University of Massachusetts Amherst researchers disclosed a "Zombie Card" attack that can make some expired or replaced Visa contactless credit cards usable again for unauthorized purchases. The attack uses a man-in-the-middle NFC relay to alter expiration data during the EMV contactless transaction flow, exploiting the fact that in the tested Visa setup the expiration date shown to the point-of-sale terminal was not cryptographically bound to the data later used in online authorization. The researchers said this let proxy devices tamper with expiry information in transit and bypass terminal checks under certain issuer configurations.
In lab testing and limited live transactions, the technique reportedly worked against one major U.S. bank for purchases from small retail amounts up to $500, while another bank consistently rejected the same tampered transactions, indicating issuer-side controls affect exploitability. The researchers found that Mastercard, American Express, and Discover configurations resisted the attack because their implementations bind expiration data cryptographically. They disclosed the issue to Visa and affected banks in 2025, proposed fixes including cryptographic binding of expiry data and issuer validation of the specific card instance and stored expiration date, and reported that no CVE had been assigned and no confirmed mitigation had been publicly acknowledged at publication.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers from the University of Massachusetts Amherst presented the 'Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments' findings at USENIX Security 2026. They showed that certain expired or replaced Visa contactless cards could be used for unauthorized payments by modifying expiry data during NFC transactions.
The researchers sent a follow-up disclosure to Visa and affected banks regarding the same contactless payment flaw. One source says the package included a reproduction guide, transaction records, and a demonstration video.
University of Massachusetts Amherst researchers notified Visa and affected banks about the expired-card contactless payment issue, providing reproduction details and evidence. The sources state the initial disclosure occurred in May 2025.
Visa accepted the researchers' report through initial triage, and its red team was reproducing the issue. This status was reported as of the article's publication, but no explicit event date beyond that status was provided.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcecybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcetheregister.com
Open sourceumass.edu
Open sourceusenix.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.