Cyber Security

Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments

IT Club Editorial7 minutes read30 August 2026
WhatsAppEmail
Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments

Keep up with IT Club

Add IT Club as a preferred source in Google Search.

USENIX Security 2026 research from the University of Massachusetts Amherst shows how a relay can make an expired Visa contactless card appear unexpired to a checkout terminal under particular conditions. This defensive guide explains what was tested, what was not, why the result depends on the issuer and terminal, and what cardholders and businesses should do when an old card reaches the end of its life.

Most people treat an expired payment card as dead. The date printed on the front has passed, the bank has sent a replacement and the old piece of plastic is now an administrative leftover. That assumption is usually sensible. It is also exactly the assumption that a new piece of payment-security research asks us to examine.

Researchers from the University of Massachusetts Amherst presented “Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments” at USENIX Security 2026. Their finding is precise: in particular Visa contactless payment configurations, a relay could make an expired card appear unexpired to a checkout terminal. The result depended on the card, terminal, issuer and payment path. It was not a demonstration that every expired Visa card works, and it was not a break of Visa’s card cryptography.

An expired card should not be treated as harmless until it has been securely destroyed. But “some expired cards worked under test conditions” is not the same claim as “every expired card can be used”.

The quick answer

The research found a gap in how expiry is checked across a distributed contactless payment system. A controlled relay changed the expiry value read by a checkout terminal while leaving the card’s normal cryptographic responses intact. Where the terminal and issuer did not independently enforce the same lifecycle state, an expired card could still reach a successful transaction.

  • The tested scenario required physical possession of the card or sustained NFC proximity, plus a relay between card and terminal.
  • The result was observed in particular Visa contactless configurations across tests involving five major US banks.
  • The researchers report the underlying issue at $1, $100 and $500 when the relevant issuer and terminal conditions allowed it.
  • The Mastercard, American Express and Discover configurations tested rejected the change; that is not a universal guarantee for every implementation.
  • The practical response is straightforward: expire the card in your records, revoke it with the issuer, destroy the physical card and verify afterwards.

Checked: 30 August 2026. Payment-network rules and issuer controls vary by country, card product, terminal and time. This article explains the published research; it is not a recommendation to test payment systems yourself.

What the researchers actually found

Contactless payments are not decided by one object. A card, a point-of-sale terminal, the merchant’s acquiring bank, a payment network and the issuing bank each contribute to the transaction. Expiry is meant to be a simple lifecycle rule, but the parties do not necessarily receive or validate the same representation of that rule.

Physical card → contactless terminal → payment network → issuing bank
       expiry view          transaction data       lifecycle decision

In the Visa contactless configuration studied, the terminal reads an expiry date from the card. The researchers report that this particular value was not protected by the card’s digital signature in the same way as other security information. A relay could therefore change what the terminal saw, while the card’s genuine cryptographic responses continued through the transaction.

That distinction matters. The card was not impersonated by inventing a valid cryptogram. The problem was that one part of the system could be shown a different expiry state from the one a person expected, while another part still saw an authentic-looking payment response. The security question was divided across boundaries, and the boundaries did not always agree.

This was a relay problem, not a remote card-number trick

The published research describes a man-in-the-middle relay between the physical card and the contactless terminal. In plain English, the card still had to be present or kept close enough to communicate, and the payment conversation had to be relayed to the checkout. Knowing a card number, expiry date or security code would not by itself reproduce this contactless scenario.

The relay also had to stay within the payment system’s timing expectations. The researchers’ project page says the added delay remained within the normal response allowance in their setup. That is a useful technical detail for understanding the result, not an instruction to reproduce it.

Do not turn a published security finding into a home experiment. Payment testing should be performed only by authorised researchers with owned cards, informed merchants, a controlled account and a responsible disclosure route.

What was tested — and what was not

The study evaluated real-world transaction configurations across multiple EMV kernels, point-of-sale terminals, merchants and five major US banks. The project summary identifies Visa as the susceptible configuration in the reported experiments. It says that the Mastercard, American Express and Discover configurations tested rejected the change.

Published resultThe careful interpretation
Visa contactless transactions were susceptible in the tested configurationA particular Visa contactless path did not protect or independently enforce expiry strongly enough in the tested conditions.
Mastercard, American Express and Discover configurations rejected the changeThose tested configurations rejected the manipulation; this is not a promise that every implementation everywhere is identical.
The issue was observed at $1, $100 and $500Amount did not prevent the underlying issue when the issuer and terminal conditions allowed it. Other transaction rules may still stop a payment.
Some live merchant purchases succeeded in the researchThe researchers used controlled, authorised testing and paid the charges. This does not make unauthorised testing acceptable.

The research does not establish that every Visa card, every bank, every terminal or every country is affected. It also does not establish that the same issue applies to chip-insert transactions. Contactless and contact payment paths have different interactions and checks.

Expiry, revocation and destruction are different controls

One reason the result is useful beyond payment cards is that it exposes a common lifecycle mistake: treating a label as if it were a complete security action. Expiry is a date. Revocation is a decision by the issuer or account owner that a credential should no longer be accepted. Destruction removes the physical object that can present the credential.

ControlWhat it meansWhat it does not prove
ExpireThe card reaches the end date printed or encoded for its product lifecycle.That every part of the payment chain will independently reject the old physical card.
RevokeThe issuer marks the card or payment credential as no longer authorised.That an old physical card has disappeared or that every local terminal check has the same state.
DestroyThe chip, magnetic stripe, printed numbers and other usable card surfaces are made unusable.That a replacement account has been closed or that suspicious transactions will be noticed without monitoring.
VerifyA person or business confirms the issuer state, disposal record and monitoring route.That security is permanent without repeating the lifecycle process when cards or staff change.

