'Scammers stole £4,000, but my bank wouldn't believe me'

When 34-year-old Sahil Gandhi finished a gym class in central London, his phone alerted him to two mystery debit card charges in Dubai totalling £3,850. A third credit card payment attempt for £3,500 was blocked.
Sahil's cards were still safely tucked away in his gym locker, so how could scammers use them to make Chip and Pin payments in the Middle East?
When he reported the fraud to his bank, HSBC, Sahil said it accused him of writing down his Pin and refused to reimburse him.
'It’s clearly impossible for me to be in Dubai and the UK at the same time. I’m confused as to how this happened. I’ve never even been to Dubai. HSBC didn’t believe me and were adamant that I’d written down my Pin. They’re treating me like a fraudster,' says Sahil.
So what do you do when your bank doesn’t believe you? Here’s how we helped Sahil fight to prove his innocence and get his money back.
Was it a relay attack?
Sahil has no idea how the fraudsters knew his card Pin – he used a different code for the gym locker, and as he rarely uses his HSBC Visa debit card, so ‘shoulder surfing’ at a cash machine seemed impossible.
HSBC initially rejected his fraud claim because 'the genuine card had been used along with the correct Pin for one of the transactions and the genuine card was read for the other', rather abruptly telling him 'the bank is not responsible for identifying the person who made the debits'.
When we discussed Sahil’s case with Tom Chothia, a professor in cyber security for the School of Computer Science at the University of Birmingham, he pointed us towards relay attacks.
This is where fraudsters intercept the low-power radio signal from your card or phone – known as near field communication (NFC) – and instantly relay it to another device they control, potentially making unauthorised transactions thousands of miles away.
'If the bank says the real card was used in Dubai, and the owner says the card was in the UK, this certainly sounds like a relay attack. This isn’t particularly hard to do,’ says Chothia.
Card cloning is less likely, where scammers hide skimming devices, perhaps at self-service ticket machines at railway stations and car parks, to steal magnetic stripe data and create dummy cards. Although some payment terminals in Dubai still accept magnetic stripe cards as back-up to chip and Pin, HSBC would have known immediately if a magnetic stripe, rather than the card's chip, was read during the transaction.
Are Visa cards more vulnerable to relay attacks?
Security researchers have previously exposed a specific vulnerability that might allow an attacker to bypass the Visa relay payment limit. This means relay attacks have a much higher impact on Visa cards, potentially allowing very large transactions.
We asked Visa what it has done to mitigate the risk of NFC relay attacks. It told us: ‘While relay attacks are technically possible in a range of payment scenarios, they require significant criminal coordination and are not a scalable fraud technique. There is no specific vulnerability that makes relay attacks more likely with a Visa card present.’
Visa pointed to its layers of ‘network security and real-time authorisation controls’ to help detect and prevent suspicious transactions, adding that customers are protected from unauthorised transactions under its Zero Liability Policy. However, Sahil’s case clearly shows that some customers fall through the cracks.
When banks don’t believe fraud victims
Banks dismiss sophisticated attacks as rare outliers, but advanced card fraud tactics can mean victims are wrongly accused of negligence. It was only after Which? intervened, challenging HSBC on the geographic impossibility of being on two continents at the same time that the bank issued a full refund and apology.
HSBC said: ‘We take all reports of suspected card fraud extremely seriously and investigate each case in line with regulatory requirements. Our checks confirmed the presence of a genuine card when these transactions occurred, as well as the use of a Pin, which resulted in the initial decision to not reimburse Mr Gandhi.
'On further review, we have decided to reverse this decision due to the unique nature of this claim. We hope this is a satisfactory conclusion and apologise for any stress this process may have caused.’
This isn’t the first time Which? has stepped in when a bank has initially refused to refund an innocent victim. In another case, Barclays refused to refund over £6,000 because the payments came from the victim's own phone. Which? helped prove that he had inadvertently downloaded banking malware, giving scammers remote access to his device, and Barclays refunded him.
But fraud victims should not need a consumer champion to force firms to investigate complex fraud claims fairly and thoroughly.
If you find yourself in a similar situation, you should complain to your bank in the first instance. Once you have exhausted the bank's complaints procedure, you can escalate a complaint to the Financial Ombudsman.
Card fraud myths vs reality
Reassuringly, chip and Pin cards are broadly very safe, benefiting from encryption and unique codes for every transaction. In fact, UK Finance told Which? in February 2026 that there have been no recorded cases of criminals walking into a public place with a contactless card reader and initiating unauthorised transactions.
The urban legend of criminals scanning card details through your pocket on a crowded commuter train remains largely a myth, says Timur Yunusov, security researcher from Payment Village.
‘Nobody goes around scanning your data on the Tube. It’s such a faff to target one person and they can only extract the card number and expiry date. What does happen is criminals infecting point-of-sale systems to capture unencrypted card information, especially abroad.’
Which? has warned about fraudsters stealing card details and adding them to digital wallets on their own device, which industry insiders say is a growing problem.
Relay attacks are a very different kind of digital sleight-of-hand. While the industry downplays such sophisticated threats – one bank told us it had only seen a ‘handful’ of relay fraud cases – cybersecurity researchers warn that NFC scams are surging.
The truth is unclear, as there is no publicly available data on the volume of relay attacks. And, although the industry works with specialists to proactively detect advanced threats, Sahil’s case shows that banks don’t always have the answers.


