RFID Skimming and Blocking: Should Your Employee and Access Cards Carry Protection?

You rolled out contactless access badges because they are fast and convenient — a tap at the reader, no fumbling for a magstripe. But a reader in the wrong hands can also read or clone a card from a distance you never intended. Walk any trade-show floor, or search “RFID-blocking wallet,” and you will find a wall of products promising to shield your credentials. The real question for a security manager is narrower: is the skimming threat to your employee and access cards genuine, and do RFID blocking cards and sleeves actually reduce it — or are you buying peace of mind while the real weakness sits elsewhere?

This guide separates the verified risk from the marketing. It shows which card technologies are actually cloneable, explains what RFID-blocking products can and cannot do, and gives you a pragmatic control plan you can act on this quarter — without wrapping every badge in foil.

What contactless skimming actually is (and what it is not)

Skimming is the silent reading of a card’s data by a covert reader held close to the card. For the 13.56 MHz high-frequency cards used in most modern access systems — standardised as ISO/IEC 14443 — that range is typically a few centimetres; for older low-frequency 125 kHz proximity it can be a little further. Cloning then writes that captured data onto a blank card. The two steps are often conflated, but they are different, and the second step is where the real barrier sits.

A more sophisticated variant is the relay attack: two devices, one near the card and one near the legitimate reader, extend the conversation so the reader believes the card is present. A blocking sleeve does nothing against a relay attack, because the card is read while it is being used normally — not while it rests in a wallet.

The point worth memorising: reading a card’s serial number (UID) is trivial, but the UID alone is rarely enough to clone a secure credential. Whether a card can be cloned is decided by its chip generation and key management, not by whether someone can brush past it with a reader. For the underlying contactless technologies, see our explainer on RFID vs NFC vs BLE on the smart card.

A contactless smart card being read by a handheld device in the field
A contactless credential being interrogated at close range — the scenario every “RFID blocking” product is built to defeat.

Which cards are actually at risk

Not all contactless cards are equal, and frequency is a poor proxy for risk. The deciding factors are the chip family and whether the data is protected by mutual authentication and diversified keys.

  • 125 kHz proximity (HID Prox, EM4100 and similar): a fixed, unencrypted ID with no cryptography. It is trivially cloneable with inexpensive hardware and remains widespread in older North American installs. This is the highest-risk format still in service.
  • MIFARE Classic: its CRYPTO1 cipher was broken in 2008, and credentials can be cloned with modest effort. It still appears in many legacy systems — a real, exploitable exposure rather than a theoretical one.
  • MIFARE DESFire EV1/EV2/EV3, MIFARE Plus (SL3), HID Seos, iCLASS: mutual authentication with diversified, per-card keys. Reading or cloning the useful data requires the secret keys, which are not recoverable from a casual skim. Practical risk is low.
An HID 125 kHz proximity card, the most cloneable legacy access credential
A 125 kHz proximity card — fixed-ID and unencrypted, which is exactly why it tops the cloning-risk list.

The takeaway is uncomfortable for anyone who bought “RFID” as a single category: a card’s chip generation — not its frequency — decides whether it can be cloned. A 13.56 MHz DESFire card is far safer than a 125 kHz prox card, even though both are “contactless.” If you are still running Classic or prox, our MIFARE Classic to DESFire migration playbook lays out the staged path off them.

What RFID-blocking products do (and where they stop)

A blocking sleeve or wallet is essentially a Faraday cage: a thin metalised layer that attenuates the radio field so a reader cannot power and interrogate the card inside. A well-made sleeve tuned to 13.56 MHz (and/or 125 kHz) genuinely prevents a casual close-range skim of a card at rest. Independent tests of quality sleeves show field attenuation of 30–40 dB — enough to defeat an opportunistic reader.

A “blocking card” that you drop into a wallet alongside your credentials works differently: it tries to jam the channel with noise. It is less reliable and easier to defeat, and we do not recommend it as a primary control.

Understand the limits. Blocking helps only against an opportunistic read of a card sitting in a pocket or on a desk. It does not stop a relay attack, and a blocked card is also unusable until you take it out — so you are trading everyday convenience for a narrow, tactical control. Treat blocking as a band-aid, not a security architecture.

