HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Researchers Reveal “Zombie Card” Attack Allowing Expired Contactless Cards to Process Unauthorized Payments

A UMass Amherst team showed that expired contactless cards can be used for payments by relaying NFC data and rewriting the expiration field, exposing a control gap in Visa’s transaction flow. The finding highlights the need for SOC 2‑aligned control mapping and continuous monitoring of payment‑processor integrity.

LiveThreat™ Intelligence · 📅 August 20, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Researchers Reveal “Zombie Card” Attack Allowing Expired Contactless Cards to Process Unauthorized Payments

What Happened — Researchers at the University of Massachusetts Amherst demonstrated that a contactless credit card can still be used after its printed expiration date. By relaying NFC data between two smartphones and rewriting the expiration field, they were able to complete a payment with an “expired” card on Visa’s contactless network.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits a control gap in the payment‑transaction flow where each party assumes the others have validated card validity – a classic SOC 2 “control mapping” failure.
  • Continuous evidence collection on card‑validation controls (e.g., cryptographic binding of expiration data) is essential to prove that the Security principle is being enforced.
  • Demonstrates the need for real‑time monitoring of third‑party payment processors and the ability to surface gaps as audit‑ready evidence.

Who Is Affected — Financial services, payment processors, merchants that accept Visa contactless payments, and any organization handling cardholder data (PCI‑DSS scope).

Recommended Actions

  • Map the card‑validation step to your SOC 2 security controls (CC6.1) and verify that expiration dates are cryptographically bound.
  • Deploy continuous monitoring of payment‑gateway logs for anomalous “future‑date” transactions.
  • Engage with card issuers to confirm they have patched the identified relay weakness and obtain audit‑ready evidence of remediation.

Technical Notes

  • Attack vector: NFC relay using two smartphones, Wi‑Fi link, and date‑field manipulation.
  • Affected flow: Visa contactless transactions (tested on Visa; Mastercard, Amex, Discover rejected the tampered date).
  • No CVE assigned; the vulnerability lies in the protocol design rather than a firmware bug.

Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/08/20/zombie-credit-card-attack-expired/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →