started · updated
University of Massachusetts Amherst researchers find security flaw in expired bank cards
Researchers at the University of Massachusetts Amherst have identified a security vulnerability dubbed the ‘Zombie Card’ attack, which allows certain expired contactless bank cards to be reused for payments.
The vulnerability stems from the fact that a physical card's expiration date and the underlying bank account or card relationship do not always expire simultaneously. Using everyday NFC-enabled devices and simple software, researchers demonstrated that they could intercept data from an expired card and modify the expiration date sent to a payment terminal. By presenting a future date to the terminal while using the original card's authentication data, they were able to successfully complete transactions.
The study found that the expiration date lacks sufficient end-to-end cryptographic protection in some instances, and banks may sometimes rely on the terminal's decision without verifying the physical card's current validity. While the researchers tested various systems including Mastercard, Discover, and American Express, the successful ‘Zombie Card’ attack was specifically demonstrated on a version of the Visa contactless payment system.
Entities
American Express · Discover · Mastercard · University of Massachusetts Amherst · Visa