As cited
Citation snapshot as of .
vulnerabilities
Risky Bulletin: Expired cards can be used for new transactions
Academics at the University of Massachusetts Amherst disclosed an attack that exploits incomplete encryption in NFC contactless payment cards. The technique intercepts transaction data via man-in-the-middle tactics, modifies the expiration date without invalidating the card's signature, and relays the altered payment to a point-of-sale terminal to execute unauthorized transactions.
Why it matters: Merchants and payment processors should assess their NFC terminal validation logic, as this attack affects contactless card acceptance workflows and could enable fraud with expired cards in their payment infrastructure.
- Source published
- First seen by Cybersecurity Tracker