Click2Houston and FOX 26 reported that Leighton Dickson, owner of Leighton’s — House of Lamb and Ramen on Montrose, has absorbed more than $5,000 in tap-to-pay chargebacks since the location opened around Mother’s Day 2026. Click2Houston cites 30 to 45 disputes; FOX 26 cites 30 to 40 totaling $5,000 to $6,000. Guests tapped phones. Cardholders later said they never ate there. The restaurant ate the loss.
This is not a duplicate of WindRelay / SpyNote NFC relay. WindRelay needs a sideloaded Android app that relays a live physical-card tap. Houston’s case is wallet provisioning: a stolen card number (usually from phishing) is added to Apple Pay or another mobile wallet, then used at a real Toast terminal. Houston Public Media recapped the restaurant story in its Aug 28 week-in-review; this post covers the payment and phishing piece only.

Snapshot
| Field | Detail |
|---|---|
| Merchant | Leighton’s — House of Lamb and Ramen, Montrose (leightonshtx.com) |
| Window | Opened ~May 10, 2026; losses reported Aug 25–26, 2026 |
| Loss | $5,000+ across ~30–45 chargebacks |
| POS | Toast (Dickson reviewed tickets with Toast) |
| Vector | Stolen cards loaded onto phones / Apple Pay; dine-in tap |
| CourtListener | 0 matching RECAP dockets for this restaurant or Toast wallet-chargeback claim (searched Aug 30, 2026) |
How the money leaves the restaurant
Intezer’s Mitchem Boles, quoted by Click2Houston, said the usual start is not a POS hack. It is a phishing email or text that harvests card or login data. The thief then adds the card to their phone. The wallet’s biometrics are the thief’s, not the cardholder’s.
| Step | What Houston reporting describes |
|---|---|
| 1. Steal | Phishing / smishing harvests PAN + expiry, or a bank OTP |
| 2. Provision | Card is added to a mobile wallet on the thief’s phone |
| 3. Dine | Expensive tickets (Dickson described lobster and lamb after 10 p.m.) |
| 4. Dispute | Real cardholder files a chargeback; merchant often loses |
FOX 26 quotes Leah Napoliello of the BBB of Greater Houston: digital wallets skip the ID / signature habit many staff still expect with a plastic card, so banks often side with the cardholder unless the merchant can show a physical card and a signature. Dickson’s new house rule: physical card, or tap plus a photo ID that matches the wallet name.
That ID check is a front-of-house control. It does not fix the issuer OTP that approved the wallet in the first place. If your bank texts “enter this code to add your card to Apple Pay” and you read it to a caller or type it on a fake page, the token is already on someone else’s phone.

What to do
Cardholders
- Treat “verify your card” / “add this card to Wallet” mail and texts as hostile. Call the number on the card.
- If you get a bank alert that your card was added to Apple Pay or Google Wallet and you did not do it, call the issuer and ask them to kill the device token (DPAN) and reissue the card.
- Prefer a credit card in wallets over debit when you can — the dispute is the issuer’s float, not your checking account.
Restaurants and other Toast merchants
- Watch chargeback reason codes weekly. Dickson’s Utah-cardholder example is the tell: geography and ticket size that do not match the dining room.
- Keep itemized tickets, table times, and any ID notes. Wallet taps still need a dispute packet.
- Lock Toast Web with an authenticator app (below). Do not share one login across the floor.
- Type toasttab.com/login yourself. Do not open “Toast payout held” mail.
MFA: YubiKey and Google Authenticator
A hardware key on your bank login does not stop a thief who already has a provisioned wallet. It does stop a lot of the phishing that stole the card in the first place. Toast Web is the merchant back office — a stolen Toast login is a different loss (payouts, guest data, refunds).
| Platform | Grade | YubiKey | Authenticator |
|---|---|---|---|
| Toast Web | Pass | No | Yes |
| Apple Account | Strong | Yes | No |
Toast’s MFA article (updated Aug 27, 2026) names Google Authenticator or similar and SMS. MFA is required for 8.1 Financial Accounts, 8.7 Instant Deposits, and some Payroll users. Other users can skip it. MFA does not apply on a Toast POS device. Device biometrics can skip email/password on a trusted browser; Toast says that is not MFA. YubiKey / FIDO and account passkeys are not documented.
Apple Account HT102637 names YubiKey 5C NFC / 5Ci. Google Authenticator is not documented for Apple Account login. Wallet card add is an issuer check (often SMS). A YubiKey on your Apple ID does not approve someone else’s Wallet enrollment.
Directory rows: MFA support directory · filter Category → Business Apps for Toast.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited restaurant, POS, researcher, and wallet-ecosystem hosts on August 30, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not say whether a tap at the counter is the real cardholder.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| Apple | apple.com | 69% | −31 |
| Intezer | intezer.com | 63% | −37 |
| Toast | toasttab.com | 42% | −58 |
| Leighton’s | leightonshtx.com | 33% | −67 |
| Leighton’s order | order.leightonshtx.com | 28% | −72 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| apple.com | 50% | 15% | 98% |
| intezer.com | 75% | 45% | 37% |
| toasttab.com | 25% | 15% | 37% |
| leightonshtx.com | 0% | 15% | 40% |
| order.leightonshtx.com | 0% | 15% | 37% |
Audit links: apple.com · intezer.com · toasttab.com · leightonshtx.com · order.leightonshtx.com
The restaurant marketing host is on Wix with Identity 0% and no MX we could score — easy to impersonate in “Leighton’s reservation / refund” mail. Toast’s login brand is the one staff should type.

