Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
Summary
Researchers have developed a "Zombie Card" attack that can revive expired Visa contactless credit cards for in-store purchases. The attack exploits the near-field communication (NFC) protocol to rewrite the expiration date read by point-of-sale terminals, bypassing cryptographic security measures.
IFF Assessment
This attack enables unauthorized transactions using expired payment cards, posing a direct threat to financial institutions and consumers.
Severity
The CVSS score is estimated based on the attack's potential to compromise confidentiality and integrity of financial transactions, with a relatively low attack complexity and user interaction required for successful exploitation via NFC.
Defender Context
This highlights a novel attack vector against contactless payment systems, emphasizing the need for robust validation mechanisms beyond simple expiration date checks at the POS. Defenders should be aware of potential vulnerabilities in NFC communication protocols and ensure that card data is rigorously authenticated before authorizing transactions.