{
  "id": 1809493,
  "title": "Expired credit cards revived by researchers to make unauthorized payments",
  "url": "https://urgent.news/2026/08/18/expired-credit-cards-revived-by-researchers-to-make-unauthorized-1809493",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-18T20:20:28.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/08/18/expired-credit-cards-revived-by-researchers-to-make-unauthorized-payments/5289229"
  },
  "original_language": "en",
  "account": "Researchers from the University of Massachusetts Amherst have uncovered a method to revive expired contactless credit cards and make unauthorized payments, a discovery presented at the USENIX Security 2026 conference. In their paper titled \"Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments,\" authors Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza detail their findings. Credit cards typically have expiration dates, but the researchers discovered that the way expiration dates are checked and enforced is inconsistent. They devised an attack that makes expired contactless cards appear valid to payment terminals. The Europay, Mastercard, and Visa (EMV) payment process involves a card and a point-of-sale terminal communicating over a direct NFC channel. The EMV contactless protocol, however, is considered fragile due to selectively authenticated transaction flow, which leaves an opening for unwanted interference. The researchers demonstrated that they could meddle with Visa contactless transactions, making them vulnerable to man-in-the-middle tampering due to a lack of effective integrity protection. Visa's kernel allows the point-of-sale terminal to evaluate processing restrictions based on the Application Expiration Date, but the card issuer relies on a different expiration date in the online authorization request. These two dates are not cryptographically bound, allowing the attack to succeed. The researchers' findings show that Visa contactless cards are susceptible to this type of attack, while Mastercard, American Express, and Discover configurations resisted it. The authors notified Visa of their findings in May 2025 and December 2025, but neither Visa nor the banks involved have confirmed that they've addressed the issue.",
  "summary": "Gaps in expiry checks could let dead plastic make purchases again",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Expired credit cards revived by researchers to make unauthorized payments",
        "url": "https://urgent.news/2026/08/18/expired-credit-cards-revived-by-researchers-to-make-unauthorized",
        "published": "2026-08-18T20:20:28.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}