Zombie Card: Expired Visa Contactless Cards Can Be Reactivated for In‑Store Purchases
What Happened — Researchers at UMass Amherst demonstrated that the expiration date field in the Visa Kernel 3 contactless flow can be altered by a malicious terminal, allowing an expired Visa card to be accepted for a real purchase. The flaw was not observed on Mastercard, Discover, or American Express cards, and Visa behavior varied across issuers.
Why It Matters for Compliance & Audit Readiness
- The scenario maps directly to SOC 2 CC6.1 (Logical Access) and CC7.1 (System Operations) controls that require “authorized, authenticated, and auditable access to system resources.”
- Continuous control monitoring of payment‑terminal firmware and issuer validation processes provides the audit evidence needed to demonstrate that expired credentials are reliably rejected.
- Verisq’s Control Mapping capability helps you map this technical gap to SOC 2 requirements and collect ongoing evidence for audit readiness.
Who Is Affected — Financial services firms that issue or accept Visa contactless cards, payment processors, and merchants using vulnerable terminals.
Recommended Actions
- Inventory all contactless terminals and verify they run firmware that enforces kernel‑level expiry checks.
- Update terminal configurations or apply vendor patches that bind the Application Expiration Date to the card’s cryptographic data.
- Incorporate terminal‑firmware validation into your continuous compliance monitoring program and retain evidence of successful checks.
Source: Malwarebytes Labs – Zombie Card
Technical Notes
- Vulnerability resides in Visa Kernel 3 contactless flow; the Application Expiration Date is not cryptographically bound to the card data.
- Exploit requires a malicious or compromised payment terminal that can rewrite the expiry field before authorisation.
- No CVE assigned yet; the issue is disclosed in academic research.