When blocking protection is genuinely warranted

There are clear cases where a shielded sleeve is a sensible, low-cost measure:

  • You still run 125 kHz prox or MIFARE Classic. These are cloneable today. Issuing sleeves to at-risk holders is a cheap risk reducer while you migrate to a secure chip.
  • High-value targets: executives, data-centre access, or anyone whose card also carries a payment application. The incremental friction is justified by the consequence of compromise.
  • A transition window: whenever you are mid-migration and legacy cards are still live, sleeves are a reasonable interim control.
A batch of employee ID badges being reviewed during procurement
Employee badges are the credentials most often wrapped in blocking sleeves during a security upgrade — sensible only while legacy chips remain live.

The strategic fix, however, is not the sleeve. It is upgrading the credential to a secure chip with mutual authentication and diversified keys, then pairing it with encrypted readers. Blocking buys you time; it does not buy you safety.

When blocking is over-engineering

If your cards are already on a secure platform, blocking often adds cost and friction with little security gain:

  • DESFire / Seos with diversified keys + OSDP readers: a casual skim yields nothing usable, so sleeves mostly protect against a threat that does not exist for your stack.
  • Insider or relay threats: if an attacker can coerce or observe a legitimate presentation, a sleeve changes nothing.
  • Lost-card friction: sleeves get forgotten, left behind, or cause failed reads at the turnstile — eroding the very convenience that justified contactless in the first place.
A modern high-durability contactless smart card
A modern secure contactless card — already resistant to casual skimming, so a sleeve adds friction without reducing real risk.

The risk here is subtle: letting sleeve-buying stand in for a credential-security roadmap. A drawer full of shielded wallets can look like a programme while the underlying chips remain cloneable. For the temporary-credential side of the same problem, our visitor and contractor badge guide covers expiry and reclaim controls.

A pragmatic control plan for a skim-resistant program

You do not need to choose between “do nothing” and “shield everything.” A staged plan gets you there:

  • Inventory the technologies in use. Read the chip type on every credential family you issue; you cannot protect what you have not classified.
  • Retire cloneable formats. Phase out 125 kHz-only and MIFARE Classic; migrate to MIFARE DESFire EV3 or HID Seos with key diversification.
  • Upgrade the readers to OSDP. Encrypted, bidirectional OSDP readers replace unencrypted Wiegand and stop credentials being intercepted on the wire. Our OSDP vs Wiegand breakdown shows why this matters.
  • Bridge the gap with sleeves. For the transition window, issue shielded sleeves to the highest-risk holders only — not the whole population.
  • Run the policy basics. Disable lost cards within an SLA, rehearse revocation, and consider mobile or biometric credentials for the most sensitive roles.
A secure ID card production line inside a factory
A credential program is only as strong as the cards and readers you actually deploy — build the upgrade, then bridge with sleeves.

If you are unsure which chips your current badges use, we can audit a sample set and map a migration path. Request a credential review and we will send a prepaid sample envelope.

Frequently asked questions

Can a phone skim my access card?

An NFC phone can read the public data (including the UID) of an ISO/IEC 14443 card at close range, but it cannot clone a secure credential that uses mutual authentication and diversified keys. The phone is a reader, not a cloner. Background on the standard is at ISO/IEC 14443 and NFC Forum.

Do RFID-blocking wallets actually work?

A correctly tuned Faraday sleeve works against the frequency it targets. Independent tests show quality sleeves attenuate the field by 30–40 dB. Cheap or worn sleeves may leak — verify, do not assume.

Is my contactless payment card at risk too?

Contactless payment uses the same 13.56 MHz physics, but issuers layer risk controls — transaction limits, behavioural scoring, liability shift — that access systems usually lack. Different vector, different backstop; see EMVCo for the payment-side specs.

Will a blocking sleeve stop a relay attack?

No. A relay attack reads the card while it is being used normally, so the sleeve is irrelevant. The defence is a secure, proximity-bound credential plus reader-side controls. Credential management guidance from NIST SP 800-116 Rev.1 is a useful reference.

Should I shield all employee cards?

Only legacy (125 kHz / MIFARE Classic) or high-value cards warrant it. For modern secure chips, invest in the chip and reader upgrade instead of sleeves. For phishing-resistant options beyond the card, the FIDO Alliance tracks standards worth watching.

Skimming is a real risk for the wrong card technology — and a non-event for the right one. The fastest way to find out which camp you are in is a credential audit. Contact our team for a sample review and migration plan, or start the upgrade now with our OSDP vs Wiegand and MIFARE Classic to DESFire guides.

Table of Contents

This is the heading

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.

Scroll to Top
Request A Qute