HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Researchers Demonstrate 'Zombie Card' Attack Reviving Expired Visa Contactless Cards for Fraudulent Purchases

University of Massachusetts Amherst researchers proved that expired Visa contactless cards can be revived by rewriting the expiration date via NFC at POS terminals, allowing real in‑store purchases. The proof‑of‑concept exposes a critical flaw in payment‑card handling that could affect merchants and issuers, underscoring the need for robust SOC 2 controls and continuous monitoring.

LiveThreat™ Intelligence · 📅 August 20, 2026· 📰 thehackernews.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Zombie Card Attack Revives Expired Visa Contactless Cards for Real Purchases

What Happened — Researchers at the University of Massachusetts Amherst proved that an attacker can rewrite the expiration date stored on a Visa contactless card via near‑field communication (NFC) at a point‑of‑sale (POS) terminal. The manipulation does not break the card’s cryptographic protections, allowing the “expired” card to be used for in‑store purchases.

Why It Matters for Compliance & Audit Readiness

  • Highlights a control gap in POS firmware and card‑data handling that SOC 2 security controls (CC6.1 System Operations, CC7.1 Change Management) are designed to detect and remediate.
  • Continuous evidence collection on POS configuration changes provides defensible audit trails and satisfies the SOC 2 requirement for ongoing monitoring of critical systems.
  • Demonstrates the need for rigorous vendor‑risk assessments of payment‑card processors and POS providers, a core component of the SOC 2 vendor‑management criteria.

Who Is Affected — Financial‑services firms (banks, card issuers, payment processors) and retail merchants that accept contactless Visa cards.

Recommended Actions

  • Review POS firmware and configuration settings that handle card expiration data; map findings to SOC 2 change‑management controls.
  • Deploy continuous monitoring of NFC transaction logs to detect unauthorized expiration‑date rewrites.
  • Update vendor‑risk assessments for card‑issuers and POS vendors, documenting controls in your SOC 2 evidence repository.

Technical Notes — The attack exploits a lack of validation on the expiration‑date field in the NFC data exchange between card and terminal. No CVE has been assigned yet; the vulnerability is a design flaw in the contactless payment protocol rather than a software bug. Data at risk includes cardholder account numbers and transaction amounts. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →