LIVE · cybersecurity feed
Live wire
security

Expired credit cards revived by researchers to make unauthorized payments

Gaps in expiry checks could let dead plastic make purchases again

zeroday.news ·

Researchers at the University of Massachusetts Amherst have identified a vulnerability in the EMV contactless payment protocol that could allow expired Visa credit cards to be used for unauthorized transactions. The findings, presented at the USENIX Security 2026 conference, detail how a man-in-the-middle (MitM) attack can bypass expiration date checks for certain contactless Visa cards.

The research paper, "Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments," by Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza, explains that while credit cards have expiration dates, the enforcement of these dates within the EMV contactless protocol is inconsistent. This inconsistency creates an opening for attackers to make expired cards appear valid to point-of-sale (POS) terminals.

The EMV contactless protocol, which governs communication between payment cards (or digital wallets) and POS terminals via NFC, relies on selective authentication. Some transaction data is transmitted in plaintext and is only later linked to cryptographic verification through Offline Data Authentication (ODA) and issuer-verified cryptograms. This design allows for intermediary interference.

The researchers demonstrated that they could use NFC proxy devices to meddle with the transaction flow, specifically targeting Visa contactless transactions. They found that Visa's implementation of the EMV kernel, which processes these transactions, is more permissive than those used by American Express, Discover, and Mastercard.

According to the researchers, the Visa kernel does not cryptographically bind the expiration date. While the POS terminal evaluates processing restrictions based on an "Application Expiration Date," the card issuer relies on an expiration date from a different data field in the online authorization request. The lack of cryptographic binding between these two dates allows an attacker positioned between the card and the terminal to alter the expiration date seen by the terminal without invalidating the card's other security checks.

The success of the attack also depends on how the card issuer handles the transaction. The researchers found that some banks succumbed to the attack, while others did not, indicating varying levels of enforcement at the issuer level. The Wallet Card Transaction Qualifiers settings also play a role, potentially steering transactions toward online authorization checks rather than immediate rejection, shifting the enforcement burden to the card issuer.

Lead author Raja Hasnain Anwar noted that the susceptibility of Visa cards stems from design choices made by different card manufacturers in their contactless transaction protocols. While common messages ensure global acceptance, each manufacturer makes additional design choices, often compromising between backward compatibility with older POS terminals and performance criteria. He explained that although security checks are in place, only a subset may be invoked for faster transactions, creating vulnerabilities.

The researchers stated they notified Visa of their findings in May 2025 and followed up in December 2025. However, neither Visa nor the notified banks have confirmed that the expiration issue has been mitigated. Visa has not publicly commented on the findings.

ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

'CoSnitch' Attack Tricked Copilot into Mapping Out Architecture

Researchers discovered a "meta-hacking" technique that can manipulate the AI service into revealing its own security weaknesses.

security

Comcast turns your Xfinity WiFi into a home motion detector

Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]

aicritical

OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue

The ChatGPT maker says its upcoming Astra model may have reached “critical” cyber capabilities, prompting it to halt a significant number of training runs while it tightens internal safeguards.

CVE-2026-68820high

CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now

Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing the pressure on teams to move quickly from patch availability to verified remediation. Installing [

ransomwarecritical

More than 200 victims of Medusa ransomware identified over the last year, CISA says

The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025.

ransomware

Clop created custom web shell for Windchill data theft attacks

A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]