Expired Visa Contactless Cards Could Be Brought Back to Life, Researchers Warn

Expired Visa Contactless Cards Could Be Brought Back to Life, Researchers Warn

A security report describes a 'Zombie Card Attack' that can revive expired Visa cards for contactless payments. The flaw affects how some terminals handle offline transactions.

Security researchers have published details of a technique they call the 'Zombie Card Attack' that can make an expired Visa card usable again for contactless payments. The name reflects the core problem: a card that should be dead, because its printed expiration date has passed, can be brought back to life in certain payment situations. The finding matters for anyone who carries a contactless payment card and for merchants that accept those cards, because expired cards are often forgotten in drawers or thrown away without being physically destroyed.

Contactless payment cards contain a small chip and an antenna that let them communicate with a payment terminal using near-field communication, or NFC. NFC is a short-range wireless technology that works only when the card is held very close to the terminal. When a contactless transaction happens, the card and terminal exchange data, including the card number, the card's expiry date, and a cryptographic proof that the card is genuine. The expiry date is an important security control: it limits how long a card can be used and forces the cardholder to receive a new card with a new chip and new security keys. Normally, when a card has passed its expiry date, both the card itself and the terminal should reject the transaction.

The Zombie Card Attack appears to target situations where a terminal cannot immediately contact the bank that issued the card. Many payment terminals are designed to work even when the network is temporarily down, for example in a parking garage, a vending machine, or a rural shop with poor connectivity. In these offline transactions, the terminal may rely on data from the card and a set of rules stored on the terminal to decide whether to accept the payment. If the terminal's software does not correctly enforce the card's expiry date, or if an attacker can trick the terminal into ignoring that date, an expired card could be accepted. The attack may also involve manipulating the card's chip data or using a device that emulates a card and sends a fake expiry date. While the full technical details have not been released, the consequence is clear: an expired card that should be rejected can be used to pay for goods or services.

The practical risk is highest for stolen or discarded expired cards. Many people simply cut a card in half and throw it away, but the chip and antenna can remain functional if the cut does not sever the right parts. A criminal who finds an expired card could try to use it at a terminal that does not check the expiry date online. Because the payment network may still route the transaction to the issuer, the issuer might detect the expired status and decline it, but in some offline scenarios the issuer is not contacted until later, by which time the criminal has left with the goods. Merchants may then face a chargeback or be left with a loss. Cardholders may find it harder to dispute a transaction made with their own card, even if it was expired, because they may have failed to report the card lost or stolen.

For website owners and businesses that accept payments, this research is a reminder that payment security is not only about the checkout page on your website. Many organisations operate physical point-of-sale terminals, unattended kiosks, or mobile card readers, and those devices run software that must be updated and configured correctly. Outdated terminal software is a common weak point. If a terminal does not enforce expiry dates or has been set to accept offline transactions too broadly, it could become a target for this type of attack. Payment terminal vendors and acquirers issue firmware updates that fix such issues, and merchants should apply them promptly. For organisations that manage payment terminals or connected IT infrastructure, working with a security-first IT partner such as AEU-I can help review device configurations, apply firmware updates, and segment payment networks from other systems to reduce the risk of these kinds of attacks.

Cardholders can take a few simple steps to protect themselves. When a card expires, destroy the chip and antenna as thoroughly as possible, not just by cutting the plastic once. Shred the card if you can, or cut it into several pieces across the chip. Keep an eye on bank and credit card statements, even for accounts you rarely use, because a charge from an expired card might otherwise go unnoticed. If you suspect your expired card was not destroyed or was lost, contact your bank and ask them to block the card number. Finally, consider using a mobile wallet such as Apple Pay or Google Pay, which adds an extra layer of security because the phone does not transmit the physical card's expiry date in the same way and often requires biometric authentication.

The security community has long warned that offline payment terminals are a weak spot because they must balance convenience with security. The Zombie Card Attack is the latest example of how an attacker can exploit that balance. As the payment industry moves toward faster, contactless-first experiences, it is crucial that security checks like expiry dates remain effective everywhere, not just when a terminal happens to be online.

How to Protect Yourself

  1. When a bank card expires, destroy it completely by cutting through the chip and antenna several times or using a shredder that can handle cards.
  2. Regularly check your bank and credit card statements for any unexpected small charges, even on old or rarely used accounts.
  3. If you have lost an expired card or think it was not properly destroyed, call your bank immediately and ask them to block that card number.
  4. Turn on transaction alerts from your bank so you get a text or app notification for every payment, making it easier to spot fraud quickly.
  5. If you run a shop or business with a card reader, ask your payment provider to confirm the terminal software is up to date and set to reject expired cards.

Related AEU services