Researchers Warn Expired Visa Cards Can Be ‘Zombified’ for Fraudulent Contactless Payments

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Researchers at the University of Massachusetts Amherst have raised concerns about a new technique that allows expired Visa cards to be used for fraudulent contactless payments. This warning was issued during the Usenix Cybersecurity Conference, where the researchers explained how fraudsters could exploit vulnerabilities in the authentication chain of contactless payments. According to reporting by WIRED, the method involves proxying the expired card’s data through a man-in-the-middle app that connects two phones.

The researchers found that whether a transaction using an expired card would be rejected depended on the cryptographic implementations of various card issuers. Visa’s system had a specific flaw that allowed some expired cards to bypass checks. While some banks have measures in place to prevent the use of these “zombified” cards, others do not, potentially enabling fraudsters to make unauthorized payments using discarded or lost expired cards.

This alarming discovery highlights the importance of properly disposing of expired credit cards. The researchers emphasized that cutting up expired cards can prevent them from being misused by criminals who might find them in the trash.

As the cybersecurity landscape continues to evolve, incidents like this serve as a reminder of the vulnerabilities that can exist within payment systems, underscoring the need for ongoing vigilance and security improvements.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Japan’s Digital Agency Confirms Data Breach Exposing 246,000 Records

In a significant cybersecurity incident, Japan's Digital Agency has confirmed a data breach that exposed approximately 246,000 records. This breach, attributed to a vulnerability...

Canadian Privacy Commissioner Investigates IDScan.net Following Data Breach of 153 Million Driver’s Licenses

Privacy Commissioner of Canada Philippe Dufresne has initiated an investigation into IDScan.net following reports of a significant data breach affecting personal data and scans...

Dubai Government Launches Real-Time Cybersecurity Dashboard in Partnership with Microsoft

The Dubai Electronic Security Center (DESC) has partnered with Microsoft to launch a new Zero Trust assurance dashboard, providing real-time visibility into the cybersecurity...

INS Trishul arrives in Toulon with upgraded BrahMos missile capability

INS Trishul, the Indian Navy’s Talwar-class frigate, arrived at Toulon naval base in France on September 22, 2026, as part of its operational deployment...