Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [incident, contactless, payment-fraud, research, visa, nfc] ยท confidence: medium ยท affected_sectors: [finance, retail, technology] ยท au_impact: false

"Zombie Card" Attack Can Revive Expired Visa Cards For Contactless Payments

Researchers at the University of Massachusetts Amherst demonstrated an attack that revives expired Visa contactless cards at real point-of-sale terminals by rewriting the expiry date the terminal reads over near-field communication (NFC), without breaking any of the card's cryptography.

Key Facts

Field Detail
Attack type Expired-card revival via NFC expiry-date rewrite
Requirements Cardholder in physical possession of (or near) the expired card; man-in-the-middle relay between card and terminal; account open under the same PAN; bank does not re-check expiration during authorisation
Impact Transactions succeeded at most of the five large US banks tested
Related mechanism CDCVM-flag tampering (same undetected-transaction weakness)
Status Academic research; no known live abuse reported

Significance

The demonstration is a reminder that account-to-card state, not cryptography alone, is carrying contactless payment security. The researchers tied the same weakness to CDCVM-flag tampering. Stolen or unreported expired cards remain usable at the point of sale until banks and networks verify card state at the terminal.

Source