Your Shredded Visa Card May Still Work at the Checkout
ID: d84f68e8-166f-52a0-ab9a-74e94309ba57
STIX ID: report--d84f68e8-166f-52a0-ab9a-74e94309ba57
Feed Name: Security Affairs
Researchers at UMass Amherst demonstrated a practical attack against Visa’s contactless EMV Kernel 3 that revives expired Visa cards for real purchases by relaying and altering the terminal-visible expiry field (tag 5F24) while leaving the bank-visible data and cryptographic checks intact. The attack used two NFC-capable Android phones as a relay/MITM and succeeded in lab and on-campus merchant purchases depending on the issuer and kernel; Mastercard, AmEx, and Discover were not vulnerable in tests. The paper recommends cryptographically binding expiry, making terminal/issuer checks visible, and issuer-side PAN+expiry authorization as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
