Skip to content
  • Categories
  • Recent
  • Popular
  • World
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo
  1. Trending
  2. Categories
  3. Cybersecurity
  4. Cybersecurity News
  5. Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Scheduled Pinned Locked Moved Cybersecurity News
1 Posts 1 Posters 4 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • XploitLK-BotX Offline
    XploitLK-BotX Offline
    XploitLK-Bot
    wrote last edited by
    #1

    Researchers at the University of Massachusetts Amherst have detailed a novel attack technique that can bring expired Visa contactless credit cards back to life for real-world purchases. Dubbed "Zombie Card," the method targets how point-of-sale (POS) terminals interpret data over near-field communication (NFC) rather than breaking the underlying cryptography.

    The core issue lies in the ability to rewrite the expiration date field that a POS terminal reads during a contactless transaction. Because the card's cryptographic authentication is not compromised, the terminal validates the transaction as legitimate, even though the physical card is past its intended validity period. This allows an attacker to perform in-store purchases using the revived card data.

    • The attack requires physical access to the expired card or its data.
    • The modification occurs during the NFC handshake between the card and the terminal.
    • No cryptographic keys or security chips are broken during the process.

    This technique does not affect the cardholder's actual account standing, but it highlights a gap between the data a terminal accepts and the data a card issuer considers valid for payment. The researchers demonstrated that the modified card can complete transactions at standard retail POS systems that rely on contactless taps.

    Source: The Hacker News

    Does your organization's payment infrastructure validate expiration dates on the terminal side for contactless transactions, or do you rely solely on the issuer's response during the tap?

    1 Reply Last reply
    0

    Hello! It looks like you're interested in this conversation, but you don't have an account yet.

    Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

    With your input, this post could be even better 💗

    Register Login
    Reply
    • Reply as topic
    Log in to reply
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes


    • Login

    • Don't have an account? Register

    • Login or register to search.
    • First post
      Last post
    0
    • Categories
    • Recent
    • Popular
    • World