PUBLISHED Aug 20, 2026, 12:56 AM ET
Researchers at the University of Massachusetts Amherst have uncovered a cybersecurity vulnerability allowing expired contactless credit cards to execute unauthorized transactions. Revealed at the USENIX Security conference, the "Zombie Card" attack exploits a validation gap where point-of-sale terminals fail to invalidate payment permissions on expired cards. Investigators demonstrated that using a basic smartphone relay system, an attacker can modify unencrypted expiration metadata during a tap-to-pay transaction. Although credit card accounts remain active for functions like billing refunds, the vulnerability bypasses standard bank rejections because some issuing institutions do not verify terminal-read dates against authenticated records. The research team notified major financial institutions and payment networks prior to public disclosure, prompting card issuers to review validation protocols. Experts advise consumers to securely destroy expired physical plastic rather than assuming discarded cards are completely inert.
By Emily Rhodes | JQJO News
Left: Focuses on corporate accountability and necessary regulatory payment network fixes. Center: Reports technical findings neutrally while emphasizing consumer security best practices. Right: Emphasizes individual consumer responsibility to properly destroy old credit cards.
University of Massachusetts Amherst published security research on August 17, 2026. https://www.umass.edu/news/article/when-zombie-credit-cards-attack-umass-researchers-discover-loophole-can-reanimate
No left-leaning sources found for this story.
Researchers Expose "Zombie Card" Flaw Allowing Unauthorized Contactless Payments on Expired Credit Cards
Help Net Security / USENIX Security Help Net Security HotHardware Khwarizmi Lab The CU Daily University of Massachusetts Amherst Pasquale Pillitteri Tech Blog TechXplore The Register SecurityWeek Bleeping Computer Dark Reading The Hacker News ZDNet CNET Forbes PCMag Ars Technica Wired Threatpost InfoSecurity Magazine SC Media CSO Online SiliconANGLE The Verge Engadget Gizmodo Mashable Digital Trends Tom's Guide VentureBeatNo right-leaning sources found for this story.
Comments