Get the latest tech news
Japan's IC cards are weird and wonderful
Exploring what makes Japan's transit cards so unique compared to the West.
I could find barely any info on successful attacks on FeliCa outside of a single paper detailing a bug exploited by a cashier, which was caught anyway by audit logs and HK Octopus cards' clearing house system. The only real concern I've seen brought up is the fact that the crypto is proprietary, and probably buried underneath a mountain of NDAs, so the public can't audit it independently. Card charging machines and station gates may be viable to some kind of attack, but even if you could pull one off, they (probably) send transaction logs to a central audit server somewhere, and your misdeeds will be easily flagged as an anomaly.
Or read this on Hacker News