Zombie Card Attack Revives Expired Visa Cards for Real Purchases

A A
Resize

Expired credit cards may not be as useless as they appear. Researchers at the University of Massachusetts Amherst have uncovered a major security flaw that lets criminals use expired Visa contactless cards to make unauthorized purchases in stores.

The researchers, presenting their findings at the 35th USENIX Security Symposium, call this the “Zombie Card” attack. The method is alarmingly simple: with just two regular smartphones, attackers can set up a relay system. All they need is to get hold of an expired card, or stay close to it with NFC equipment.

The flaw exploits a fundamental weakness in how Visa handles expiration dates in tap-to-pay transactions.

When a customer taps their card at checkout, the payment terminal reads one expiration date, but the card’s issuing bank sees another. The system does not securely link these two pieces of information.

With the two-phone relay, attackers can intercept the card data and change the expiration date that the terminal receives.

Since the digital security certificates on the card often stay valid long after the card itself expires, the payment terminal accepts the card as if it were still active and approves the purchase.

Lead researcher Raja Hasnain Anwar explained that attackers do not even need to know the victim’s actual replacement expiration date. Because the metadata lacks cryptographic protection, any arbitrary future date can easily fool the system.

The UMass team tested this flaw against five major US banks. While responses varied, no bank cleanly rejected the exploit. The researchers successfully completed live retail and grocery store purchases on campus, as well as laboratory transactions totaling up to $500.

The researchers first reported their findings to Visa and the banks involved earlier this year, but so far, Visa has not updated its terminal requirements.

READ MORE: AmnesiaStealer malware hijacks macOS browsers via fake GitHub pages

To fix the problem, the researchers recommend that the payment industry start digitally signing expiration dates, require terminals to verify mismatched information, and ensure that validation results are sent directly to the banks.

Till these changes are made, security experts say people should destroy the chip and magnetic stripe on any expired credit card before throwing it away.