CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Researchers find a loophole that lets expired credit cards make unauthorized payments

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4746

As cited

Copy frozen at (site build).

vulnerabilities

Researchers find a loophole that lets expired credit cards make unauthorized payments

Researchers at the University of Massachusetts Amherst discovered that contactless credit cards can process payments after their printed expiration dates, even when cardholders have received replacement cards. The team presented this vulnerability, called the Zombie Card attack, at USENIX Security 2026 and noted that the issue stems partly from cardholders failing to properly destroy expired cards as instructed by issuers.

Why it matters: Financial institutions and payment processors need to implement controls to deactivate expired cards at the point of sale, as cardholders are unlikely to reliably destroy old cards and fraudsters can exploit dormant contactless credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Researchers find a loophole that lets expired credit cards make unauthorized payments

Researchers at the University of Massachusetts Amherst discovered that contactless credit cards can process payments after their printed expiration dates, even when cardholders have received replacement cards. The team presented this vulnerability, called the Zombie Card attack, at USENIX Security 2026 and noted that the issue stems partly from cardholders failing to properly destroy expired cards as instructed by issuers.

Why it matters: Financial institutions and payment processors need to implement controls to deactivate expired cards at the point of sale, as cardholders are unlikely to reliably destroy old cards and fraudsters can exploit dormant contactless credentials.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary