Are NFC Business Cards Safe? A Straight Answer, With Sources

Short answer: yes — with one real caveat that almost nobody writing about this mentions.

An NFC business card is safer than most people assume, and the reason is boring: there is almost nothing on it to steal. But there is one genuine risk, and it has nothing to do with someone secretly reading your card from across a room. Here is the honest version, with the sources, so you can check it rather than take our word for it.

What is actually stored on the chip

A passive NFC tag in a business card holds one thing: a short record containing a web address. Your phone number, your title, your company and your socials are not on the chip. They live at the other end of that link.

The chip is tiny by design. A common tag used for this — the NTAG213 family — has 144 bytes of user memory. That is roughly the length of this sentence. There is no room for a contact database, and no attempt to store one. The format is a standard NDEF record holding a URI, which is what both iPhone and Android are looking for when they read a tag (NXP datasheet, Android developer docs).

It also has no battery. The chip is powered by the phone's own radio field for the fraction of a second it is near — the datasheet is explicit that the field is used “both [for] communication and as power supply for the tag.” A card sitting in your wallet is completely inert.

What an NFC business card cannot do

Worth stating plainly, because the unstated version is where the fear comes from:

  • It cannot be read from across a room. The NFC Forum's current specification sets the certified operating volume at 2 cm (NFC Forum, Release 15). NIST puts the practical range of this class of system at roughly 7–15 cm (NIST SP 800-98). Either way: near-contact, not across a table.
  • It cannot read anything off the other person's phone. The traffic goes one way. The tag hands over a link; it receives nothing.
  • It cannot install anything. A link is a link. Nothing runs, nothing downloads.
  • It cannot save itself to their contacts. The other person decides what to save, every time.
  • It cannot know who tapped it. More on that below.
  • It cannot hold your payment details, because it holds a URL and nothing else.

Your phone already asks before it opens anything

This is the part that does most of the security work, and it is worth knowing exactly how it behaves.

On iPhone, Apple's documentation is unambiguous: the system shows a notification when it reads a tag, and “after the user taps the notification, the system delivers the tag data.” If the phone is locked, it prompts you to unlock first (Apple developer docs). Nothing opens on its own.

On Android, the phone looks for tags when the screen is unlocked. This behavior recently changed in a way that is worth knowing: from Android 16, a tag holding a web link triggers a standard view action rather than the older tag intent, and from Android 17 the system “surfaces an ‘open link’ notification, requiring explicit user interaction” before anything opens (Android developer docs). In other words, both platforms now work the same way: a tag can only ever suggest a link. A person has to tap it.

The one real risk

Here it is, and it is not the one people worry about.

A tag that has not been locked can be rewritten — with an ordinary phone and a free app. NXP's datasheet is blunt about it: pages that are not locked “can be reprogrammed using any write command.” That means an unlocked card left unattended could be pointed somewhere else, or physically swapped for a different card, and the next person to tap it would be sent to a URL you never chose.

This is a documented threat, not a hypothetical. NIST's Mobile Threat Catalogue carries a dedicated entry for it — LPN-13, “Malicious NFC tags” — describing tags “that redirect the user to a malicious website,” and listing the countermeasure directly: require explicit user confirmation before following a URL. Security researchers have demonstrated the same idea with tags embedded in everyday objects (“Trojan of Things”, 2017), and Kaspersky flagged reprogramming of legitimate tags left unlocked as a live phishing route in April 2025.

The fix is one thing: the tag should be locked. Locking sets the record permanently read-only — the datasheet notes the process “is irreversible.” It does not hide the link, and it is not supposed to: a business card is meant to be read by anyone who taps it. It just means nobody can change where it points.

If you are buying an NFC card of any kind, that is the question worth asking: is the tag locked? It matters more than the material, the finish, or the app.

This is not the same thing as payment card skimming

These two get blended together constantly, and they are genuinely different technologies.

A contactless payment card runs a cryptographic challenge–response. EMVCo's own documentation describes a fresh, transaction-unique cryptogram generated on every tap, specifically so a captured exchange cannot be replayed onto a counterfeit card. That protection exists because there is something worth protecting.

A business card tag has none of that, and needs none of it: a read command returns the same public link to any reader, every time. There is no secret to intercept. “Someone might skim my NFC business card” describes an attack with no prize — they would obtain a web address that you hand to strangers on purpose.

Warnings you may have seen from consumer-protection bodies about “ghost tapping” are about payment cards and wallets. They are real, and they are a different subject.

Can it be cloned?

Copied, yes — in the sense that anyone can read a public link and write it onto another tag. That gets them a second card pointing at your page, which is the same thing they would achieve by writing your web address on a sticker.

What they cannot do is change your card if it is locked, or take over the page it points to. The chip's serial number is set at the factory and is not writable through the normal command set, and some tags additionally support a cryptographic originality signature. The thing worth protecting was never the chip — it is the account behind the link.

Does it track the person who taps it?

No, and it is worth being precise about what a tap does reveal.

Opening a link — any link, from a tap, a QR code, or a text message — means the destination server sees the visitor's IP address, their browser's user-agent string, and the time of the request. That is how the web has always worked, and modern browsers deliberately send a reduced, generic user-agent to limit exactly this kind of fingerprinting.

None of that is identity. It does not produce a name, a phone number, or a face. Knowing that “someone on a mobile browser opened the page at 4:12pm” is not knowing who they are. Anyone claiming a tap tells you who tapped is describing something the technology does not do.

How to sanity-check a card you have been handed

  • Look at the link before you tap it. Both platforms now show you the URL in a notification first. Read it.
  • Be more careful with tags in public places — a sticker on a poster, a table, a display — than with a card handed to you by a person. The unattended ones are the ones that can be swapped.
  • You can turn NFC off. On Android it is a settings toggle. On iPhone, background tag reading only runs when the phone is unlocked and awake anyway.
  • Nothing should ever install. If tapping something tries to make you download a file, close it.

How AirLnk handles this

The AirLnk Smart Card and the AirLnk Smart Wristband — a woven fabric band with a stitched NFC patch, not silicone — both carry a locked tag pointing at your AirLnk profile. You change what the profile shows, in the free app, whenever you like. The link on the product never changes, which is the whole point: the physical object stays correct forever, and it cannot be repointed at something you did not choose.

Nothing installs on the other person's phone. They see your profile in their own browser and decide what to save. If their phone has no NFC, or has it turned off, every AirLnk includes a QR-code backup — which is also why we do not claim it works with every phone on earth. It does not, and no NFC product does.

If you want the mechanics of the tap itself, we wrote the full explanation here. If you are still deciding whether to move off paper at all, the honest comparison is here.

Common questions

Can someone steal my information by walking past me?
No. The certified operating range is about 2 cm, and the chip holds a public web address, not your details.

Can an NFC business card give my phone a virus?
No. It hands over a link. Nothing installs, and both iPhone and Android now require you to tap a notification before the link even opens.

Is it the same as someone skimming my credit card?
No. Contactless payment uses a fresh cryptogram on every tap because there is something secret to protect. A business card tag has no secret — the link is public by design.

What is the actual risk, then?
An unlocked tag can be rewritten, or a card swapped for another one, so it points somewhere you did not choose. Locking the tag prevents it permanently.

Does it work if my phone is locked?
No. Both platforms require the phone to be unlocked and awake, and both ask you before opening anything.

Can I turn NFC off?
Yes, on both platforms.

Does the other person need an app?
No. Your profile opens in their browser and they choose what to save.

See the wristband and the card →

Back to blog