Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments
ID: 2e54dcc6-e7a1-54be-90a0-86a7a6fd7d5f
STIX ID: report--2e54dcc6-e7a1-54be-90a0-86a7a6fd7d5f
Feed Name: The Hacker News
Researchers demonstrated a practical 'Zombie Card' attack that uses an NFC man-in-the-middle relay to rewrite the terminal-facing expiration date on contactless EMV transactions, allowing expired cards to transact when issuer and terminal policies permit; the weakness stems from Visa Kernel 3 not cryptographically binding the terminal expiry field (5F24) to issuer-verified data. The team tested five U.S. banks and multiple kernels, found mixed issuer policies and that Visa Kernel 3 was susceptible while other kernels (Mastercard, AmEx, Discover) behaved differently, and recommended binding expiry data, cross-checking expiry representations, and forwarding terminal validation signals. No CVE or confirmed exploitation was reported, but related NFC relay malware (WindRelay) has been observed in the wild, underscoring fraud potential.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
