HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Zombie Card: Expired Visa Contactless Cards Can Be Reactivated for In‑Store Purchases

University researchers showed that a flaw in Visa's contactless kernel lets a malicious terminal rewrite an expired card's expiry date, allowing fraudulent purchases. The issue highlights the need for SOC 2‑aligned control monitoring of payment‑terminal firmware and issuer validation processes.

LiveThreat™ Intelligence · 📅 August 22, 2026· 📰 malwarebytes.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
malwarebytes.com

Zombie Card: Expired Visa Contactless Cards Can Be Reactivated for In‑Store Purchases

What Happened — Researchers at UMass Amherst demonstrated that the expiration date field in the Visa Kernel 3 contactless flow can be altered by a malicious terminal, allowing an expired Visa card to be accepted for a real purchase. The flaw was not observed on Mastercard, Discover, or American Express cards, and Visa behavior varied across issuers.

Why It Matters for Compliance & Audit Readiness

  • The scenario maps directly to SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) controls that require “authorized, authenticated, and auditable access to system resources.”
  • Continuous control monitoring of payment‑terminal firmware and issuer validation processes provides the audit evidence needed to demonstrate that expired credentials are reliably rejected.
  • Verisq’s Control Mapping capability helps you map this technical gap to SOC 2 requirements and collect ongoing evidence for audit readiness.

Who Is Affected — Financial services firms that issue or accept Visa contactless cards, payment processors, and merchants using vulnerable terminals.

Recommended Actions

  • Inventory all contactless terminals and verify they run firmware that enforces kernel‑level expiry checks.
  • Update terminal configurations or apply vendor patches that bind the Application Expiration Date to the card’s cryptographic data.
  • Incorporate terminal‑firmware validation into your continuous compliance monitoring program and retain evidence of successful checks.

Source: Malwarebytes Labs – Zombie Card

Technical Notes

  • Vulnerability resides in Visa Kernel 3 contactless flow; the Application Expiration Date is not cryptographically bound to the card data.
  • Exploit requires a malicious or compromised payment terminal that can rewrite the expiry field before authorisation.
  • No CVE assigned yet; the issue is disclosed in academic research.
📰 Original Source
https://www.malwarebytes.com/blog/news/2026/08/zombie-card-an-expired-visa-credit-card-can-be-used-for-purchases

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →