We protect our computers, homes, cars and phones – so why do we often overlook the contactless payment and identity tools we carry every day?
We live in a cyber world and increasingly understand the importance of protecting ourselves within it.
We pay for antivirus software. We secure our laptops, browsers, emails and cloud accounts. We use passwords, facial recognition and two-factor authentication. We insure our homes, cars, phones, holidays and possessions.
Yet many of us carry our money and identity around every day on contactless RFID/NFC chips without giving their everyday management a second thought.
Our bank cards, travel cards, identity cards, access cards, hotel keys and ePassports are designed to communicate wirelessly with readers. That is what makes them so fast and convenient – but should we also understand how, when and where that communication takes place?
Contactless is great
Let me be clear: I believe contactless technology is great.
It has transformed how we pay, travel, identify ourselves and enter buildings. It is quick, convenient and, overall, supported by sophisticated security systems.
This is not an argument that every contactless card will be skimmed, every user will experience fraud or contactless technology should be feared.
Visa, for example, explains that contactless payments generate transaction-specific security codes and says fraud using skimmed information is difficult and limited in scope. Banks also prevent and reimburse a substantial proportion of unauthorised fraud.
However, secure should not be confused with incapable of creating any vulnerability, mistake or inconvenience.
Contactless works through over-the-air communication. Understanding and managing that communication is simply another sensible layer of personal cyber safety.
Three different contactless events we should understand
The terms Accidental Payment, Card Clash and eSkimming are sometimes used interchangeably. They should not be, because they describe different events.
1. Accidental Payment
An Accidental Payment can occur during an active terminal scan window when a contactless card other than the one intended responds and is accepted.
The person paying may believe their chosen card has completed the transaction, while another sufficiently close contactless card has responded instead.
This is not a suggestion that ordinary terminals randomly charge cards from across a room. A payment reader must be active, a transaction must have been initiated, and the card must be within the effective reading conditions.
The point is simpler: if several unshielded contactless credentials are exposed during an active scan, how does the consumer know with certainty which one has communicated unless they check?
Transport for London specifically advises passengers to keep Oyster and bank cards separate and to use the same card or device when touching in and out. TfL also provides a process for checking journey histories and requesting adjustments when the wrong card has been charged.
2. Card Clash
Card Clash occurs when two contactless cards respond at the same time and the reader cannot determine which one should be used.
The transaction may be cancelled, a payment terminal may ask the user to try again, or a transport barrier may fail to open.
Some providers use Card Clash more broadly to include a payment being taken from the wrong card. I believe it is helpful to separate the two outcomes:
- Card Clash: the reader receives competing responses and rejects or cancels the interaction.
- Accidental Payment: the reader accepts a card that the user did not intend to use.
Both can create inconvenience, uncertainty and time spent checking what happened.
3. eSkimming
eSkimming is an unauthorised attempt to read or interact with an RFID/NFC payment or identity credential using reader or relay equipment while the credential is exposed.
That does not mean every attempted read produces usable information or results in fraud. Modern payment systems contain important protections, including transaction-specific codes, monitoring and issuer controls.
Nevertheless, independent security researchers continue to study eavesdropping, relay attacks and other contactless attack methods. The existence of those protections does not remove the value of controlling when a physical card or identity document is available to communicate.
Shielding is therefore not a replacement for bank security, transaction alerts, strong passwords or reporting suspicious activity. It is an additional physical layer: the credential remains shielded until its owner chooses to present it.
Why is there still a knowledge gap?
Banks and technology providers give us extensive advice about:
- Passwords and PINs
- Phishing emails and suspicious links
- Online shopping and banking apps
- Lost and stolen cards
- Identity theft and account takeover
- Telephone, impersonation and investment scams
But how often are consumers clearly taught about managing the physical contactless credentials they carry?
TfL publishes Card Clash guidance, and payment providers publish information about contactless security. However, the guidance is often fragmented across different organisations, websites and customer-service systems.
- Are consumers being given the complete picture?
- Do most people understand the difference between Card Clash, Accidental Payment and eSkimming?
- Do they know which of their cards, passports, travel passes, hotel keys or access credentials use RFID or NFC?
- Do they understand how to check which card has been charged – or what they must do to correct an event?
- If providers believe these issues are sufficiently important to explain on help pages and through refund processes, why are they not explained more prominently at the point where contactless products are issued?
