Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Researchers Demonstrate 'Zombie Card' Attack Reviving Expired Visa Contactless Cards for Fraudulent Purchases

University of Massachusetts Amherst researchers proved that expired Visa contactless cards can be revived by rewriting the expiration date via NFC at POS terminals, allowing real in‑store purchases. The proof‑of‑concept exposes a critical flaw in payment‑card handling that could affect merchants and issuers, underscoring the need for robust SOC 2 controls and continuous monitoring.

LiveThreat™ Intelligence · 📅 August 20, 2026· 📰 thehackernews.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
thehackernews.com

Zombie Card Attack Revives Expired Visa Contactless Cards for Real Purchases

What Happened — Researchers at the University of Massachusetts Amherst proved that an attacker can rewrite the expiration date stored on a Visa contactless card via near‑field communication (NFC) at a point‑of‑sale (POS) terminal. The manipulation does not break the card’s cryptographic protections, allowing the “expired” card to be used for in‑store purchases.

Why It Matters for Compliance & Audit Readiness

  • Highlights a control gap in POS firmware and card‑data handling that SOC 2 security controls (CC6.1 System Operations, CC7.1 Change Management) are designed to detect and remediate.
  • Continuous evidence collection on POS configuration changes provides defensible audit trails and satisfies the SOC 2 requirement for ongoing monitoring of critical systems.
  • Demonstrates the need for rigorous vendor‑risk assessments of payment‑card processors and POS providers, a core component of the SOC 2 vendor‑management criteria.

Who Is Affected — Financial‑services firms (banks, card issuers, payment processors) and retail merchants that accept contactless Visa cards.

Recommended Actions —

  • Review POS firmware and configuration settings that handle card expiration data; map findings to SOC 2 change‑management controls.
  • Deploy continuous monitoring of NFC transaction logs to detect unauthorized expiration‑date rewrites.
  • Update vendor‑risk assessments for card‑issuers and POS vendors, documenting controls in your SOC 2 evidence repository.

Technical Notes — The attack exploits a lack of validation on the expiration‑date field in the NFC data exchange between card and terminal. No CVE has been assigned yet; the vulnerability is a design flaw in the contactless payment protocol rather than a software bug. Data at risk includes cardholder account numbers and transaction amounts. Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →