Expired Visa Cards Can Be 'Zombified' for Contactless Fraud

Original: Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

Why This Matters

The flaw exposes a systemic gap in contactless payment security affecting millions of expired Visa cards globally.

Researchers at UMass Amherst revealed at Usenix Cybersecurity Conference that expired Visa cards can be exploited via a man-in-the-middle app proxying card data between two phones, bypassing expiration checks due to flaws in Visa's contactless payment authentication chain.

Researchers at the University of Massachusetts Amherst presented findings at the Usenix Cybersecurity Conference showing that expired Visa credit cards can be 'zombified' to make contactless payments. The attack works by proxying the expired card's NFC data through a man-in-the-middle application that relays signals between two smartphones, effectively tricking payment terminals into accepting the card.

The core vulnerability lies in how Visa handles expiration authentication in its contactless payment protocol. Rather than enforcing expiration checks itself, Visa delegates authentication responsibility to individual card-issuing banks. While some banks successfully block these transactions, others do not, leaving a gap that fraudsters can exploit.

The practical threat: a bad actor could retrieve a discarded or found expired Visa card and use it to make unauthorized purchases from the original cardholder's account. Visa did not respond to requests for comment from The Register, which first reported on the research. The researchers' findings highlight inconsistencies in the contactless payment security chain that affect consumers even after a card's official expiration date.

Source

wired.com — Read original →