Getting the money back is not the whole story
UK Finance reported that contactless fraud losses increased by 8% to £46.8 million during 2025. It also says banks refund almost all cases of unauthorised fraud.
That protection is important, but reimbursement does not make an incident effortless.
When an unfamiliar or incorrect transaction appears, the customer may need to:
- Notice the transaction in the first place.
- Check receipts, travel records and account activity.
- Decide whether it is an incorrect charge or suspected fraud.
- Contact the retailer, transport operator or card issuer.
- Freeze or cancel the card if fraud is suspected.
- Provide information while the transaction is investigated.
- Wait for a refund or adjustment.
- Replace the card and update services if necessary.
- Continue monitoring the account for further activity.
For a transport error, the customer may need to check their journey history, identify which bank card or Oyster card was used, locate the incorrect or maximum fare and apply for an adjustment.
Even when the money is eventually returned, the customer has still experienced worry, administration, inconvenience and lost time.
Why don’t we think in terms of a toolkit?
No single product solves every cyber or personal-safety issue. That is why we use layers.
We do not expect one password to protect our entire digital life. We use secure devices, software, alerts, insurance and good habits together.
The same principle can be applied to contactless:
- A shielded everyday wallet for payment cards
- A separate shielded wallet for a backup bank card and ID, to support smartphone pay habits
- An RFID/NFC shield for individual cards
- A shielded passport wallet or ePassport solution
- Appropriate protection for travel, hotel and access credentials
- Transaction notifications and regular account checks
- A clear plan for reporting anything unexpected
This does not complicate contactless. It helps us remain in control of when each credential is available to communicate.
What should you look for when buying RFID/NFC protection?
Price alone does not prove that a product works – and an expensive product is not automatically a good one either.
However, very cheap, unverified protection can sometimes mean less effective materials, incomplete coverage, poor construction or unsupported performance claims. An inferior product can create something worse than no product at all: false reassurance.
Before buying, ask:
- Does the supplier clearly explain what the product is designed to protect?
- Is it intended for payment cards, identity cards, access credentials, ePassports – or a specific combination?
- Does the supplier provide credible information about its shielding material and construction?
- Has the design been researched or tested for the relevant RFID/NFC applications?
- Is the credential protected when the wallet, sleeve or product is used as instructed?
- Can the user deliberately access the correct card without exposing everything else?
- Is the manufacturer or supplier identifiable and accountable?
- Does the business provide proper product guidance, customer support and a returns process?
- Are its claims specific and supportable, rather than based on exaggerated fear?
- Does the product fit naturally into everyday life, so it will actually be used?
A few pounds saved on an unknown or poorly constructed product is not a saving if the protection is unreliable.
How we can help
At Blocktek, we have developed the NOMO™ range as a family of practical, affordable RFID/NFC safety products – not as a reason to fear contactless technology.
Our published history traces our technology research to a UK Government-supported project beginning in 2005, followed by patented VoyagerBlue shielding technology in 2006 and continued research and product development.
That heritage matters because effective contactless protection is not simply about placing a piece of metal inside a wallet. Materials, coverage, construction and the way the user accesses the protected credential all matter.
Our range includes solutions for payment cards, backup cards, identity and travel credentials and ePassports. The NOMO™ Flippa, for example, is designed as a separate smartphone buddy for a backup bank card and ID.
A backup bank card should not be stored in the back of the same phone it is intended to back up. If the phone is lost or stolen, the backup disappears with it and is no longer a backup.
While stored unshielded in the back of a phone, that card may also be exposed to the same three everyday contactless vulnerabilities described earlier: Accidental Payment, eSkimming and Card Clash.
Carrying the backup card separately in a reputable shielded wallet preserves the reason for having a backup in the first place, while helping to keep it protected until the owner deliberately chooses to use it.
Contactless is great. We believe it simply needs a little affordable, well-designed help to stop an unexpected event becoming a hassle – or an avoidable risk.
So, now that you know more about Accidental Payment, Card Clash and eSkimming, is it really not worth spending a few pounds to help protect two of the most valuable assets we carry – our identity and our money?
What do you think: should contactless protection become a normal part of everyone’s personal cyber-safety toolkit?
Rob Rostron
Owner and Managing Director
Blocktek Ltd

