
Zombie Card Attack Revives Expired Visa Contactless Credit Cards for Fraudulent Purchases
CybersecurityHackingPaymentFraudVulnerabilities
Researchers at the University of Massachusetts Amherst demonstrated an attack named 'Zombie Card' that revives expired Visa contactless credit cards for real in-store purchases. The attack works by rewriting the expiration date that a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the card's cryptography. The attack requires physical proximity to execute the manipulation of the card data during contactless transactions.