TECH
When zombie credit cards attack: UMass researchers discover loophole that can ranimate expired cards
A new security loophole can bring some expired credit cards back to life, researchers from the University of Massachusetts Amherst have discovered. If stolen, these “zombie credit cards” could leave cardholders vulnerable to fraudulent charges, according to the new study, presented at the conference USENIX Security 2026.
The researchers discovered that thieves “can still use the victim’s expired credit card, despite the victim receiving another card,” says Taqi Raza, assistant professor in the Riccio College of Engineering at UMass Amherst.
This loophole exists because credit card accounts do not expire with the physical card. For instance, if you make a return, your account will be refunded, even if the purchasing credit card has expired. But this made Raza wonder: “If the card can get a refund, can the card make a payment?”
For some credit cards, the answer is yes. Raza and his research team devised a system using two, off-the-shelf smartphones and basic emulator software to fool an in-store card reader, also known as a point-of-sale (POS) terminal, into thinking a card was active.
Using the same technology that enables tap-to-pay transactions (near-field communications, or NFC), the first phone is used to activate the credit card. It tells the card: a purchase is trying to be made, so send over the cardholder data and payment application. This includes the past-due expiration date.
However, using a “man-in-the-middle” Wi-Fi-based relay system, the second phone takes the credit card information but rewrites the expiration date. Raja Hasnain Anwar, the lead author of the study and doctoral candidate with the Khwarizmi Lab at UMass Amherst, notes that this attack is particularly dangerous because thieves do not need to determine the actual expiration date of a replacement card; any arbitrary expiration date in the future is sufficient to successfully make a charge.
“The expiration date printed and stored on the card is the only way for the POS to know whether the card is active or expired,” he says. “Yet it is not cryptographically protected. So we can easily modify it to fool the POS.”
This second phone is then tapped to the card reader. To an outside observer, the behavior would look the same as using any kind of digital wallet.
“Now, you’re expecting the bank should notice it,” says Raza. But not all banks verify the terminal-read expiration date against authenticated data. If other security measures are not in place to recheck card lifecycle status, the fraudulent transaction will be successful.
''The expiration date printed and stored on the card is the only way for the POS to know whether the card is active or expired, yet it is not cryptographically protected. So we can easily modify it to fool the POS''... Raja Hasnain Anwar, doctoral candidate with the Khwarizmi Lab at UMass Amherst and lead author of the new study.
The loophole that enables an expired credit card to be revived is based on a relay system using software that can be run on two standard smartphones and the physical card. The researchers found it worked across a variety of point-of-sale terminals(image above)
In fact, credit cards have another expiration date in addition to the one printed on your card: a date embedded in the security key that encrypts the transaction between the card and the bank, referred to as a digital certificate. This digital certificate is checked first, enabling the card to “talk” to the POS.
“What we found is that the expiry date for the digital certificate for the security key is longer than the expiry date of return on the card,” says Raza, making this date an ineffective check of the card’s actual expiration status.
The researchers demonstrated that this loophole works both in the lab and in the wild—at local dining facilities and grocery stores. However, not all credit cards were equally impacted by this loophole and digital wallets included additional security measures making them more resilient against this particular kind of attack. However, separate research from Raza’s lab has found digital wallets are susceptible to other types of exploitation.
The root cause of such issues lies in how payment cards and systems have evolved over time. As we move to smarter but distributed systems, decisions are divided between the card chip, POS terminal, payment networks (e.g., VISA, Mastercard), and the bank. Discrepancies often arise, such as the ability to fool a terminal with a limited view of card expiration when the bank relies on that terminal’s verification. “With the rise of AI, it is becoming increasingly easy for attackers to spot these discrepancies and devise exploits, effectively putting millions of credit cards at risk,” says Anwar.
While the major card companies have been notified of their discovery, Raza says consumers should still abide by safe credit card practices.
“The attack exploits a documented misconception—expired cards are widely assumed inert, so cardholders discard them carelessly,” says Raza. “Always discard your expired card, no matter what. Even if you permanently close your credit card, still monitor the transaction on the closed account.”
Start by demagnetizing the card by slowly running a magnet along the magnetic strip. Next, destroy the embedded chip either with a hammer or scissors. Cut apart your card or put it through a paper shredder, ensuring you cut through any raised letters or numbers. Finally, separate the credit card pieces into different trash cans. For metal cards, contact your company’s customer service department. Fraudulent charges should be immediately reported to your bank.
No comments:
Post a Comment