Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
2 clusters · 6 sources · 1 days · First seen · Last updated
Contactless credit card security vulnerabilities
Overview
Researchers at the University of Massachusetts Amherst have identified a security vulnerability involving expired contactless credit cards, which they have termed “zombie credit cards.”
Presented at the USENIX Security 2026 conference, the study demonstrates a man-in-the-middle attack using two smartphones acting as NFC proxies. One device collects payment information from an expired card and relays it via Wi-Fi to a second device, which modifies the expiration date to a future date. Because certain data is sent in plaintext and the expiration date is not cryptographically protected, some payment terminals and banks may accept the modified information as genuine.
Researchers noted that “Visa contactless transactions are susceptible to man-in-the-middle tampering due to a lack of effective integrity protection,” highlighting specific flaws in the EMV payment process.
Entities
University of Massachusetts Amherst · Visa · Europay · Mastercard · Simula Research Laboratory
Timeline
-
9 days ago
[TECHNOLOGY] 2 sourcesCybersecurity research identifies governance gaps and credit card vulnerabilitiesResearch reveals a gap in corporate digital security oversight and demonstrates how 'zombie' credit cards can be exploited via NFC technology to bypass expiration dates.
-
9 days ago
[TECHNOLOGY] 4 sourcesUniversity of Massachusetts researchers find security flaw in expired credit cardsUniversity of Massachusetts Amherst researchers discovered a way to revive expired contactless credit cards for fraudulent payments using a man-in-the-middle NFC attack.
Sources
blogspan.net · cybersecuritynews.com · kapool.com · knowridge.com · nordnesrepublikken.no · theregister.co.uk