Advertisement
Advertisement
Advertisement
23 August 2026ยท8 min readยทBy Sloane Meyer

Zombified Visa cards: expired cards can make contactless payments

Researchers at Usenix show how expired Visa cards can be 'zombified' to make contactless payments, bypassing authentication due to issuer flaws.

Zombified Visa cards: expired cards can make contactless payments

Zombified Visa cards: expired cards can make contactless payments

Zombified Visa cards are the latest trick in a fraudster's playbook. The threat is real. Researchers are sounding alarms, and a team from the University of Massachusetts Amherst presented findings at the Usenix Cybersecurity Conference last week that demonstrate how expired Visa cards can be revived and used for contactless payments. It's a clever man-in-the-middle attack. The technique involves proxying the card's data through a pair of phones, effectively bringing a dead piece of plastic back to life for unauthorized transactions, but don't think your wallet is safe just yet. So they're pushing for fixes.

The Mechanics of a Card Reanimation

The attack exploits a gap in Visa's authentication chain. It's a clever trick, really. When a fraudster gets hold of an expired card, they don't need the physical plastic to make a payment, and that's the key point. So they use a man-in-the-middle app that relays the credit card's data between two phones, and here's how the whole thing works. One phone acts as the card, communicating with a point-of-sale terminal, while the other phone intercepts and forwards the necessary authentication signals. But the gap remains. They've found a way through.

The core problem lies in how Visa handles expired cards during contactless transactions. The researchers discovered that whether an expired card's transaction gets blocked depends entirely on the cryptographic implementation used by individual card issuers. Visa essentially outsources this authentication decision to the cardholder's bank. Some banks properly reject the zombified Visa cards. Others don't.

That inconsistency creates a dangerous opening.

Why Your Expired Card Matters

Most people assume an expired card is useless. The magnetic stripe might still work at an ATM, but the chip and contactless features should be dead. The researchers found that's not always true with Visa. The card's expiration date is supposed to be part of the authentication check, but Visa's implementation left a flaw that allows out-of-date cards to pass through.

Visa did not respond to requests for comment from tech news outlet The Register, which reported on the research this week. That silence is telling. The company appears to have deferred the security decision to banks, and that decision-making process is inconsistent across the financial industry.

Real-World Scenarios: Dumpster Diving Pays Off

The practical implications are straightforward and unsettling. A fraudster could go dumpster diving, find an expired Visa card, and use it to make payments from the unwitting owner's account. The attack works particularly well at point-of-sale terminals where no human is present to question why someone is holding a phone against the payment reader instead of a physical card.

Card and envelope with scissors and marker

The attack works particularly well at point-of-sale terminals where no human is present to question why someone is holding a phone against the payment reader instead of a physical card. Those are prime targets for this technique. The absence of a human observer means the fraudster can comfortably hold their phone-based proxy setup to the terminal without raising suspicion.

The fact that any bank allowed these transactions points to a serious security gap.

The Scissors Solution

There's a simple fix for consumers, and it doesn't require any technical expertise. So grab a pair of scissors when that Visa card expires, cut it up, and then throw it away, because the physical destruction of the card ensures it can't reanimate in someone else's hands, and that's a safeguard anyone can manage without a single phone call or form. It's that easy.

It sounds almost too basic to be the answer, but it's the most effective protection available right now. Shred that card into multiple pieces, and it becomes utterly useless to a fraudster, no matter what clever proxying technique they employ, because the physical data is gone and there's nothing left to reconstruct or exploit. Useless. That's the whole trick. And it works.

Broader Security Landscape: A Week of Hacks

The zombified card research wasn't the only security news this week. But that's hardly the whole story. The timing of these findings coincides with a broader wave of digital threats, one that's now washing across multiple sectors and demanding urgent attention from every organization that's connected to the internet. We've seen this pattern before. It doesn't end well.

Apple sent out an unprecedented number of spyware alerts to potential victims in 110 countries last weekend. That's a staggering jump. The alerts, which target people who may be the subject of mercenary spyware attacks, reached numbers more than 30 percent higher than previous rounds, and they came with a chilling urgency that caught many security experts off guard. Mohammed Al-Maskati, who leads a team of security investigators at Access Now, a digital rights group that Apple refers victims to, provided that estimate. But he didn't name the exact total. At least one recipient was a Ukrainian soldier who said others in the Ukrainian military also received the alert. So the threat isn't theoretical. It's real.