Website stack note
Passive website-tech probes on August 30, 2026:
| Domain | Stack signal |
|---|---|
| leightonshtx.com | Wix; Let’s Encrypt TLS expires 2026-10-24 (~54 days) |
| order.leightonshtx.com | Next.js; Phusion Passenger 6.1.8 in X-Powered-By; TLS expires 2026-11-23 |
| toasttab.com | Stack undetected; Amazon Trust TLS expires 2027-01-05 |
| intezer.com | Webflow; GoDaddy TLS expires 2027-01-24 |
| apple.com | Stack undetected; Apple TLS expires 2026-11-05 (~66 days) |
Point-in-time only. A clean Toast website does not make a “held payout” email legitimate.
Blacklist and lookalike domains
Email blacklist checks (public DoH, August 30, 2026): toasttab.com and intezer.com were clear on mail/domain lists we can query. leightonshtx.com has no MX (no_ips); Wix web IPs showed informational SPFBL notes. apple.com inbound MX showed Spamhaus PBL / SPFBL notes — policy-list noise, not a reason to click apple-secure.com mail.
DNS lookalike scans (BEC profile, registered DNS signals only):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| leightonshtx.com | 0 | 0 | 0 |
| toasttab.com | 39 | 1 | 0 |
| apple.com | 84 | 8 | 0 |
High-interest registered names (investigate; not proof this restaurant’s thieves used them):
| Lookalike | Technique | Note |
|---|---|---|
| toasttaab.com / toasttabb.com | insertion / duplication | Live NS + MX |
| toasttab.ai / toasttab.co | tld-swap | Live NS + MX |
| toastab.com | omission | CNAME to www.toasttab.com (likely owned) |
| apple-account.com / apple-secure.com | affix | Live NS + MX |
| applelogin.com | phishing-host | Live NS + MX |
Several apple.* TLD swaps already redirect to Apple. Continuous monitoring: Cybersquat Domain Monitoring.
Related coverage
- WindRelay / SpyNote NFC relay — live card tap via Android malware, not wallet provisioning
- FaceTime bank scam
- National banks MFA — SMS vs YubiKey
- Safe card processing: tokenization vs skimmers
- Memorial Hermann MyChart phishing alert (Aug 21, 2026 — separate Houston phishing wave; not this restaurant)
- MFA support directory
Run a free audit at audit.emailmenow.com or contact EmailMeNow for restaurant email authentication and phishing response aimed at the 100% ideal.
Sources: Click2Houston, Aug 25, 2026 · FOX 26 Houston · Houston Public Media, Aug 28, 2026 · Community Impact — Montrose opening · Toast Set up MFA · Apple security keys. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 30, 2026. Domain scores: audit.emailmenow.com only.