Zombie Card Attack (Expired Contactless Payment)

 


“Zombie Card Attack” is a cybersecurity attack technique disclosed in August 2026 that can make some expired Visa contactless payment cards appear valid for NFC tap-to-pay transactions. Researchers from the University of Massachusetts Amherst demonstrated that, under specific conditions, an attacker can alter the expiration date seen by a payment terminal without breaking the card's cryptographic protections.

Key points:
  • It requires physical possession of the expired card or close NFC access to it, plus a relay/man-in-the-middle setup between the card and the payment terminal.
  • The attack targets how some Visa contactless kernels process expiration dates, exploiting the fact that certain expiration data is not cryptographically protected.
  • Researchers reported mixed results across banks. Some institutions rejected the transactions, while at least one approved them during testing.
  • No widespread real-world exploitation had been reported at the time of disclosure.

What you can do

  • Destroy expired cards promptly. Since the attack requires access to an expired physical card (or very close NFC proximity to it), cutting up and disposing of expired cards reduces the opportunity for misuse. [thehackernews.com], [cybersecur...tynews.com]

  • Activate and use replacement cards as soon as they arrive. The attack relies on the underlying account remaining open and linked to the same account number after reissuance. Prompt activation helps ensure you're using the most current card credentials. [thehackernews.com]

  • Monitor account activity. Enable transaction alerts through your bank's mobile app so you'll know immediately if an unauthorized purchase occurs. This is good practice for all payment card fraud.

  • Report lost or stolen cards immediately. Even though the attack requires more than just possession of a card, notifying your bank quickly limits potential abuse.

  • Use your issuer's card controls. Many banks allow you to:

    • Lock or freeze a card temporarily.
    • Disable contactless payments.
    • Restrict certain transaction types.
    • Receive real-time purchase notifications.
  • Keep cards physically secure. The researchers noted that the attack requires physical possession of the card or sustained NFC proximity combined with specialized equipment. [thehackernews.com], [cybersecur...tynews.com]

Do RFID-blocking wallets help?

An RFID- or NFC-blocking wallet may reduce the chance of unauthorized close-range reading of a card when you are carrying it, but the published attack still requires a sophisticated relay setup and access to the card. The most important protection remains safeguarding the card itself and monitoring your account. [thehackernews.com], [cybersecur...tynews.com]

What banks and card networks should do

The research suggests that stronger issuer-side expiration checks and protocol changes would be the most effective long-term mitigations, because the vulnerability stems from how some contactless transactions process expiration data rather than from consumer behavior. [thehackernews.com], [cybersecur...tynews.com]


Comments

Popular posts from this blog

Entire List Leaked for Canvas Ransomware Attack

OpenAI Discloses Emerging Risks in Autonomous AI Agent Behavior

WSUS CVE-2025-59287 Mitigation

Cloud Infrastructures are Having a Bad Week

CVE-2025-58034 Fortinet Warnings and Mitigation

Broadcom is dismantling of VMware Cloud Service Providers (VCSPs)

FBI Seizes RAMP Cybercrime Forum

Instagram Data Leak Update

CodeRED emergency alert system is currently down across many regions!

Notepad++ update service was compromised