University researchers have demonstrated that expired contactless credit cards can still be used to carry out fraudulent transactions. The study, presented at USENIX Security 2026, exposes a serious flaw in modern payment systems — one that affects certain Visa contactless cards and payment terminals that fail to properly validate expiration dates.
The Vulnerability Uncovered by Researchers
How the Attack Works with Expired Contactless Cards
A team from the University of Massachusetts Amherst conducted extensive testing and found that some expired contactless cards remain fully operational. The root cause is straightforward: certain payment terminals simply do not verify the card’s expiration date at all.
The attack exploits a man-in-the-middle technique. An attacker positions themselves between the card and the terminal, intercepting and manipulating transaction data mid-transmission. The terminal detects nothing unusual and authorizes the payment as if everything were legitimate.
Not every card is equally at risk, however. The research points primarily to certain Visa card issuances as the main exposure point. Not all banks and payment networks are affected.
The Technical Mechanics Behind the Exploit
To understand the issue, it helps to know how contactless communication works. When a card interacts with a terminal, it transmits encrypted data — including the card’s expiration date as one of the data fields.
The problem arises when a terminal fails to actively validate that field. Some terminals rely on the card itself to self-report its validity rather than independently checking it. This creates a window for manipulation: an attacker can alter the expiration date field during transmission, and the terminal accepts the transaction without further scrutiny.
The result is that a physically expired card can successfully complete a real payment — without any involvement or awareness from the cardholder.
Impact on Businesses and Consumers
Why CISOs Should Take Notice
For enterprise security leaders, this research deserves close attention. Organizations typically manage fleets of corporate cards, and some of those cards may be expired yet still physically in circulation. Former employees who have left the company might still have them in their wallets.
IT and security teams need to revisit card decommissioning procedures. Cancelling a card in internal systems is not enough. Physical terminals must also be confirmed to correctly enforce expiration date checks.
Organizations operating their own payment terminals carry a share of the responsibility too. Terminals must be kept up to date with the latest security standards — accountability doesn’t rest solely with the issuing banks.
Real-World Risk for Cardholders
For individual consumers, the most immediate concern is unauthorized charges. A lost or discarded expired card could be weaponized by a bad actor, while the cardholder — assuming the card is useless — may never think to monitor their statement for related activity.
That said, it’s important to keep perspective: this is a laboratory-demonstrated vulnerability, not a documented mass-exploitation campaign. No active criminal operations exploiting this flaw have been identified at this time.
Research Context and Industry Accountability
USENIX Security 2026: A Benchmark for Responsible Disclosure
Presented at USENIX Security 2026 — one of the most respected academic venues in cybersecurity — this research followed established responsible disclosure practices. Visa and terminal manufacturers were notified in advance, and the research community respected the necessary timelines to allow for potential remediation. No ready-to-use offensive tools were made public.
What Fixes Look Like
The payments industry now faces a clear call to action. Terminal manufacturers need to push firmware updates, and banks must verify that their systems enforce proper expiration date validation.
The issue also points to a deeper structural problem. EMV standards for contactless payments do require expiration date verification — but not all terminals implement those standards fully or consistently. The gap between what the standard mandates and what gets deployed in the field is where this vulnerability lives.
On the consumer side, the fix is simple and low-tech: physically destroy expired cards. Cutting through both the chip and the NFC antenna renders the card useless for attacks of this kind.
Conclusion
The discovery that expired contactless cards can still process real payments is a wake-up call — not a sign of imminent crisis, but a clear indicator of a gap in payment security controls. The industry must respond with concrete, verifiable updates. Until terminals universally enforce what the standards already require, the risk remains open.
Sources:
- The Register – Expired credit cards revived by researchers
- Risky Biz News – Expired cards can be used for new transactions
- Pasquale Pillitteri – Zombie Cards: Expired Visa Contactless Payments
- Original source – Risky Biz RBNEWS604
Source: Original article
Vulnerabilities like the expired contactless card flaw make one thing clear: financial organizations and security teams need fast, reliable channels for sharing intelligence on emerging threats. IsacChain enables secure threat intelligence sharing between ISACs and sector operators, with blockchain-guaranteed traceability and automated NIS2 compliance features that streamline regulatory obligations. In an environment where attack vectors evolve rapidly, having a verifiable and trustworthy collaboration platform can mean the difference between a reactive response and a proactive one. Discover how IsacChain can help your organization at www.isacchain.com