Zombie Card Attack Revives Expired Credit Cards for Unauthorized Payments

Zombie Card Attack Revives Expired Credit Cards for Unauthorized Payments

First seen 20 Aug 2026, 07:13 UTC TheregisterFeeds2.Feedburner 81% similarity 64.5

Article Content

Browse articles
ThreatCluster

Researchers from the University of Massachusetts Amherst have demonstrated a method to exploit expired contactless credit cards, allowing unauthorized payments. This vulnerability, presented at the USENIX Security 2026 conference, reveals that certain Visa cards can be manipulated to appear valid past their expiration dates. The attack leverages weaknesses in the EMV contactless payment protocol, specifically the lack of cryptographic binding between expiration dates and transaction authorizations. The researchers showed that by using NFC proxy devices, they could successfully execute transactions with expired cards. While Mastercard, American Express, and Discover configurations resisted the attack, Visa cards were particularly vulnerable. This finding raises concerns about the security of contactless payment systems and the handling of expired cards by consumers. The researchers emphasize the need for improved security measures in payment processing to prevent such exploits.

Key Points: • Expired Visa contactless cards can be exploited for unauthorized payments. • The attack relies on weaknesses in the EMV payment protocol's expiration date checks. • Mastercard, American Express, and Discover cards were not affected by this vulnerability.

ThreatCluster AI How this analysis works

Timeline

2026-08-18
Research findings presented at USENIX Security 2026
UMass Amherst researchers revealed a method to exploit expired Visa contactless cards, allowing unauthorized transactions.
Theregister
2026-08-20
Media coverage of Zombie Card attack
Various outlets reported on the Zombie Card attack, highlighting the implications for expired credit card security.
Feeds2.Feedburner

Community

Browse all →

Tracked Entities in This Story