Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 7 sources · 3 days · First seen · Last updated
Visa contactless payment security vulnerability
Overview
Researchers at the University of Massachusetts Amherst have identified a security vulnerability known as the ‘Zombie Card’ attack. This exploit allows expired Visa contactless credit cards to be used for real in-store purchases by utilizing a man-in-the-middle (MitM) relay attack via near-field communication (NFC).
By using two smartphones to create a digital bridge between an expired card and a point-of-sale terminal, attackers can intercept the data exchange and rewrite the expiration date to a current one. The vulnerability exists because the expiration data in certain Visa contactless implementations is not cryptographically bound to the transaction, allowing it to be modified without detection.
While testing showed that major networks such as Mastercard, American Express, and Discover were resistant, the flaw specifically impacts Visa contactless (Kernel 3) implementations. The researchers noted that while some banks detected the modification, others accepted the altered dates and allowed transactions to proceed.
Entities
Visa · University of Massachusetts Amherst · Mastercard · USENIX Security Symposium · Discover
Timeline
-
1 day ago
[TECHNOLOGY] 3 sourcesUniversity of Massachusetts Amherst researchers find security flaw in expired bank cardsUniversity of Massachusetts Amherst researchers discovered a ‘Zombie Card’ vulnerability that allows expired contactless bank cards to be manipulated and reused for fraudulent payments.
-
4 days ago
[TECHNOLOGY] 4 sourcesUniversity of Massachusetts researchers reveal Zombie Card contactless payment exploitResearchers have demonstrated a “Zombie Card” attack that uses NFC relay technology to revive expired Visa contactless cards for unauthorized in-store purchases by manipulating expiration date data.
Sources
168.hu · chip.com.tr · cybernoz.com · divany.hu · frisss.hu · wzzk.com · yenialanya.com