Researchers at the University of Massachusetts Amherst have uncovered a practical attack that allows fraudsters to reactivate expired Visa contactless cards for real transactions at retail locations. The attack, dubbed "Zombie Card," bypasses card expiration protections by manipulating the expiration date transmitted between the card and point-of-sale terminals via near-field communication (NFC) without compromising the card's cryptographic security.
The Zombie Card attack exploits a fundamental asymmetry in how Visa contactless payment systems validate expiration dates. When a cardholder taps a card at an NFC-enabled terminal, the card transmits transaction data, including the expiration date. The researchers discovered they can intercept and modify this data mid-transaction, telling the terminal the card is still valid even when the magnetic stripe or physical card states otherwise. Critically, the attack does not crack the card's encryption or authentication mechanisms. Instead, it manipulates the application layer data that the terminal reads and processes.
The practical implications are severe. An attacker with basic NFC interception equipment can intercept communications between an expired card and a POS terminal, alter the expiration date field, and authorize purchases that should fail. Victims include both cardholders whose expired cards remain compromised and merchants whose terminals accept invalid payment credentials. The attack works against Visa's contactless payment infrastructure because terminals typically prioritize speed and convenience over rigorous expiration validation, accepting whatever date the card communicates.
The University of Massachusetts research team demonstrated real-world proof-of-concept attacks on actual Visa terminals in retail environments. They successfully completed unauthorized transactions using physically expired cards that had been reactivated through NFC manipulation. The attack requires an attacker to be in close physical proximity to the card and terminal during the transaction, limiting large-scale exploitation. However, the proximity requirement is minimal, typically three to four inches, making the attack viable on crowded retail floors or public transportation systems.
Visa's contactless payment protocol relies on card authentication but assumes the expiration date transmitted by the card itself is trustworthy. This assumption breaks down when attackers can modify data in transit. The researchers noted that while individual payment networks implement additional fraud detection mechanisms like velocity checks and transaction limits, these systems operate downstream of the terminal authorization process and may not catch every compromised transaction.
Merchants and card issuers face an uncomfortable choice. Strengthening expiration date validation at the terminal level could slow transaction processing, negating the speed advantage of contactless payments. Alternatively, payment networks could implement additional cryptographic binding between the expiration date and other card parameters, making manipulation more difficult. However, retrofitting existing terminals with new security protocols requires massive infrastructure investment and coordination across millions of devices globally.
The researchers disclosed their findings responsibly to Visa and payment industry bodies before public release. Visa acknowledged the vulnerability but noted that existing fraud detection systems catch most unauthorized transactions. For consumers, the immediate risk is limited. Expired cards remain vulnerable only if they remain in circulation, and fraud detection typically catches unauthorized purchases. Cardholders should monitor expired cards closely and report suspicious activity immediately. The Zombie Card attack underscores the ongoing tension between transaction speed and security in modern payment systems, a tension that continues to create windows for attackers.
