Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

A new type of attack, dubbed a “Zombie Card” exploit, has been discovered that can breathe life back into expired contactless payment cards. This clever technique allows hackers to revive and reuse compromised card data for malicious purposes, putting millions of users at risk.

The Zombie Card attack works by exploiting vulnerabilities in the payment processing system, specifically targeting contactless transactions. When a card is used for a contactless payment, it sends a unique identifier to the payment terminal, which then forwards this information to the bank’s server for verification. If the card has expired or been compromised, the bank typically flags it and prevents further transactions.

However, hackers have found a way to manipulate these systems by injecting fake data that mimics legitimate contactless payments. This allows them to bypass security checks and revive the compromised card’s credentials, making it possible to use the card for malicious purposes once again.

The impact of this attack is significant, as millions of people use contactless payment methods every day. According to a recent study, over 70% of credit card issuers in the US have reported instances of Zombie Card attacks on their systems. This means that anyone who has used a contactless payment method recently may be at risk.

The main reason why this attack is so effective lies in the way modern payment processing systems are designed to prioritize convenience and speed over security. Contactless payments, for example, rely heavily on tokenization – a technique that replaces sensitive card information with anonymous tokens. While this makes transactions faster and more secure, it also creates vulnerabilities like the Zombie Card exploit.

As a result of this attack, banks and financial institutions must rethink their security measures to prevent similar exploits in the future. This may involve implementing additional checks and balances on contactless transactions or developing new technologies that can detect and prevent these types of attacks.

For individuals, there is a simple takeaway: be aware of your card’s expiration date and monitor your accounts regularly for any suspicious activity. If you have used a contactless payment method recently, it’s essential to keep an eye out for any potential problems – whether it’s unusual transaction activity or notifications from your bank about compromised cards.


Source: The Hacker News — 2026-08-20