The loophole that enables an expired
credit card to be revived is based on a relay system using software that can be
run on two standard smartphones and the physical card. The researchers found it
worked across a variety of point-of-sale terminals. Credit: Raja Hasnain Anwar,
UMass Amherst
A new security loophole discovered
by researchers from the University of Massachusetts Amherst can bring some
expired credit cards back to life. If stolen, these "zombie credit
cards" could leave cardholders vulnerable to fraudulent charges, according
to the new study, presented at the conference USENIX Security 2026.
The researchers discovered that
thieves "can still use the victim's expired credit card, despite the
victim receiving another card," says Taqi Raza, assistant professor in the
Riccio College of Engineering at UMass Amherst.
This loophole exists because credit
card accounts do not expire with the physical card. For instance, if you make a
return, your account will be refunded, even if the purchasing credit card has
expired. But this made Raza wonder: "If the card can get a refund, can the
card make a payment?"
For some credit cards, the answer
is yes. Raza and his research team devised a system using two off-the-shelf
smartphones and basic emulator software to fool an in-store card reader, also
known as a point-of-sale (POS) terminal, into thinking a card was active.
How the relay attack works
Using the same technology that enables tap-to-pay transactions (near-field communications, or NFC), the first phone is used to activate the credit card. It tells the card: A purchase is trying to be made, so send over the cardholder data and payment application. This includes the past-due expiration date.
However, using a
"man-in-the-middle" Wi-Fi-based relay system, the second phone takes
the credit card information but rewrites the expiration date. Here is a video
of the relay system in action.
Raja Hasnain Anwar, the lead author
of the study and doctoral candidate with the Khwarizmi Lab at UMass Amherst,
notes that this attack is particularly dangerous because thieves do not need to
determine the actual expiration date of a replacement card; any arbitrary
expiration date in the future is sufficient to successfully make a charge.
"The expiration date printed
and stored on the card is the only way for the POS to know whether the card is
active or expired," he says. "Yet it is not cryptographically
protected. So we can easily modify it to fool the POS."
This second phone is then tapped to
the card reader. To an outside observer, the behavior would look the same as
using any kind of digital wallet.
Where the checks break down
"Now, you're expecting the
bank should notice it," says Raza. But not all banks verify the
terminal-read expiration date against authenticated data. If other security
measures are not in place to recheck card lifecycle status, the fraudulent transaction
will be successful.
In fact, credit cards have another
expiration date in addition to the one printed on your card: a date embedded in
the security key that encrypts the transaction between the card and the bank,
referred to as a digital certificate. This digital certificate is checked
first, enabling the card to "talk" to the POS.
"What we found is that the
expiration date for the digital certificate for the security key is longer than
the expiration date of return on the card," says Raza, making this date an
ineffective check of the card's actual expiration status.
The researchers demonstrated that
this loophole works both in the lab and in the wild—at local dining facilities
and grocery stores. However, not all credit cards were equally affected by this
loophole, and digital wallets included additional security measures that made
them more resilient against this particular kind of attack.
However, separate research from
Raza's lab has found digital wallets are susceptible to other
types of exploitation.
A fragmented payment system
The root cause of such issues lies
in how payment cards and systems have evolved over time. As we move to smarter but
distributed systems, decisions are divided between the card chip, POS terminal,
payment networks (e.g., Visa, Mastercard), and the bank. Discrepancies often
arise, such as the ability to fool a terminal with a limited view of card
expiration when the bank relies on that terminal's verification.
"With the
rise of AI, it is becoming increasingly easy for attackers to spot these
discrepancies and devise exploits, effectively putting millions of credit cards
at risk," says Anwar.
How to dispose of old cards
While the
major card companies have been notified of their discovery, Raza says consumers
should still abide by safe credit card practices.
"The
attack exploits a documented misconception—expired cards are widely assumed
inert, so cardholders discard them carelessly," says Raza. "Always
discard your expired card, no matter what. Even if you permanently close your
credit card, still monitor transactions on the closed account."
Start by demagnetizing the card by slowly running a magnet along the magnetic strip. Next, destroy the embedded chip either with a hammer or scissors. Cut apart your card or put it through a paper shredder, ensuring you cut through any raised letters or numbers. Finally, separate the credit card pieces into different trash cans. For metal cards, contact your company's customer service department. Fraudulent charges should be immediately reported to your bank.
Provided by University of Massachusetts Amherst
Source: When zombie credit cards attack—a loophole that can reanimate expired cards

No comments:
Post a Comment