Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Expired Visa Cards Vulnerable to Contactless Payment Hack

Expired Visa Cards Vulnerable to Contactless Payment Hack

Posted on August 20, 2026 By CWS

Recent research has unveiled a significant vulnerability in expired Visa credit cards that allows them to still process contactless transactions. This discovery was made by a team from the University of Massachusetts Amherst and was presented at the 35th USENIX Security Symposium. The study details how a near-field communication (NFC) relay attack, named ‘Zombie Card,’ can enable contactless payments with expired cards.

Understanding the EMV Contactless Payment Flaw

The vulnerability arises from how EMV contactless payments handle card expiration. Unlike what many might believe, the expiration check is not cryptographically enforced on the card itself. Instead, it is a transaction policy check performed by the terminal. This means that the expiry data is read and validated locally, leaving room for manipulation.

Private keys in the card’s chip do not expire, and certificates used for card authentication remain valid beyond the printed expiration date. The expiry is determined by the Application Expiration Date field, which is checked in plaintext by the terminal.

How the Zombie Card Attack Works

Researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza demonstrated the attack using two NFC-enabled Android phones. One phone emulates the card at the point-of-sale (POS) terminal, while the other emulates the terminal near the physical card, communicating over Wi-Fi. This setup allows the interception and rewriting of Application Protocol Data Units (APDUs) during the transaction in real-time.

Their tests across various EMV kernels showed that most detected tampering through cryptographic means, except for Kernel 3, used by Visa. This kernel’s expiration field isn’t part of the signed data, allowing an expired date to be changed to a future date without triggering security alerts.

Implications and Proposed Solutions

The research highlighted that some banks unknowingly processed these ‘zombie transactions,’ with one bank approving payments up to $500 as long as the account and cryptogram were valid. The researchers suggested several countermeasures, such as binding expiry data to signed records and ensuring consistency checks between terminal and issuer data.

They disclosed their findings to Visa and affected banks in May 2025. However, as of the time of their report, no fixes had been confirmed. Cardholders are advised to destroy expired cards completely to prevent misuse.

While the industry works towards systemic changes, individuals should remain vigilant and follow recommended practices to safeguard against potential fraud arising from this vulnerability.

Cyber Security News Tags:Banking, contactless payment, credit card, Cybersecurity, EMV, expired cards, fraud prevention, NFC relay attack, payment security, payment system, research study, security flaw, transaction security, USENIX Symposium, Visa

Post navigation

Previous Post: T-Mobile Cuts Cable to Halt Chinese Cyberattack
Next Post: NASA’s AIT-GUI Vulnerabilities Pose Severe Security Risks

Related Posts

India Cracks Down on Apps Disabling E-Rickshaws India Cracks Down on Apps Disabling E-Rickshaws Cyber Security News
Microsoft Urges OEM Manufacturers to Fix Windows 11 USB-C Notification Issues Microsoft Urges OEM Manufacturers to Fix Windows 11 USB-C Notification Issues Cyber Security News
AI-Based Obfuscated Malicious Apps Evading AV Detection to Deploy Malicious Payload AI-Based Obfuscated Malicious Apps Evading AV Detection to Deploy Malicious Payload Cyber Security News
Laravel APP_KEY Vulnerability Allows Remote Code Execution Laravel APP_KEY Vulnerability Allows Remote Code Execution Cyber Security News
Open Source Firewall OPNsense 25.7.11 Released With Host Discovery Service Open Source Firewall OPNsense 25.7.11 Released With Host Discovery Service Cyber Security News
Malicious Streaming App Threatens Android Devices Malicious Streaming App Threatens Android Devices Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Trump Appoints Clayton to Lead Federal AI Task Force
  • South Korea Initiates Security Overhaul After Bank Data Breaches
  • China-Linked TA419 Targets U.S. AI Experts with Phishing
  • Key Arrest in ShinyHunters Case Aids FBI Investigation
  • Vercel Unveils KVM Zero-Day Flaw, Rewards Researcher $50K

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark