A team of researchers from the University of Massachusetts Amherst has identified a significant security flaw that enables transactions to be processed using expired bank cards. Their findings were presented at the USENIX Security 2026 conference. The method requires merely an old card and two Android smartphones. When a bank card reaches its expiration date, the associated account remains active, allowing for refunds on previous purchases. This led the researchers to inquire whether an expired card could also be used to initiate new payments. In certain situations, the answer is affirmative. During contactless transactions, the card transmits various data to the payment terminal, including its expiration date. The researchers discovered that this information lacks robust cryptographic protection. Consequently, it can be modified during transmission between the card and the terminal without compromising the card's security. To illustrate the vulnerability, the researchers employed two smartphones: one connected to the expired card via NFC and the other linked to the payment terminal. Transaction details were exchanged, but the terminal received a tampered expiration date. To the cashier, this transaction appeared as a standard mobile payment. While the bank receives a legitimate cryptographic response from the actual card, it does not consistently verify whether that specific card is still active. Therefore, the outcome of the transaction is contingent upon the bank and the overall payment-processing system. The researchers conducted tests using Visa, Mastercard, American Express, and Discover cards from five prominent U.S. banks. They found that only Visa cards were susceptible to this attack, while the other three networks rejected the manipulated data. The team successfully executed transactions of $1, $100, and $500, replicating the attack in both laboratory settings and real retail environments—with the consent of the merchants involved.
Informational material. 18+.