The internet has two narratives about RFID skimming. One says criminals are walking around train stations with antennas, harvesting cards through your jacket pocket. The other says it never happens and it is all marketing scare. Neither is accurate.
Here is what the threat actually looks like in 2026, based on recent law-enforcement reporting, payment-industry incident data, and academic research that has continued through the contactless-card era.
What RFID skimming is
RFID skimming is the use of a portable radio reader to query a contactless card without the cardholder's knowledge or permission. The reader pretends to be a payment terminal. The card responds. The reader captures whatever data the card transmits.
What gets captured depends on the card. For older mag-stripe-equivalent contactless cards, the data was enough to clone the card. For modern EMV contactless cards, the data is tokenized and one-time, so a captured response is much less useful for cloning. Modern chip cards rotate authentication data on every transaction.
So is it a real threat, or solved?
Both, in different proportions.
For your contactless credit and debit cards in 2026: cloning is hard because of EMV tokenization. So the threat profile has shifted. The newer concern is data correlation: getting card numbers and identifying information that combine with other harvested data for fraud at non-EMV checkpoints, account takeover, and phishing personalization.
For your e-passport: the chip layer at 13.56 MHz contains your name, date of birth, nationality, and biometric face image. A skimmed read does not let someone impersonate you at a border, but it does give a determined attacker a complete identity package linked to a face.
For hotel keycards: these often run on the same 13.56 MHz band but with weaker encryption than payment cards. Captured reads can be replayed in some properties, depending on the lock vendor.
For older proximity ID cards (employee badges, garage access): often weaker, but not relevant to most travelers.
Where it actually happens
Crowded transit, queues at busy attractions, festivals, large markets. Anywhere a hand-held reader can be walked past dozens of bags within a few feet. The criminals are not lone weirdos with antennas. They are organized crews trading captured data wholesale, the same way credit-card numbers have been traded for years.
Industrial-grade skimmers built into payment terminals or hotel checkin devices are also documented in security research. These are stationary, harder to detect, and capture cards held to them for tap-to-pay or tap-to-check-in transactions.
The simple defense
Shielding works. A continuous conductive enclosure cancels the radio field inside before it reaches the card. The card cannot respond to a signal it cannot detect.
That is exactly what every Alpine Rivers® product is designed to do. How RFID Protection Works covers the physics in more detail.
The honest framing in 2026 is this: RFID skimming is no longer the loud headline threat it was in 2015, but it has not gone away. The math has shifted. The fix is the same. Carry your cards inside something that prevents the read, and you remove yourself from one specific category of opportunistic attack while costing yourself nothing in convenience.