type: incident ยท created: 2026-08-21 ยท updated: 2026-08-21 ยท tags: [incident, contactless, payment-fraud, research, visa, nfc] ยท confidence: medium ยท affected_sectors: [finance, retail, technology] ยท au_impact: false
"Zombie Card" Attack Can Revive Expired Visa Cards For Contactless Payments
Researchers at the University of Massachusetts Amherst demonstrated an attack that revives expired Visa contactless cards at real point-of-sale terminals by rewriting the expiry date the terminal reads over near-field communication (NFC), without breaking any of the card's cryptography.
Key Facts
| Field | Detail |
|---|---|
| Attack type | Expired-card revival via NFC expiry-date rewrite |
| Requirements | Cardholder in physical possession of (or near) the expired card; man-in-the-middle relay between card and terminal; account open under the same PAN; bank does not re-check expiration during authorisation |
| Impact | Transactions succeeded at most of the five large US banks tested |
| Related mechanism | CDCVM-flag tampering (same undetected-transaction weakness) |
| Status | Academic research; no known live abuse reported |
Significance
The demonstration is a reminder that account-to-card state, not cryptography alone, is carrying contactless payment security. The researchers tied the same weakness to CDCVM-flag tampering. Stolen or unreported expired cards remain usable at the point of sale until banks and networks verify card state at the terminal.