Cookie Consent by Free Privacy Policy Generator

Zombie Card attack: expired credit cards continue processing payments

Researchers from the University of Massachusetts Amherst have disclosed a significant vulnerability in contactless payment systems that allows expired credit cards to continue processing transactions even after their printed expiration date has passed and replacement cards have been issued. Help Net Security reports that the research team, presenting their findings at USENIX Security 2026, demonstrated what they call the "Zombie Card attack", showing that the contactless chip in an expired card remains functional and can authorise payments despite the card being officially invalid. The vulnerability exists because the contactless payment protocol does not consistently enforce expiration date validation at the point of transaction, and many cardholders retain expired cards rather than destroying them as instructed by issuers.

Why this matters for UK organisations

For UK businesses that handle payment processing, issue corporate credit cards, or manage expense systems, this finding highlights a fundamental gap in how payment security controls are implemented and enforced. The research demonstrates that the expiration date printed on a card is not a reliable security boundary in contactless transactions, and that organisations cannot assume an expired card is automatically disabled. This has direct implications for corporate expense policies, fraud detection systems, and the controls around card lifecycle management. Organisations that rely on card expiration as a control point for limiting employee spending authority or managing vendor payments may find that expired cards continue to function longer than expected, creating both financial and audit risk. The vulnerability also affects how organisations manage the return of corporate cards when employees leave, change roles or reach spending limits, as the assumption that an expired card is no longer usable may not hold in practice.

What to review

Finance teams should review corporate card policies to ensure that card cancellation processes do not rely solely on expiration dates, and that employees are explicitly required to return or destroy expired corporate cards rather than retaining them. Expense management systems should be configured to actively validate card status and flag transactions from cards that should no longer be active. Organisations should verify that fraud detection rules account for the possibility of expired cards being used, and that transaction monitoring includes checks for cards that have passed their expiration date. HR and finance teams should also review offboarding processes to ensure that corporate card return and cancellation procedures are clearly documented, tracked and completed, and that card issuers are notified when cards need to be deactivated rather than relying on expiration dates as an automatic control. Organisations may also wish to consider whether audit processes include periodic reconciliation of active cards against authorised users and whether controls are in place to detect cards that remain in use beyond their intended lifecycle.

Source: Help Net Security

News and blog posts
Today's stories reflect how quickly the operational security landscape is...
CISA, the FBI and the NSA have issued a joint cybersecurity advisory warning...
Researchers from the University of Massachusetts Amherst have disclosed a...
The Guardian has published an investigation into the growing use of Meta's...