Zombie Card: An expired Visa credit card can be used for purchases


Did you know there is still a good reason to physically destroy your expired credit card? Scientific research found that the expiration date used by payment terminals on some contactless cards was not effectively protected against tampering.

University of Massachusetts Amherst researchers Raja Hasnain Anwar, Gerard DeCunha, and Muhammad Taqi Raza tested contactless cards across Visa, Mastercard, Discover, and American Express, using multiple terminals and merchants, and cards from five major US banks.

They found that a payment terminal could be tricked into seeing a future expiry date. Basically, they were able to modify the expiration date sent to the terminal to a future date. This allowed them to revive expired Visa contactless credit cards for real in-store purchases. Hence the name “Zombie Card.”

Read more…
Source:  MalwareBytes Labs


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Russian hackers target European firms with new spear-phishing cyberattacks

    February 24, 2026

    APT28, the infamous Russian state-sponsored hacking group also known as Fancy Bear, or Sofacy, has been observed targeting “specific entities” in Western and Central Europe with infostealers. In a newly released report, security researchers Lab52 from S2 Grupo detailed “Operation MacroMaze”, which has been ongoing since at least late September 2025 through January 2026. The campaign ...

  • Australia: Cyber attack takes major chicken processor Hazeldenes offline leaving businesses without meat

    February 23, 2026

    A cyber attack at major chicken meat processor Hazeldenes in central Victoria has led it to shutdown its wi-fi system on site, and a shortage of chicken at pubs and butchers across the state. Retail and industry have told the ABC that the chicken meat processor has been unable to fill some orders because it cannot ...

  • AWS says more than 600 FortiGate firewalls hit in AI-augmented campaign

    February 23, 2026

    Cybercriminals armed with off-the-shelf generative AI tools compromised more than 600 internet-exposed FortiGate firewalls across 55 countries in just over a month, according to a new incident report from AWS. The campaign, which ran from mid-January to mid-February, relied less on clever zero-days and more on the equivalent of trying every digital door handle – just ...

  • Massive Winos 4.0 Campaigns Target Taiwan

    February 20, 2026

    FortiGuard Labs recently observed several targeted phishing campaigns in Taiwan that use themes designed to exploit local business processes. These campaigns disseminate Winos 4.0 (ValleyRat) and subsequent malicious plugins through weaponized attachments or embedded links. The lures mimic official communications, such as tax audit notifications, tax filing software installers, and cloud-based e-invoice downloads. Fortinet researchers analysis ...

  • Age verification vendor Persona left frontend exposed

    February 20, 2026

    Researchers investigating Discord’s age-verification checks say they discovered an exposed frontend belonging to Persona, the identity-verification vendor used by Discord. It revealed a far more expansive surveillance and financial intelligence stack than a simple “teen safety” tool. A short while ago we reported that Discord will limit profiles to teen-appropriate mode until you verify your age. ...

  • ShinyHunters demands $1.5M not to leak Vegas casino and resort chain data

    February 20, 2026

    Las Vegas hotel and casino giant Wynn Resorts appears to be the latest victim of data-grabbing and extortion gang ShinyHunters. On Friday, the cybercrime crew listed the hospitality company on its blog, claiming to have stolen more than 800,000 records containing employees’ Social Security numbers and other private details. The extortionists set a February 23 deadline ...