Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

A new type of attack is making waves in the cybersecurity community, threatening the security of contactless payment systems worldwide. Dubbed “Zombie Card,” this malicious technique can revive even expired Visa cards, allowing attackers to bypass traditional authentication measures and make unauthorized transactions.

The Zombie Card attack exploits a weakness in the way Visa’s tokenization system processes expired credit card numbers. When a card is cancelled or expires, its corresponding token – a unique identifier used for contactless payments – is supposed to be invalidated. However, an attacker can manipulate this process by creating a new token using the old card number, essentially “reviving” it. This allows the attacker to make purchases without needing the original card’s physical presence.

The attack is particularly concerning because it affects not only individuals but also businesses that use contactless payment systems. Any merchant accepting Visa payments through their mobile devices or terminals could be vulnerable to Zombie Card attacks. Furthermore, as these attacks can occur across different domains – meaning an attacker may target a specific business but use a token from another – they pose a significant challenge for law enforcement and security teams.

The mechanics of the Zombie Card attack involve exploiting the Visa payment protocol’s trust mechanisms. When a card is cancelled or expires, its status should be updated in the issuer’s database, triggering a revocation request to the tokenization system. However, if this process is manipulated, the old token can still be used for transactions. This vulnerability has been observed across multiple regions and countries, suggesting it may be more widespread than initially thought.

The implications of Zombie Card attacks are significant. Not only do they compromise individual financial security but also threaten the integrity of contactless payment systems as a whole. As more people rely on mobile wallets and contactless payments for convenience, the potential damage from such attacks grows exponentially. Moreover, this type of attack highlights the need for stronger authentication measures, particularly in high-risk environments like retail or public transportation.

So what can individuals do to protect themselves? First and foremost, be aware of any unusual transactions on your account. Monitor your statements regularly and report any suspicious activity to your bank immediately. Additionally, consider using two-factor authentication (2FA) whenever possible – this can significantly reduce the risk of unauthorized transactions. By staying vigilant and taking these precautions, you can minimize the impact of Zombie Card attacks on your financial security.


Source: The Hacker News — 2026-08-20