Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Reviving the Dead: How Gaps in Expiry Checks Allow Expired Credit Cards to Make Unauthorized Payments


Researchers have discovered a critical vulnerability in the EMV payment process that allows expired credit cards to be revived and used for unauthorized payments. The findings have significant implications for the financial industry, and experts warn that this vulnerability could be exploited by attackers to turn digital intrusions into kinetic disasters.

  • Researchers at the University of Massachusetts Amherst discovered a critical vulnerability in the EMV payment process that allows expired credit cards to be revived and used for unauthorized payments.
  • The EMV payment process has a gap in the expiry check mechanism that can be exploited by attackers using NFC proxy devices.
  • The vulnerability affects Visa contactless cards and allows them to be used even after expiration, while Mastercard, American Express, and Discover configurations are resistant to the attack.
  • The researchers' findings have significant implications for the financial industry, highlighting the need for greater scrutiny of the EMV payment process.
  • The vulnerability is due to a trade-off between performance and security in the EMV protocol, leaving room for exploitation.



  • The world of digital payments has long been touted as a safe and secure method of transaction. However, a recent discovery by researchers affiliated with the University of Massachusetts Amherst has shed light on a critical vulnerability in the EMV payment process that allows expired credit cards to be revived and used for unauthorized payments. The researchers, led by Raja Hasnain Anwar, have demonstrated that it is possible to exploit a gap in the expiry check mechanism to make expired contactless credit cards appear valid to payment terminals.

    The EMV payment process involves a payment card (card or digital wallet in a phone) and a point-of-sale terminal communicating over a direct NFC channel, linked to a payment network (e.g., Visa, Mastercard, Discover) that links the merchant to a bank and a card issuer. The transaction process relies on the EMV contactless protocol, which is fragile because the transaction flow is selectively authenticated – some of the data gets sent between the card and terminal in plaintext and is only later linked to cryptographic verification using Offline Data Authentication (ODA) and issuer-verified cryptograms.

    This selective authentication leaves an opening for unwanted intermediary interference, which requires only the necessary knowledge and mobile phones acting as NFC proxies. In a recent study, the researchers demonstrated that they could meddle in a way that revives expired contactless payment cards to make purchases. They found that the EMV protocol implemented in EMV kernels is more permissive than others, allowing the POS terminal to evaluate processing restrictions based on the Application Expiration Date.

    However, the card issuer relies on an expiration date from a different data field in the online authorization request. These two dates should be cryptographically bound to each other, but they are not. This gap allowed the researchers to devise an attack using NFC proxy devices. Mastercard, American Express, and Discover configurations resisted the attack; Visa contactless cards did not.

    The researchers' findings have significant implications for the financial industry, as expired credit cards are a common occurrence. The Europay, Mastercard, and Visa (EMV) payment process is designed to ensure secure transactions, but the lack of effective integrity protection leaves a window of opportunity for attackers to exploit.

    Raja Hasnain Anwar, lead author and a doctoral candidate at UMass Amherst, explained that the reason Visa cards are affected by this attack has to do with the way different card manufacturers have different protocols for handling contactless transactions. "These protocols have most messages in common to ensure global acceptance on different types of terminals; however, each manufacturer has their design choices to make for additional mechanisms," he said. "Often, these design choices end up in a compromise to ensure backward compatibility with old POS terminals, and also to meet their performance criteria. The security checks are in place, however, only a subset of these security mechanisms are invoked to make the transaction faster and smoother. There are other research studies that have shown issues with Mastercards as well. It comes down to the trade-off between performance and security, and often leaves room for this kind of vulnerability. No design is inherently bad."

    The researchers notified Visa of their findings in May 2025 and followed up in December 2025. Neither Visa nor the banks notified have confirmed that they have mitigated the expiration issue. The findings have sparked concerns among security experts, who warn that this vulnerability could be exploited by attackers to turn digital intrusions into kinetic disasters.

    In conclusion, the recent discovery by researchers at the University of Massachusetts Amherst highlights the need for greater scrutiny of the EMV payment process. The vulnerability in the expiry check mechanism allows expired credit cards to be revived and used for unauthorized payments, posing a significant risk to the financial industry.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Reviving-the-Dead-How-Gaps-in-Expiry-Checks-Allow-Expired-Credit-Cards-to-Make-Unauthorized-Payments-ehn.shtml

  • https://www.theregister.com/security/2026/08/18/expired-credit-cards-revived-by-researchers-to-make-unauthorized-payments/5289229


  • Published: Tue Aug 18 17:07:48 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us