Home Services & Solutions Payment and card Can Zombie Card Attack Vulnera...
CIO Bulletin,
20 August, 2026
Author:
Ravathi Sunil
Flaws in wireless checkout systems allow scammers to resurrect old plastic and approve unauthorized purchases out of thin air.
Researchers have uncovered a security loophole known as the Zombie Card attack, revealing that expired contactless credit cards can still be used to make unauthorized payments. Security experts from the University of Massachusetts Amherst demonstrated that plastic cards past their printed expiration date can easily bypass standard retail checks.
The attack relies on two smartphones linked together through local wireless technology. One phone reads data from the old card, while a second phone alters the unencrypted expiration date to a future year before passing the signal to a store register. Because the main account remains open and some banking networks fail to verify specific card instances, the transaction goes through smoothly.
What actually stops an old piece of plastic from making purchases when systems rely on basic account checks rather than deep validation? CIO Bulletin reports that security gaps happen when checkout registers reset expired flags or assume someone else along the chain verified the physical card.
"This work is motivated by documented patterns of improper expired card handling. Although issuers instruct cardholders to destroy expired cards after replacement, cardholders routinely underestimate this risk precisely because expired cards are assumed to be inactive," stated the UMass Amherst research team.
Testing revealed that this specific date-tampering flaw impacted certain Visa payment configurations, whereas networks like Mastercard, American Express, and Discover consistently blocked altered dates using stronger cryptographic protections.
Attackers alter expiration dates using simple smartphones acting as a digital relay.
Some banking systems check overall account status instead of checking whether the specific card is active.
Old cards that were replaced before their expiration date also continued to process charges successfully during testing.
Everything you need to know about this news
A relay setup intercepts the card data and rewrites the unencrypted expiration date before sending it to the point-of-sale terminal.
No, researchers found networks like Mastercard, American Express, and Discover rejected tampered dates due to mandatory cryptographic checks.
Certain banks only verify if the primary account exists, ignoring whether the physical card used has already expired or been replaced.
Yes, tests showed that cards replaced early by issuers could still process transactions alongside their new replacement cards.
Cardholders should always physically destroy expired cards rather than simply throwing them away or keeping them in storage.








Comments