logo

Digital wallets can allow purchases with stolen credit cards

ID: 5ce6650c-f341-599b-a66d-c0d55e905c03

STIX ID: report--5ce6650c-f341-599b-a66d-c0d55e905c03

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2024-08-20

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Researchers presented at USENIX Security 2024 show that attackers can add stolen payment card numbers to Apple Pay, Google Pay, and PayPal by forcing banks to fall back to knowledge-based authentication (via call-based flows) and using easily obtainable PII (ZIP, DOB, last 4 of SSN), then exploit banks' token management and recurring-payment handling so the wallet token remains usable after card cancellation; the paper includes tested purchases, disclosure to vendors, and recommended mitigations such as push notifications, stronger authenticators, and improved token/recurring-payment checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.