Security researchers from the University of Massachusetts Amherst have developed and demonstrated a proof-of-concept (PoC) attack named "Zombie Card." This attack method allows an expired Visa contactless credit card to be used for making unauthorized in-store purchases. The attack works by using a man-in-the-middle (MitM) relay to intercept the communication between the card and the point-of-sale (POS) terminal, modifying the expiration date in transit. The technique successfully bypasses the terminal's offline checks without breaking the card's cryptography, enabling fraudulent transactions. The findings were presented at the 35th USENIX Security Symposium.
The Zombie Card attack exploits a discrepancy in how a Visa contactless card communicates its expiration date during a transaction. The card transmits this information in two different formats. The attack specifically targets and modifies one of these formats, Tag-Length-Value tag 5F24, which is read by the POS terminal. The other format, which is used for online authorization with the card issuer, is left unchanged.
Attack Prerequisites:
Attack Flow:
5F24 tag containing the expiration date and modifies it to a future date.Because the terminal sees a valid expiration date, it approves the transaction, especially for small amounts that rely on offline authorization. The entire process adds only ~70 milliseconds, which is well within the 500ms EMV standard, thus evading detection by latency checks.
This is a proof-of-concept attack developed by academic researchers. There is no evidence that the "Zombie Card" technique is being used by criminals in the wild. However, the underlying principle of relay attacks for payment fraud is a known and active threat. The researchers disclosed their findings to Visa and affected banks in May 2025, but no public advisory or fix has been issued as of August 2026.
While the attack requires close physical proximity, it poses a tangible risk for lost or stolen expired cards. An attacker could potentially drain small amounts from multiple expired cards before the fraud is detected. The primary risk is financial fraud. The success of the attack demonstrates a weakness in the EMV contactless protocol's offline validation process, which could be exploited by more sophisticated criminal groups if the technique were to be weaponized.
Educate consumers to securely destroy expired credit cards.
Researchers disclose their findings on the 'Zombie Card' attack to Visa.
The research is presented at the 35th USENIX Security Symposium.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.