‘Zombie Card’ Attack Shows Expired Visa Cards Can Be Tricked Into Working Again
Security researchers at the University of Massachusetts Amherst have revealed a technique called the "Zombie Card" attack, which can make an expired Visa contactless credit card usable again for real purchases at physical point-of-sale terminals. The trick doesn't involve cracking any cryptographic protections on the card. Instead, attackers intercept and rewrite the expiration date that gets transmitted to the terminal over near-field communication (NFC) during a contactless tap.
Because the attack manipulates data in transit rather than breaking the card's chip security, it highlights a gap in how some payment terminals validate card details. The researchers noted that carrying out the attack requires physical access to the card, meaning it isn't something that can be done remotely over the internet — but it does raise concerns about lost, stolen, or discarded expired cards being exploited in-store.
While this research targets consumer card security rather than business systems directly, it's a useful reminder for Australian small businesses that accept contactless payments to stay alert to evolving fraud techniques. Payment processors and card networks will likely need to update terminal validation logic to close this gap, but until then, businesses should remain cautious about accepting cards that show visible signs of tampering or unusual behaviour at checkout.