Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zombie Card Technique Revives Expired Visa Cards

Zombie Card Technique Revives Expired Visa Cards

Posted on August 20, 2026 By CWS

Researchers at the University of Massachusetts Amherst have revealed a novel method, termed the ‘Zombie Card’ attack, which allows expired Visa contactless cards to be used for transactions. This technique involves altering the expiration date read by point-of-sale (POS) terminals via near-field communication (NFC), all without compromising the card’s underlying cryptographic protections.

Mechanics of the Zombie Card Attack

The attack necessitates physical access to the expired card or a sustained NFC connection to it. A man-in-the-middle (MitM) relay device is employed between the card and the terminal to modify the expiration date information. For this attack to succeed, the account must remain active with the same primary account number (PAN), which is typical when banks issue replacement cards. Additionally, the issuing bank must not verify the expiration date during the transaction authorization process.

In their study, the researchers evaluated the attack across five major US banks. They found that one bank’s system approved transactions with revived cards, while another rejected all attempts. A different Europay, Mastercard, and Visa (EMV) kernel used by a third bank failed to process the modified transactions altogether.

Security Symposium and Industry Response

The findings were shared at the 35th USENIX Security Symposium held in Baltimore in August 2026. The research team, comprising Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza, disclosed their results to Visa and the affected banks in May 2025, with a follow-up in December 2025. As of the latest update, no Common Vulnerabilities and Exposures (CVE) identifier has been assigned, and there have been no reports of the technique being exploited in the wild.

The researchers noted the absence of any advisory or mitigation guidance concerning this vulnerability from Visa, EMVCo, Mastercard, Discover, American Express, or terminal vendor SumUp as of August 2026.

Technical Details and Mitigation Strategies

Visa contactless transactions involve two separate expiration date representations, which are processed by different systems. The terminal uses the Application Expiration Date, while the issuer assesses the expiry based on Track 2 Equivalent Data. Visa’s Kernel 3 does not require these dates to be consistently linked, allowing the attack to succeed by altering only the terminal-facing date.

The researchers propose several countermeasures, including cryptographically binding expiration-critical data and ensuring that terminal validation results are communicated to issuers. They also suggest that issuers should treat the expiration date as part of the credential identity, declining transactions where the date does not match the valid credential for the PAN.

Future Implications and Industry Developments

The Zombie Card attack underscores the complexities of maintaining security in contactless payment systems. While researchers have not released the MitM implementation, sanitized transaction logs have been made available, highlighting the need for caution in disseminating potentially harmful techniques.

Concurrently, Group-IB has identified a new Android NFC relay malware named WindRelay, which operates similarly by relaying active card data in real-time without altering expiration dates. This development emphasizes the evolving nature of fraud techniques in the digital payment landscape.

The Hacker News Tags:bank security, card data security, contactless payment, contactless transactions, credit card security, Cybersecurity, expiration date, financial technology, fraud prevention, NFC, relay attack, University of Massachusetts, USENIX Security Symposium, Visa cards, Zombie Card

Post navigation

Previous Post: Cisco Patches Critical XML Vulnerability in BroadWorks
Next Post: Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia

Related Posts

Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs Chainlit AI Framework Flaws Enable Data Theft via File Read and SSRF Bugs The Hacker News
UNG0002 Group Hits China, Hong Kong, Pakistan Using LNK Files and RATs in Twin Campaigns UNG0002 Group Hits China, Hong Kong, Pakistan Using LNK Files and RATs in Twin Campaigns The Hacker News
MintsLoader Drops GhostWeaver via Phishing, ClickFix — Uses DGA, TLS for Stealth Attacks MintsLoader Drops GhostWeaver via Phishing, ClickFix — Uses DGA, TLS for Stealth Attacks The Hacker News
GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies The Hacker News
Dynamic PDF Phishing Threatens Latin America and Europe Dynamic PDF Phishing Threatens Latin America and Europe The Hacker News
New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login New Oracle E-Business Suite Bug Could Let Hackers Access Data Without Login The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OpenAI Pauses AI Training Over Cybersecurity Concerns
  • Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia
  • Zombie Card Technique Revives Expired Visa Cards
  • Cisco Patches Critical XML Vulnerability in BroadWorks
  • MLflow Flaw Exploited for Credential Theft in Cloud

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OpenAI Pauses AI Training Over Cybersecurity Concerns
  • Massive Camera Hack Hits 14,000 Devices in Ukraine and Russia
  • Zombie Card Technique Revives Expired Visa Cards
  • Cisco Patches Critical XML Vulnerability in BroadWorks
  • MLflow Flaw Exploited for Credential Theft in Cloud

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark