Update on Apple Pay / bank - Fraud (UK)

Ok so just thought I would bring everyone up to speed on what’s happened with my fight with Monzo bank for unauthorised transactions from our joint account without us knowing and paid to 5 separate Revolut payment cards ..


we have been fighting this since March 24 when the alarm was raised when the transactions started leaving our account showing on our Apple Watches while we sat and watched TV .. we immediately emptied the account of all remaining funds and contacted MONZO , who froze all cards associated immediately and then started to look into it .. we contact Revolut who told us to go away as we are not customers , we contacted Apple support who said that the payments had not shown up on our account history .. however have now said they should have not said that ? … that same day Monzo fraud specialist team …LOL we have authorised it and they will not pay the money back (£650)


The whole case eventually after arguing with Monzo was sent across to the financial ombudsman who have looked into it and said that they will rule in favour of the bank saying that the payment token was set up in September 2024 on my wife’s iPhone and approved via the Monzo app !!!!!!! So in nut shell we have done it which is total nonsense!


we have no dealings with revolut , the money was leaving our account one after the other £100 then £150 the £100 etc while my wife was screaming at me someone is taken money out of our account ! and no one can explain how !! All we can assume we have been subject to a very clever set of fraudsters who have accessed our account wither Apple Pay , iPhone or bank without us knowing set up a payment token and used it 6 months later ..


we have checked our payment history back in September and everything looks in order , no dodgy payments , in fact my wife never really uses Apple Pay online , last used was July 2024 , and always uses her phone as tap and pay .


some have said that her card has been skimmed yet this does not explain how they have been able to access Apple Pay to set up this so called payment token


in a nutshell we have lost £650 ($893) in 13 min’s and can’t prove this is fraud !


we are about to close our Monzo bank accounts and stop using Apple Pay as somewhere down the line one of these is to blame for all this ! So please please be very careful what you do only have minimal funds in your debit account and have the rest in a savings account that can be used to move money around as and when needed


we shouted out to Apple support again for help and as expected we got passed from one advisor to another , one said one thing and the other said another , it was basically go away we don’t want to know … thanks allot ! Small fish in big ocean springs to mind !!


So don’t use Apple Pay and don’t bank with Monzo



one last evidence I’ve supplied yesterday , I put my wife’s email account which is her Apple account in NORD VPN and this has come back with a dark web breach back in September 2024 ? Possible details been leaked from a website that sells left over tickets for shows in London , I’ve send this to the ombudsman so hopefully this will help our case , yet it still does not explain how they have been able to set up the payments , my wife never used this company and never paid for anything just simple registered with NO payment . Who knows !


thanks for your time if you have read this right to the bottom


take care and be careful we are always under attack ! and the so called financial institutions won’t help us , yet want our money !


Andy





iPhone 13 Pro Max, iOS 18

Posted on Jun 27, 2025 1:18 AM

Reply
Question marked as Top-ranking reply

Posted on Jun 29, 2025 6:57 AM

There is nothing suspicious in the approvals for each transaction. A unique approval for each transaction is standard as is the ARD/ARN (Acquirer Reference Number).


There really is only one way you’re going to prove your case. Each Apple iPhone that works with Apple Pay has a unique SEID (Secure Element ID). Apple has encrypted data on their servers that know the SEID of the device used to approve the transactions in question. The issuing bank can confirm the SEID of the device that was used.


Apple will generally cooperate with investigations, but it takes a court order. Have you filed a police report?

35 replies

Jun 27, 2025 4:32 AM in response to Jeff Donald

5 unauthorised payments started transferring out of our account via apple pay to 5 different payment cards at a bank called Revolut ( the are cards that you put money onto them ) while we sat at watched TV all via Apple Pay online transactions to who we don’t know .. this was not authorised by us , all this information has been supplied by MONZO who are claiming we have done it !! The investigation by the ombudsman has said that a token was set up in September 2024 and authorised by my wife’s device (Apple iPhone) and within the Monzo app , I can confirm that this did NOT happen and we are at a total loss at how this has occurred ! Yesterday I put my wife’s iPhone account email into NORD VPN and straight away this identified a breach in data on the black web back in September 2024 , which seems abit coincidental that’s when the so called token was set up ?

Jun 27, 2025 4:43 AM in response to Smigglechops

In fact Jeff we had this discussion back when we disputed the transactions and I used all the information you supplied and help me understand how Apple Pay works … no one can explain how it’s happened and keep blaming us , the truth is we have been defrauded out of £650 ($891) ny what I would say are some very sophisticated fraudsters who have somehow got into our account and made the payments disguised them as Apple Pay why I am saying this we spoke to Apple on the day this happened and they confirmed that no payments had been made via Apple Pay as these did not show up in the history however now Apple are now saying that they should not have told us that and will not help us endless phone calls being passed from one agent to another and just keep getting the door shut in our face when you search the net you find case after case after case of people who have had this type of transaction on their account and can’t explain how it’s happened even this week I have a colleague who I work with her dad has had £30 taken out of his account via Apple Pay at a butchers he goes to and no one can explain how that has happened. It all seems very very suspicious that something is wrong with Apple Pay and fraudsters today are able to get into this system collect the data and then set up payments without the anyone’s knowledge.

Jun 27, 2025 4:59 AM in response to Jeff Donald

Who ever took the money transferred the money out of our account one after the other within 13 min


card 1 was transferred £ 150

card 2 was transferred £ 100

card 3 was transferred £ 150

card 4 was transferred £ 100

card 5 was transferred £ 150


basically we paid Revolut bank from our account which showed as Apple Pay online transactions , we only know now that they are prepaid cards because this is what the back have told us , each one had different Authority codes and transaction numbers

Jun 27, 2025 5:18 AM in response to Jeff Donald

The transactions were made via online payment via Apple Pay to these accounts in Revolut bank our bank account shows five transactions to Revolut bank when you go into the transaction history it shows where it’s gone which was five prepaid cards so someone somewhere was able to get into our account and use our Apple Pay to make a payment as an online transaction, similar to if you were purchasing an item online

However, the bank and the ombudsman are saying that we set up the transaction in September 2024 and approved a token which then allowed these transactions to be made on that day which we have disputed as we have not done this so basically someone somewhere has hacked into either the banking app and used our Apple Pay or has hacked into the Apple Pay and used my wife’s debit card which is loaded within Apple Pay , and made the five payments. The payments only stopped once I emptied our account or otherwise I truly believe that this type of payment via Apple Pay would’ve continued until the account was emptied and we would’ve been looking at an awful lot more money

Jun 27, 2025 5:23 AM in response to JM-Master

Hi thanks for taking the time to reply. Yes we have already done that on the day that the money was taken. The guy we spoke to was very helpful and looked into my wife’s account and said that these payments were not made via Apple Pay and advised us to continue with the dispute with our bank and tell our bank to contact Apple who would tell them that these payments did not happen However the bank did not do this which is also part of our dispute and when we have re-contacted Apple support via this method. They have passed us to one agent to another and basically in so many words have told us that this guy should not have told us that . Due to the nature of this attack on our account, we removed all payment cards from Apple Pay which unfortunately unknown to us removed all the history as we thought at the time we were under attack and all payment cards within the Apple Pay system was vulnerable. We have re-contacted Apple and made an official complaint And requested the taped conversation with this guy to be provided to us so we can prove that Apple have said that these transactions were not present unfortunately they have refused to contact us and are ignoring us .

Jun 27, 2025 5:32 AM in response to Smigglechops

The bottom lane is that the bank and the financial ombudsman have said that we made these payments to Revolut bank yet my wife was standing next to me with her phone in her hand screaming that our bank account was being emptied and when I logged onto our banking app, the money was just depositing out of it. It was only until I moved the remaining funds from our joint account to my own personal account. This stopped the bottom line is we have been victims of fraud but no one can tell us how this has been done everybody says Apple Pay is secure however this happened so something is not adding up and the bank will not accept what we are saying because we’re talking that’s associated with this payment was authorised on my wife’s device. When you look at my wife’s history with Apple Pay she has only used it once to purchase some clothing online every other payment is made via her phone via Apple Pay as tap and pay. It’s me that uses Apple Pay as a payment method online constantly. I also use my watch and my phone when I’m out she only uses her phone and her phone is never been left anywhere or security is up-to-date face recognition and two factor authorisation yet this still happened so you can imagine we just don’t know what is safe anymore.

