A newly identified security flaw in Visa's payment system allows expired cards to continue making contactless transactions, a vulnerability researchers have termed "zombified." The finding adds to a growing list of digital payment risks as cyber threats become more sophisticated.

What You Need to Know

The vulnerability affects Visa cards that have passed their expiration date but still contain valid contactless payment data. Attackers with physical access to an expired card can use it to make small purchases without authorization. The flaw highlights a broader tension between payment convenience and security. Similar vulnerabilities have been found in other payment networks, but Visa's market dominance makes this one especially concerning.

How the 'Zombified' Attack Works

The attack relies on the fact that contactless payments often do not require online verification for low-value transactions. Even after a card's expiration date, the embedded chip and antenna still function. Researchers demonstrated that expired Visa cards could be read by a standard payment terminal, and the transaction would process as long as the amount stayed under the contactless limit.

  • Card expiration: The printed expiry date is not always checked during offline contactless transactions.
  • Offline processing: Terminals can approve payments without contacting the bank, leaving expired cards active.

The phrase "Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments" captures exactly how the system fails to revoke the card's payment credentials. Visa has acknowledged the issue and is working on updates to its authentication protocols, but the fix may take months to deploy across millions of terminals.

Why This Matters

The implications extend beyond individual cardholders. For banks and merchants, the existence of "zombie" transactions creates reconciliation nightmares. Fraud losses from expired cards could increase if attackers target high-traffic locations such as transit stations or coffee shops. Regulators are likely to scrutinize whether payment networks are doing enough to deactivate credentials in real time. Consumers may lose trust in contactless payments, which have become a standard convenience worldwide.

Separately, Apple sent out an "unprecedented" number of spyware warnings to iPhone users in recent weeks, signaling a surge in mercenary surveillance targeting journalists and activists. Ukraine also carried out cyber and drone attacks against a Russian e-commerce giant, disrupting logistics for military supplies. These events underscore the expanding battlefield of digital security.

Broader Industry Context

The Visa vulnerability is part of a pattern where payment infrastructure prioritizes speed over security. Contactless limits were raised during the pandemic to reduce physical contact, and those higher thresholds now make the zombified attack more dangerous. Industry analysts predict that payment networks will accelerate the adoption of tokenization, which replaces static card numbers with dynamic codes that expire after each transaction. But the transition is slow, and legacy systems remain widespread.

For now, the best defense for consumers is to destroy expired cards immediately and monitor account statements for unexpected charges. Businesses should ensure payment terminals are updated to check expiration dates online whenever possible.