connected - An old phone, watch or tablet may remain authorised.
  • Using the same password for email and banking-related services - A compromised password can expose several parts of your financial life.
  • Failing to update an old UK or Spanish telephone number - Security alerts may be missed or sent to a number you no longer control.
  • Waiting to see whether more transactions appear - Freeze the card as soon as suspicious activity is identified.
  • Assuming the bank must refund everything - Reimbursement can be disputed where the customer shared a code or approved an action.
  • Feeling too embarrassed to report what happened - Scammers are skilled manipulators. Fast action is more useful than self-blame.
  • aying a recovery company that contacts you unexpectedly - This may be a second scam targeting previous victims.

Your Action Checklist

  • Never share a one-time passcode.
  • Read the complete security message before using a code.
  • End unexpected bank-fraud calls.
  • Contact the bank through its official app or trusted number.
  • Never move money to a safe account.
  • Do not transfer money for a caller.
  • Do not approve unfamiliar banking notifications.
  • Check which cards are stored in digital wallets.
  • Review devices connected to your banking accounts.
  • Remove old or unfamiliar devices.
  • Enable transaction notifications.
  • Set card-spending limits where available.
  • Disable payment features you do not use.
  • Use a strong screen lock.
  • Protect your main email account.
  • Use unique passwords.
  • Turn on two-step verification.
  • Update UK and Spanish telephone numbers.
  • Record genuine bank fraud contacts.
  • Make sure both partners know how to freeze cards.
  • Freeze a card immediately after suspicious activity.
  • Contact every bank involved.
  • Check recent and pending transactions.
  • Preserve security messages and screenshots.
  • Report the fraud to the appropriate authorities.
  • Contact INCIBE on 017 for cybersecurity guidance.
  • Keep copies of bank complaint decisions.
  • Seek independent complaint advice where necessary.
  • Beware of recovery scammers.
  • Review your digital-wallet security regularly.

In Summary

A criminal does not need to steal your physical bank card to use it.

They may only need:

your card details;

your card details;

access to personal information;

access to personal information;

a one-time security code;

a one-time security code;

your approval of an app notification;

your approval of an app notification;

an opportunity to add your card to a new device.

an opportunity to add your card to a new device.

Once a card has been added to a criminal’s digital wallet, they may be able to make contactless and online payments using their own telephone.

Protect yourself by:

never sharing one-time codes;

never sharing one-time codes;

ending unexpected fraud-department calls;

ending unexpected fraud-department calls;

contacting the bank independently;

contacting the bank independently;

reading every security message carefully;

reading every security message carefully;

refusing app approvals you did not initiate;

refusing app approvals you did not initiate;

checking devices and wallets connected to your accounts;

checking devices and wallets connected to your accounts;

freezing the card immediately when something looks wrong;

freezing the card immediately when something looks wrong;

making sure both partners understand the warning signs.

making sure both partners understand the warning signs.

A caller knowing your balance, address or card information does not prove they work for your bank.

Sue’s final thoughts & experiences

A personal note from Sue Berry

The most frightening part of this type of scam is that the criminals can sound as though they are helping. It happened to me one time and I quickly realised that my bank wouldn't phone me. I was with Lloyds in the UK. I hung up and contacted my bank giving them the number the other call came from. They confirmed they would never phone me and if I got a message to call them, I must always call through my bank app.

They may know your name, bank, account balance or recent transactions. They may tell you that your money is in danger and that you need to act immediately.

That knowledge does not prove they are genuine.

Living abroad often means we manage several accounts, currencies and telephone numbers. It can be difficult to know which security message relates to which card.

The safest habit is simple:

Do not share the code. End the call and contact the bank yourself.

A genuine bank will understand why you want to verify the situation.

Protecting your money is more important than being polite to an unexpected caller.