The card is only one trust boundary

The most important lesson is not “Visa is bad” or “contactless is broken”. It is that a payment is a chain of decisions. The card can produce a genuine cryptographic response. The terminal can make a local decision. The network can route an authorisation. The issuer can approve or decline. If each part assumes that another part has enforced expiry, a lifecycle control can become nobody’s complete responsibility.

Ask the boundary question

Whenever a business relies on a credential becoming unusable, ask: which system has the authoritative state, which system verifies it, what evidence crosses the boundary and what happens if the two answers disagree?

  • For payment cards: does the issuer revoke the old card as soon as the replacement is active?
  • For staff access: does disabling the account also remove sessions, tokens, keys and local access?
  • For suppliers: does contract termination also remove shared accounts, API credentials and cached copies?
  • For devices: does a wipe request produce evidence that the device was actually reset or destroyed?

What cardholders should do

There is no need to stop using ordinary contactless payments because of this research. The proportionate response is to stop treating old cards as harmless rubbish. When a replacement arrives or a card expires, follow the issuing bank’s disposal guidance.

  1. 1Confirm that the replacement card is active and ask the issuer how the old card is being revoked.
  2. 2Cut through the embedded chip, magnetic stripe, printed card number and security code, or use the issuer’s approved return service.
  3. 3Do not put an intact old card in a drawer, desk bin or shared recycling box while assuming the date makes it useless.
  4. 4For metal cards, contact the issuer rather than trying to cut the card with unsuitable tools.
  5. 5Keep transaction alerts enabled and monitor the old or replaced account for unexpected activity.
  6. 6Report a suspicious transaction to the bank immediately using the bank’s official contact route.

What businesses should add to the card lifecycle

A business may hold more payment cards than it realises: purchasing cards, fuel cards, corporate cards, expense cards, spare cards and cards assigned to people who have left. A replacement email or a note in an accounting system is not the same as proving that the credential is no longer usable.

Lifecycle momentBusiness controlEvidence to keep
IssueRecord the cardholder, purpose, spending limit, approving owner and issuer contact route.Inventory entry and approval record.
Change role or leaverRemove the card from wallets, expense tools, recurring payments and shared purchasing processes.Revocation confirmation and a named person responsible for collection.
Replace or expireConfirm issuer-side revocation and destroy the old physical card through an approved process.Date, card reference or last four digits, disposer and destruction confirmation.
After disposalKeep alerts and account review in place for a sensible period, especially where a replacement or closed account remains open for refunds.Monitoring owner, review dates and escalation record.

Do not store full card numbers or security codes in an internal spreadsheet just to make the inventory easier. Use the minimum reference needed to identify the card, restrict access to the record and follow the organisation’s payment-data obligations.

The “Is It Really Dead?” test

Before closing a card lifecycle ticket, a manager or control owner should be able to answer five plain questions:

  • Has the issuer or provider marked the old credential as revoked, not merely past its printed date?
  • Has the physical card been collected, cut or returned through an approved route?
  • Have recurring payments, expense platforms and digital wallets been checked for the replacement?
  • Who will notice an unexpected transaction on the old or closed account?
  • Can we show an evidence trail without retaining unnecessary payment data?

EXPIRE → REVOKE → DESTROY → VERIFY

A simple control to remember

Use the four-word sequence whenever a physical credential is replaced: EXPIRE the item in the lifecycle record, REVOKE it with the authority that accepts it, DESTROY or return the physical object, then VERIFY that the old path is no longer trusted and that monitoring is still active.

  • EXPIRE — record the end of the intended lifecycle.
  • REVOKE — make the authoritative service reject the old credential.
  • DESTROY — remove the physical or local artefact that could still present it.
  • VERIFY — check the result and watch for exceptions.

Operational Heartbeat: lifecycle state drifts

A card inventory is not a set-and-forget spreadsheet. People change roles, suppliers change processors, banks change control paths, payment apps retain old credentials and staff work around a process when it becomes inconvenient. A quarterly or event-driven review should sample issued, replaced, expired, revoked and destroyed cards and compare the records with the issuer, expense platform and finance owner.

The same Operational Heartbeat applies to other credentials. Review which accounts, tokens, keys, badges, devices and supplier identities are meant to be dead; which system is authoritative; what evidence proves revocation; what physical or cached copies remain; and what alerts would reveal a failure.

Security lifecycle controls need an Operational Heartbeat: expiry, revocation, destruction, evidence and monitoring should be reviewed rather than assumed to remain aligned.

Primary sources and further reading

This article is based on the authors’ paper, the UMass Amherst research announcement and the authors’ project page. The official payment-network pages provide useful context on contactless transactions; they are not evidence that every issuer or terminal behaves identically.

USENIX Security 2026 — Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments

UMass Amherst — When Zombie Credit Cards Attack

Khwarizmi Lab — Zombie Cards Back Online research project

Visa — Contactless payments and how tap to pay works

Mastercard — Contactless payments

Read next: Cyber Insurance for Small Businesses

Read next: Zero Trust Security for Small Businesses

Plain-English Takeaway

An expired physical card should not be treated as harmless until it has been securely destroyed. The Zombie Card research found a specific contactless Visa configuration in which a relay could alter the expiry date seen by the checkout terminal while leaving the card’s normal cryptographic responses intact. This was tested under particular issuer, terminal and payment-network conditions; it does not mean every expired Visa card can be used. Cardholders should follow their bank’s destruction guidance, and businesses should link expiry, revocation, physical disposal and transaction monitoring.

Follow The IT Club Briefing on WhatsApp

Tap to follow The IT Club Briefing on WhatsApp.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor