< Back to situations

Monitor this situation.

[SITUATION] · [QUIET] · [TECHNOLOGY]

2 clusters · 6 sources · 1 days · First seen · Last updated

Contactless credit card security vulnerabilities

Overview

Researchers at the University of Massachusetts Amherst have identified a security vulnerability involving expired contactless credit cards, which they have termed “zombie credit cards.”

Presented at the USENIX Security 2026 conference, the study demonstrates a man-in-the-middle attack using two smartphones acting as NFC proxies. One device collects payment information from an expired card and relays it via Wi-Fi to a second device, which modifies the expiration date to a future date. Because certain data is sent in plaintext and the expiration date is not cryptographically protected, some payment terminals and banks may accept the modified information as genuine.

Researchers noted that “Visa contactless transactions are susceptible to man-in-the-middle tampering due to a lack of effective integrity protection,” highlighting specific flaws in the EMV payment process.

Entities

University of Massachusetts Amherst · Visa · Europay · Mastercard · Simula Research Laboratory

Timeline

  1. 9 days ago

    [TECHNOLOGY] 2 sources
    Cybersecurity research identifies governance gaps and credit card vulnerabilities

    Research reveals a gap in corporate digital security oversight and demonstrates how 'zombie' credit cards can be exploited via NFC technology to bypass expiration dates.

  2. 9 days ago

    [TECHNOLOGY] 4 sources
    University of Massachusetts researchers find security flaw in expired credit cards

    University of Massachusetts Amherst researchers discovered a way to revive expired contactless credit cards for fraudulent payments using a man-in-the-middle NFC attack.

Sources

blogspan.net · cybersecuritynews.com · kapool.com · knowridge.com · nordnesrepublikken.no · theregister.co.uk