RFID Skimming: What the Data Actually Shows
We sell RFID-blocking cards and sleeves. This page explains why the threat they're usually marketed against — someone remotely reading your bank card through your pocket — is close to undocumented, and what they're actually good for. Every figure is attributed to a named source and linked. If that seems like a strange thing for us to publish, see how we write.
The Short Version
- Remote skimming of a payment card in your pocket is not a documented, real-world problem. The UK card industry's position is that there has never been a confirmed report of money taken from a contactless card while it was still in the cardholder's possession.
- Contactless is the lower-fraud channel, not the higher one. Per UK Finance, contactless fraud ran at about 1.2p per £100 of contactless spending in H1 2025, against 6.9p per £100 across all card fraud.
- Contactless fraud is overwhelmingly lost and stolen cards being tapped in shops — pickpocketing, not electronics. An RFID blocker does nothing about a card that has been physically taken from you.
- Where RFID/NFC blocking genuinely earns its place: access credentials — hotel keycards, office badges and older transponders, many of which use weak or no encryption and are demonstrably cloneable with cheap hardware.
Why Payment Cards Are Hard to Skim
Modern EMV contactless cards don't broadcast what a thief would need. When a reader triggers the card, it returns a single-use cryptographic token for that one transaction — not your name, not the CVV printed on the back, and not a reusable copy of your card number. Capturing that token doesn't give someone a working clone of your card, which is why the economics of remote skimming don't work: enormous effort, close physical proximity, tiny payoff, versus far easier fraud routes.
There's also a consumer-protection layer: card networks and UK/EU rules put unauthorised-transaction liability on the issuer, not the cardholder, in the ordinary case. Practically, the fastest protection is checking your statements and reporting anything you don't recognise — not shielding.
What the Fraud Data Actually Describes
When you see a "contactless fraud is rising" headline, the underlying incidents are almost always the same story: a card is lost or stolen, and the thief taps it in shops before it's cancelled. That's a real problem — it's just not an electronic one, and it isn't solved by a blocking card or sleeve. It's solved by noticing the card is gone and cancelling it.
We'd rather say that plainly than sell you a product for a threat model that doesn't match the evidence.
Where RFID Blocking Is Genuinely Worth It
This is the honest use case, and it's a real one:
- Office access badges and hotel keycards. Many building-access credentials use older, weak or entirely unencrypted schemes. Unlike a payment card, a cloned badge is a working copy — and cheap handheld cloning hardware is widely available. If your badge opens something that matters, shielding it is reasonable.
- Passports. E-passport chips are access-controlled, but many travellers prefer them shielded in transit as a matter of principle; that's a defensible choice rather than a response to a documented epidemic.
- Older or non-EMV cards and some transit/loyalty cards, which may not have the tokenisation protections above.
- Peace of mind at a low price. Entirely legitimate — just buy it knowing what it does, which is what this page is for.
If that's your situation, our RFID blocking cards and sleeves do the job. If it isn't, you have our permission to skip them.
How to Test an RFID Blocker Yourself
- Put the card or badge inside the sleeve, or beside the blocking card in your wallet.
- Present it to a reader you're allowed to use — a contactless terminal for a payment card, or your own office/hotel reader for a badge.
- No read = the shielding works. A successful read = it doesn't.
Test the specific credential you care about: blocking performance differs between the 13.56 MHz band used by payment cards and the 125 kHz band used by many older access badges, and a product that stops one may not stop the other.
Using This Page
Journalists and editors are welcome to cite this — please credit UK Finance for the fraud figures and link to their guidance. If you want a source for "RFID skimming is largely a marketing threat, per a company that sells RFID blockers", that's us, on the record.
Related Reading
RFID skimming (glossary) · Relay car theft: what the data shows · RFID blocking cards & sleeves · What is a Faraday bag? · How we write & what we don't claim