Researchers ring up real purchases with dead Visa cards

A USENIX study shows expired Visa cards can be revived at checkout by rewriting the expiry read over NFC.

CSBadmin
2 Min Read

Researchers at the University of Massachusetts Amherst have shown that expired Visa contactless cards can be used for real in-store purchases. Their Zombie Card attack rewrites the expiration date a point-of-sale terminal reads over near-field communication (NFC), without breaking any of the card’s cryptography.

The method needs physical possession of the expired card or sustained NFC proximity, plus a man-in-the-middle relay between card and terminal. The account must stay open under the same primary account number, standard practice when issuers send replacements, and the issuing bank must not independently re-check expiry during authorization.

In a preliminary study spanning five major US banks, transactions succeeded at most of them after the team modified the Consumer Device Cardholder Verification Method flag. Three banks were then tested with expired and replaced physical cards, exposing three distinct policies: one accepted modified cards, one detected the change but accepted a single active card, and a Discover-kernel card accepted modified transactions from multiple cards.

The team, led by Raja Hasnain Anwar, presented the work at USENIX Security Symposium in Baltimore on August 12-14. The finding lands on an industry already wrestling with relay attacks and suggests issuers should validate expiry server-side rather than trusting terminal reads.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.