Zombie Card Attack Revives Expired Visa Contactless Cards for Real Purchases
What Happened — Researchers at the University of Massachusetts Amherst proved that an attacker can rewrite the expiration date stored on a Visa contactless card via near‑field communication (NFC) at a point‑of‑sale (POS) terminal. The manipulation does not break the card’s cryptographic protections, allowing the “expired” card to be used for in‑store purchases.
Why It Matters for Compliance & Audit Readiness
- Highlights a control gap in POS firmware and card‑data handling that SOC 2 security controls (CC6.1 System Operations, CC7.1 Change Management) are designed to detect and remediate.
- Continuous evidence collection on POS configuration changes provides defensible audit trails and satisfies the SOC 2 requirement for ongoing monitoring of critical systems.
- Demonstrates the need for rigorous vendor‑risk assessments of payment‑card processors and POS providers, a core component of the SOC 2 vendor‑management criteria.
Who Is Affected — Financial‑services firms (banks, card issuers, payment processors) and retail merchants that accept contactless Visa cards.
Recommended Actions —
- Review POS firmware and configuration settings that handle card expiration data; map findings to SOC 2 change‑management controls.
- Deploy continuous monitoring of NFC transaction logs to detect unauthorized expiration‑date rewrites.
- Update vendor‑risk assessments for card‑issuers and POS vendors, documenting controls in your SOC 2 evidence repository.
Technical Notes — The attack exploits a lack of validation on the expiration‑date field in the NFC data exchange between card and terminal. No CVE has been assigned yet; the vulnerability is a design flaw in the contactless payment protocol rather than a software bug. Data at risk includes cardholder account numbers and transaction amounts. Source: The Hacker News