Tuesday, August 25, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud

A UMass Amherst team found that some expired Visa cards can be used for unauthorized purchases by altering the expiration date during a relay attack, according to TechSpot.

Featured image for Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud
Featured image for Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud

TechSpot reports that researchers at the University of Massachusetts Amherst have demonstrated a way to make some expired contactless credit cards usable again without the cardholder's consent. The findings were presented at the USENIX Security 2026 conference.

Assistant professor Taqi Raza and his co-authors explain that when a credit card reaches its expiration date, the underlying account does not automatically expire – even after the cardholder has received a replacement card. This gap led the team to test whether an expired card could still be prompted to authorize a transaction. According to the researchers, the answer is yes for certain Visa contactless cards.

The approach involves two off-the-shelf smartphones and basic emulation software. The first phone activates the expired card over NFC, the same short-range wireless technology used for tap-to-pay. Once activated, the card transmits its stored data, including its expiration date. A second phone then acts as a man-in-the-middle, relaying that data over Wi-Fi to a point-of-sale (POS) terminal while rewriting the expiration date before it arrives. In the affected Visa cards, the terminal accepts the modified date and clears the transaction.

The underlying flaw, as described in the research, is that a card's expiration date is stored in two separate places. There is an Application Expiration Date that the POS terminal reads locally, and a separate expiration field that the card issuer verifies later during online authorization. In Visa's contactless implementation, these two fields are not cryptographically linked. That means an attacker can alter the local value, and the change will not be caught by the checks designed to protect the second field. The researchers report that Mastercard, American Express, and Discover configurations resisted the same attack during their tests; only Visa's did not.

Raza noted that a digital payment system involves several independent parties – the card chip, the POS terminal, payment networks like Visa or Mastercard, and the issuing bank. Gaps between how each party enforces security checks are precisely where such exploits can occur. This points to a broader lesson for payment security: when multiple independent systems each enforce only part of the security checks, an attacker can exploit the differences between them. Coordinating those checks across the card, terminal, network, and issuer would be necessary to close the gap. "The attack exploits a documented misconception – expired cards are widely assumed inert, so cardholders discard them carelessly," Raza said, as quoted by TechSpot.

Because the attack requires physical possession of an expired card, it is not a remote threat. However, since expired cards are often thrown away without being destroyed, an attacker who retrieves one could potentially use it if the card is one of the vulnerable Visa models and the POS terminal has the same weakness. The researchers recommend that cardholders always dispose of expired cards properly. TechSpot lists the recommended method: demagnetize the magnetic strip, destroy the embedded chip with scissors, then shred the whole card, and even place the pieces in separate trash cans.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Philips LatteGo 4400 Series espresso machine on a kitchen counter.
Guides

Philips LatteGo 4400 espresso machine drops to AU$613 on Amazon Australia

Alice talks to Nora and Frank
Entertainment

How AI and assistive tools are helping disabled actors like Steve Way thrive on 'Furious'

Featured image for ICO audits reveal 'mixed picture' on police facial recognition, demanding urgent improvements
Cybersecurity

ICO audits reveal 'mixed picture' on police facial recognition, demanding urgent improvements