Meanwhile, the Ukrainian military claimed to have carried out a disruptive cyberattack against Russian ecommerce giant Wildberries. It's a bold move. The attack coincided with drone strikes that destroyed parts of the company's warehouse infrastructure, and that's not all, because the Ukrainian Main Intelligence Directorate said Wildberries is part of Russia's military logistics and has played a role in financing the war. But Russian media reported the company lost nearly 13 million square feet of warehouse space to drone attacks. That's a staggering figure. So they can't hide from the damage.

And in an advisory issued this week, a group of US agencies including the NSA, the FBI, the Department of Energy, and the Cybersecurity and Infrastructure Security Agency warned that AI-assisted exploitation software is now targeting Siemens programmable logic controllers. These devices control physical systems in manufacturing, chemical, energy, water, food, and agriculture facilities. The advisory states that using AI to generate exploitation scripts "represents an evolution in threat actor capabilities, dramatically reducing the technical expertise and time required to develop working ICS exploitation scripts and malicious tools."

What the Card Research Means for You

Back to the zombie cards. The research highlights a fundamental tension in payment security: convenience versus authentication. Contactless payments are fast and easy, but that speed comes at a cost when the underlying verification systems have inconsistent implementations.

Visa lets banks decide how to handle expired cards. It's a design choice that shifts responsibility without ensuring uniform security, so the outcome depends entirely on which institution happens to hold your account. Some banks made the right call and blocked the transactions. But others didn't, and there's no way for a consumer to know which category their bank falls into. That's the problem.

The researchers' findings suggest the payment industry still has work to do in standardizing authentication protocols, and until that happens, the burden shifts squarely onto individual cardholders who must take matters into their own hands. That's a heavy lift. So the onus falls on you to physically destroy your expired cards, because no one else is going to do it for you. Don't wait. It's a simple step, but it's the only real protection you've got left.

The lesson: When that Visa card expires, a pair of scissors can ensure it doesn't reanimate in someone else's hands.

That single sentence captures the entire problem and solution in one breath. The technology may be sophisticated, but the defense is surprisingly straightforward.

Cut the card. Throw it away. Move on with your life.

The alternative is leaving a zombified Visa card out there, waiting for someone with bad intentions and a pair of phones to bring it back from the dead.

Frequently Asked Questions

What is the 'zombified Visa cards' attack described in the article?

The attack is a man-in-the-middle technique where a fraudster uses two phones to proxy an expired Visa card's data, effectively reviving the card for contactless payments. One phone acts as the card communicating with a point-of-sale terminal, while the other intercepts and forwards authentication signals.

Why does the attack work, according to the researchers?

The attack exploits a gap in Visa's authentication chain, where the expiration date is supposed to be part of the check but is not consistently enforced. Whether an expired card's transaction is blocked depends on the cryptographic implementation used by each card issuer, and some banks do not properly reject these transactions.

How can consumers protect themselves from this threat?

The article advises physically cutting up expired Visa cards with scissors and throwing them away. This ensures the card's data is destroyed, making it useless to fraudsters even if they attempt to proxy it.

Who presented the research on zombified Visa cards?

A team from the University of Massachusetts Amherst presented the findings at the Usenix Cybersecurity Conference. The research was also reported by tech news outlet The Register.

What other security threats were mentioned in the article that occurred around the same time?

The article mentions Apple sending spyware alerts to potential victims in 110 countries, a Ukrainian military cyberattack on Russian ecommerce giant Wildberries, and a US advisory warning about AI-assisted exploitation software targeting Siemens programmable logic controllers.

Sloane Meyer
Written by
Cybersecurity Editor

Sloane Meyer covers cybersecurity, privacy and the threats facing individuals and organisations online. She explains how attacks happen and what can be done to stay protected.

๐Ÿ’ฌ Comments (0)

Sign in to leave a comment.

No comments yet. Be the first!

Advertisement