Feeds2.Feedburner
Zombie Card Attack Revives Expired Credit Cards for Unauthorized Payments
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Researchers from the University of Massachusetts Amherst have demonstrated a method to exploit expired contactless credit cards, allowing unauthorized payments. This vulnerability, presented at the USENIX Security 2026 conference, reveals that certain Visa cards can be manipulated to appear valid past their expiration dates. The attack leverages weaknesses in the EMV contactless payment protocol, specifically the lack of cryptographic binding between expiration dates and transaction authorizations. The researchers showed that by using NFC proxy devices, they could successfully execute transactions with expired cards. While Mastercard, American Express, and Discover configurations resisted the attack, Visa cards were particularly vulnerable. This finding raises concerns about the security of contactless payment systems and the handling of expired cards by consumers. The researchers emphasize the need for improved security measures in payment processing to prevent such exploits.
Key Points: • Expired Visa contactless cards can be exploited for unauthorized payments. • The attack relies on weaknesses in the EMV payment protocol's expiration date checks. • Mastercard, American Express, and Discover cards were not affected by this vulnerability.