{
  "id": 2314711,
  "title": "Expired Visa cards exposed by contactless payment flaw",
  "url": "https://urgent.news/2026/08/21/expired-visa-cards-exposed-by-contactless-payment-flaw",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-21T05:10:52.000Z",
  "source": {
    "name": "Arabian Post",
    "slug": "arabian-post",
    "url": "https://thearabianpost.com/expired-visa-cards-exposed-by-contactless-payment-flaw/"
  },
  "original_language": "en",
  "account": "Security researchers have uncovered a flaw in contactless payment systems that could allow expired Visa cards to be processed as valid. Dubbed the \"Zombie Card\" attack, the technique manipulates card expiry information during transmission to bypass cryptographic protections. Demonstrated by researchers from the University of Massachusetts Amherst, the attack exploits a gap in Visa's EMV Contactless Kernel 3 specifications. When tested across Visa, Mastercard, American Express, and Discover cards, as well as Apple Pay and Google Pay, the vulnerability was found only in Visa transactions. By altering the expiry date transmitted through near-field communication, an attacker between a card and a payment terminal can enable payment without triggering fraud detection systems. The vulnerability stems from Visa's handling of two representations of a card's expiry date—one checked by the point-of-sale terminal and another derived from separate Track 2 Equivalent Data when sent to the issuing bank. The terminal checks the expiry without sufficient protection from the card's digital signature, allowing modification by an attacker using an NFC relay. This setup requires physical access to an expired card and NFC relay equipment. Tests showed the attack could complete a $100 purchase on an expired Visa card. While not guaranteed to work on every expired card, the flaw highlights a broader issue: banks often treat card expiration as a policy decision rather than a cryptographically enforced property. Visa's specifications require terminals to enforce processing restrictions based on the Application Expiration Date, but the researchers found that terminal-visible expiry information wasn't reliably tied to authenticated data. Banks can mitigate the risk by verifying the physical card's validity, not just relying on account status. Despite disclosing the findings to Visa in 2025, no comprehensive mitigation has been publicly implemented. The team proposes relay-resistance technology as a potential defensive measure, though optional and not active on the tested cards and terminals.",
  "summary": "Security researchers have demonstrated a method for making some expired Visa contactless cards appear valid to payment terminals, exposing a weakness in how card expiry information is checked across the payment chain. The technique, dubbed the “Zombie Card” attack, allows an attacker positioned between an expired card and a point-of-sale terminal to alter the expiry date transmitted through…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}