started · updated
University of Massachusetts researchers find security flaw in expired credit cards
Researchers at the University of Massachusetts Amherst have identified a security vulnerability that allows expired contactless credit cards to be used for fraudulent transactions. Dubbed “zombie credit cards,” the exploit targets weaknesses in the near-field communication (NFC) process used for contactless payments.
By using two smartphones acting as NFC proxies, researchers demonstrated a man-in-the-middle attack. One device collects payment information from the expired card, and the information is relayed via Wi-Fi to a second device. This second device modifies the expiration date to a future date before presenting the data to a payment terminal. Because the expiration date stored on the card is not cryptographically protected, some terminals and banks may accept the modified date as genuine.
The study, presented at the USENIX Security 2026 conference, highlights flaws in the EMV payment process. The authors noted that certain data is sent in plaintext, leaving an opening for interference. Specifically, the researchers stated that “Visa contactless transactions are susceptible to man-in-the-middle tampering due to a lack of effective integrity protection.”
Entities
Europay · Mastercard · University of Massachusetts Amherst · Visa