Executive Summary
Researchers at the University of Massachusetts Amherst demonstrated a critical vulnerability in Visa contactless payment systems that allows attackers to revive expired credit cards for fraudulent transactions. The 'Zombie Card' attack exploits a cryptographic binding weakness in Visa's Kernel 3 EMV implementation, enabling attackers with physical access to expired cards and NFC relay equipment to modify expiration dates without breaking card cryptography. Testing across five major US banks showed one bank approved fraudulent transactions up to $500, while others either declined or failed the modification. The attack requires the original account to remain open and relies on issuers not independently verifying expiration dates during authorization, exposing fundamental flaws in contactless payment security architecture.
This vulnerability highlights the growing sophistication of payment card fraud techniques as contactless transactions become mainstream, with researchers identifying similar NFC relay malware like WindRelay actively targeting victims across Europe, demonstrating that theoretical academic research quickly translates into real-world criminal exploitation.
Why This Matters Now
With contactless payments surging post-pandemic and NFC relay attacks becoming weaponized by criminal groups, this Visa vulnerability exposes critical flaws in payment infrastructure that millions rely on daily, demanding immediate attention from financial institutions and payment processors.
Attack Path Analysis
The Zombie Card attack exploits NFC contactless payment systems through physical possession of expired cards and man-in-the-middle relays. Attackers first obtain physical access to expired cards and deploy NFC-capable devices as relay intermediaries. They then leverage Visa Kernel 3's lack of cryptographic binding for expiration dates to modify terminal-facing data while preserving issuer authentication. The attack establishes real-time communication between compromised cards and legitimate POS terminals through Wi-Fi-connected Android devices. Financial data is exfiltrated through successful fraudulent transactions that bypass both terminal and issuer validation. The impact results in unauthorized purchases and potential financial losses across affected banking institutions.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attacker obtains physical possession of expired Visa contactless cards and deploys NFC-capable Android devices running custom card-emulator software to establish man-in-the-middle relay between card and POS terminal
MITRE ATT&CK® Techniques
Network Sniffing
Adversary-in-the-Middle
Input Capture: Keylogging
Data Manipulation: Transmitted Data Manipulation
Data from Cloud Storage Object
Exfiltration Over C2 Channel
Phishing: Spearphishing Link
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Cryptography and Security Protocols
Control ID: Requirement 4.2.1
PCI DSS 4.0 – User Identity Verification
Control ID: Requirement 8.2.1
NYDFS 23 NYCRR 500 – Penetration Testing
Control ID: Section 500.15
DORA – Identification and Classification of ICT Risk
Control ID: Article 8
CISA ZTMM 2.0 – External Information Systems
Control ID: Function ID.AM-4
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Banking/Mortgage
Zombie Card attack directly exploits Visa contactless payment vulnerabilities, enabling unauthorized transactions with expired cards, requiring immediate PCI compliance and fraud detection upgrades.
Financial Services
Payment processing systems face cryptographic bypass risks through NFC relay attacks, demanding enhanced terminal verification and real-time transaction monitoring capabilities across payment networks.
Retail Industry
Point-of-sale terminals vulnerable to man-in-the-middle attacks enabling fraudulent transactions, requiring upgraded EMV kernel implementations and enhanced terminal security validation protocols.
Restaurants
Contactless payment acceptance creates exposure to NFC relay fraud attacks, necessitating terminal upgrades with Relay Resistance Protocol and improved transaction verification systems.
Sources
- Zombie Card Attack Can Revive Expired Visa Cards for Contactless Paymentshttps://thehackernews.com/2026/08/zombie-card-attack-can-revive-expired.htmlVerified
- When Zombie Credit Cards Attack: UMass researchers discover loophole that can reanimate expired cardshttps://www.umass.edu/news/article/when-zombie-credit-cards-attack-umass-researchers-discover-loophole-can-reanimateVerified
- USENIX Security Symposium 2026 - Zombie Card Attack Research Paperhttps://www.usenix.org/system/files/usenixsecurity26-anwar.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely constrain this NFC relay attack's digital infrastructure components by limiting network reachability between compromised devices and payment processing systems. While physical card exploitation cannot be prevented, segmentation controls would reduce the blast radius of successful fraudulent transactions.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Network segmentation policies would likely limit the relay devices' ability to establish unauthorized connections with backend payment processing infrastructure and reduce their reachability to critical financial systems.
Control: Zero Trust Segmentation
Mitigation: Identity-aware access controls would likely restrict the modified card data's ability to traverse network segments, constraining privilege escalation attempts within payment processing workflows and reducing transaction scope.
Control: East-West Traffic Security
Mitigation: Network segmentation between POS terminals and backend systems would likely constrain lateral movement capabilities, reducing the attacker's ability to propagate the relay technique across multiple merchant environments.
Control: Multicloud Visibility & Control
Mitigation: Network traffic analysis would likely detect and constrain the real-time Wi-Fi communications between relay devices, reducing the reliability of command and control channels within the payment environment.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound traffic controls would likely limit the volume and scope of fraudulent transaction data that could be exfiltrated through payment networks, constraining the financial impact across merchant categories.
While segmentation controls would reduce the attack's network reach, successful relay transactions could still result in unauthorized purchases, though the overall blast radius would likely be constrained to fewer merchant terminals and payment systems.
Impact at a Glance
Affected Business Functions
- Payment Processing Systems
- Point-of-Sale Terminal Operations
- Contactless Transaction Security
- Card Authentication Services
Estimated downtime: N/A
Estimated loss: N/A
Potential unauthorized transactions using expired Visa contactless cards. The attack allows fraudulent purchases but does not expose cardholder data directly. Financial exposure limited to transaction amounts processed before detection by issuing banks.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to isolate payment processing systems and prevent lateral movement between merchant terminals and backend financial networks
- • Deploy Multicloud Visibility & Control to monitor anomalous payment interactions and detect repeated malformed NFC communication patterns in real-time
- • Enable Threat Detection & Anomaly Response capabilities to baseline normal transaction timing and alert on suspicious relay-induced latency patterns
- • Establish Egress Security & Policy Enforcement to control outbound financial data flows and prevent unauthorized transaction data exfiltration
- • Deploy Encrypted Traffic (HPE) controls to secure payment data in transit between terminals, processors, and issuing banks with line-rate encryption



