An alert saying your card was added to Apple Pay or Google Pay when you never set that up is not a routine glitch, according to a Bitdefender report on the scam. It can point to a compromised account or to provisioning fraud, an abuse of the enrollment step that puts a payment card into a mobile wallet. The card sitting in your hand does not rule it out, and the wallet platform itself does not have to be breached, because criminals go after the enrollment step rather than the contactless technology.
The mechanics are simple enough. A criminal first gets hold of your card details through phishing, a fake checkout page, or some other compromise, then adds the card to a wallet on a device they control. Apple says the card issuer or an authorized service provider has to approve a card for Apple Pay, so the thief needs one more thing: the verification step. The issuer sends an extra check, and the criminal talks the cardholder into sharing or approving it. That is the moment the victim believes they are confirming a purchase, when in fact they are authorizing a wallet registration.
The code that arrives is the tell. A wallet-registration code is not the same as an ordinary purchase confirmation code, so reading the full message matters more than trusting autofill, which is advice Santander UK gives alongside its warning about fraudulent Apple Pay and Google Pay setups. Once the token is live, the criminal can try to make purchases from that device. The complete card number never sits on the device or on Apple Pay servers; the issuer instead assigns a Device Account Number unique to that device, while Google Wallet relies on a device-specific token in place of the card number when a payment runs. Google's verification may run through a bank code, the bank's app or site, a phone call, or another method the issuer chooses.
Not every alert is real. Scam texts sometimes invent card-added-to-wallet warnings to steer people toward fake fraud departments, so an unexpected message should be checked through contact details you already trust rather than the ones in the message. Other warning signs include a wallet verification code you never asked for, an alert about a new device or a password change, unfamiliar transactions, and any caller claiming to be from the bank who wants an one-time passcode or an approval prompt.
Act even if no fraudulent charge has shown up yet. If the banking app allows it, freeze or lock the card first, then call the issuer and say the card was provisioned to a wallet you do not recognize. Ask for every unrecognized wallet token to be revoked or suspended, not just for a replacement card, because deleting the card from your own phone does not remove a token sitting on someone else's device. Apple makes the same point about its own hardware, noting that a card pulled off one device is not automatically cleared from the others. Issuers can suspend wallet credentials, and the distinction between authorized and unauthorized fraud may affect how a complaint and any reimbursement are handled.
After that, go through recent transactions and dispute anything you do not recognize, with the Consumer Financial Protection Bureau advising US consumers to report unauthorized transactions promptly. If email, banking, Apple Account, or Google Account access may be compromised, secure those accounts: change reused or exposed passwords, turn on strong multifactor authentication, and remove sessions or devices you do not know. Keep the alert, the one-time passcode message, transaction records, screenshots, and any bank case number.
Each EMV contactless tap creates its own single-use security code, so the report frames this fraud as misuse of card data or of the enrollment path rather than chip cloning. Bitdefender's own tools, including Scamio for analyzing suspicious messages, links, screenshots, and QR codes, and Digital Identity Protection for monitoring breached personal data, are marketed as a way to catch the setup early, though the company says those protections cannot undo a fraudulent charge or ensure that a wallet registration is stopped.













