Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Summary

Researchers have developed a "Zombie Card" attack that can revive expired Visa contactless credit cards for in-store purchases. The attack exploits the near-field communication (NFC) protocol to rewrite the expiration date read by point-of-sale terminals, bypassing cryptographic security measures.

IFF Assessment

FOE

This attack enables unauthorized transactions using expired payment cards, posing a direct threat to financial institutions and consumers.

Severity

7.5 High (AI Estimated)

The CVSS score is estimated based on the attack's potential to compromise confidentiality and integrity of financial transactions, with a relatively low attack complexity and user interaction required for successful exploitation via NFC.

Defender Context

This highlights a novel attack vector against contactless payment systems, emphasizing the need for robust validation mechanisms beyond simple expiration date checks at the POS. Defenders should be aware of potential vulnerabilities in NFC communication protocols and ensure that card data is rigorously authenticated before authorizing transactions.

Read Full Story →