Jun 27, 2025 6:20 AM in response to Jeff Donald

I put the information onto a post but the post has been deleted .


all we know as I’ve said ,


5 online transactions using my wife’s debit card via Apple Pay to revolut bank , on investigation this turn out to be 5 prepaid Revolut debit cards , now originally Apple said this could not be done , then later on said this could be so I’m lost still how this has actually been done .

Jun 27, 2025 12:59 PM in response to Smigglechops

One other point my wife very rarely uses her card and always uses her phone , unless it was skimmed at a cash point machine ? Yet the token was set up on the 21st I just don’t get it . Unless the token is his and the money was paid , put the card skimming happened at another time ? It’s all very very confusing and no one actually knows what’s gone on , apart from the only clear cut evidence we did not make the payments

Jun 28, 2025 7:26 AM in response to Smigglechops

Please do me and other community members a favor and use periods and paragraphs when you write lengthy posts. It’s extremely difficult to read and refer back to when I need to double check what you’re saying. 😃😃😃


Yes, ATM’s frequently are targets for skimmers and Shimmers (skimmers read mag strip and shimmers read the chip data). So are gas stations and many small merchants. Gas stations have an additional issue with Tap-To-Pay using the card being used at the pump. There are numerous YouTube videos you can search. Literally, any time the physical card is used the account is at risk.


The bank can see the date and time the various tokens were created and used or setup. The merchant token was setup September 21, 2024 and when exactly did the fraud occur?

Jun 28, 2025 8:12 AM in response to Jeff Donald

Thanks for the well explained use of Tokens to process payments. I have a couple of questions for my knowledge of their use that may also help the OP that I think only you can answer.

  • Can a merchant request a Merchant Token used for subscriptions to keep the information as a card on file transaction that can be used for later charges, instead of a Payment Token for a one time use charge? It does not appear as a user we have the choice of what type of token we want to send.
  • If a merchant has their information hacked that contains your Merchant Token, can a scammer use the token for other purchases or can the future charges only be made by that merchant?
  • With the latest iOS, we are supposed to be able to revoke Merchant Tokens in the Wallet app when viewing the cards recurring charges, is this at all helpful? Since the OP removed the card, that would be no longer possible to view, but would those tokens reappear if the card was added back to the Wallet app? And lastly, since the bank knows the token used for the transactions, is there anyway on your device to see if that token is one used for a recurring charge in the Wallet app?

Jun 28, 2025 9:18 AM in response to Jeff Donald

Got it. Thanks again!


Shouldn't we as the user have the choice on whether we want the merchant to have a one time use token or a Merchant Token used for subscriptions? It is my understanding that this communication is done between the merchant and the bank, but we appear to be left out of the loop. I think Apple is also left out of the loop as the only information we have comes from our bank. I do understand that the PNO is also involved, but for simplicity I refer to the communication from our bank.

Jun 28, 2025 10:10 AM in response to Mac Jim ID

Merchants have always had the ability to retain payment information. In the old days, it wasn’t even encrypted, just plain text data. But when a merchant offers a subscription, they need some method of controlling fulfillment of the contract. I understand that some unscrupulous merchants may make it difficult, but I’m surprised that people simply will not call a phone to cancel a subscription. Withholding payment is not the way subscriptions work. Apple permitting tokens to be revoked may be dependent on the bank and the merchant.


Cardholders don’t own the token, just like they don’t own the payment method.

Jun 29, 2025 3:29 AM in response to Jeff Donald

Thanks for getting back with this information and sorry for the long messages I will make sure they are broke up abit


I’ve copied this info for when the ombudsman comes back with a final decision .


Whats confusing which we don’t understand the token was set up on the 21 September 2024 , and then the money was taken on the 14th March with what we believe was a test payment 13mins before the rest went out , the wife did not register or use her phone on any site that day in question or put her details into anything.


what’s got me if the token was set up 6 months before surly a test payment would have gone out of the account , I’ve checked and nothing has been paid to any suspicious accounts .


so does the token last 6 months ?


thanks for all your reply’s I really do appreciate it


Andy

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

Update on Apple Pay / bank - Fraud (UK)

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.