CYBERSECURITYTRACKER
TRACKING4,485 stories844 vuln stories
Permanent story citation

Risky Bulletin: Expired cards can be used for new transactions

The story is preserved as cited. Later corrections remain visibly typed and adjacent to the original snapshot.

← newsStory 4899

As cited

Citation snapshot as of .

vulnerabilities

Risky Bulletin: Expired cards can be used for new transactions

Academics at the University of Massachusetts Amherst disclosed an attack that exploits incomplete encryption in NFC contactless payment cards. The technique intercepts transaction data via man-in-the-middle tactics, modifies the expiration date without invalidating the card's signature, and relays the altered payment to a point-of-sale terminal to execute unauthorized transactions.

Why it matters: Merchants and payment processors should assess their NFC terminal validation logic, as this attack affects contactless card acceptance workflows and could enable fraud with expired cards in their payment infrastructure.

Source published
First seen by Cybersecurity Tracker

Source attribution