UMass Researchers Expose 2-Phone Loophole That Revives Expired Credit Cards for Fraud
Updated
Updated · UMass News and Media Relations · Aug 17
UMass Researchers Expose 2-Phone Loophole That Revives Expired Credit Cards for Fraud
2 articles · Updated · UMass News and Media Relations · Aug 17
Summary
USENIX Security 2026 research found some expired credit cards can still be used for in-store fraudulent charges after replacement, creating what UMass Amherst researchers call “zombie” cards.
Two off-the-shelf smartphones and basic emulator software let attackers relay an NFC tap, capture card data, and rewrite the expired date to any future date before presenting it to the point-of-sale terminal.
The attack works because card accounts outlive the plastic and the printed expiration date is not cryptographically protected; some banks also fail to verify the terminal-read date against authenticated card data.
Lab tests and real purchases at local dining facilities and grocery stores showed the loophole works on some cards, while digital wallets were more resistant to this specific exploit.
UMass said major card companies were notified and urged consumers to destroy expired cards, since discarded cards may still expose millions of accounts if stolen.