Home AI Expired Credit Cards May Not Be as Dead as You Think

Expired Credit Cards May Not Be as Dead as You Think

Credit: Unsplash+.

An expired credit card may look useless, but researchers have discovered a security loophole that could allow some old cards to come back to life and make purchases.

Researchers at the University of Massachusetts Amherst found that certain expired credit cards can still be used for fraudulent payments, even after the cardholder has received a replacement. They call these old cards “zombie credit cards.”

The problem exists partly because a credit card account does not expire when the physical card does.

For example, if you return something bought with a card that has since expired, the refund can still reach your account. This led researchers to ask whether an expired card might also still be able to make a payment.

For some cards, they found that it could.

The researchers demonstrated an attack using two ordinary smartphones and readily available software. The method takes advantage of near-field communication, or NFC, the same technology used for contactless payments.

One phone communicates with the expired card and collects the payment information it provides, including its expired date. That information is then relayed to a second phone over Wi-Fi. Before presenting the information to a store’s payment terminal, the system changes the expiration date to one in the future.

Surprisingly, attackers do not even need to know the expiration date of the replacement card. According to the researchers, simply providing a future date can be enough in some cases.

The weakness exists because the expiration date stored on the card is not cryptographically protected. A payment terminal may therefore accept a modified date as genuine.

You might expect the cardholder’s bank to catch the problem. However, the researchers found that some banks do not properly compare the expiration date received from the payment terminal with authenticated card information.

If other security checks also fail to confirm whether the physical card is still active, the payment can go through.

Another complication is that payment cards contain a separate expiration date associated with the digital security credentials used to communicate securely with payment systems. This security credential may remain valid longer than the expiration date printed on the card, meaning an apparently expired card may still be capable of participating in part of the payment process.

The researchers tested the attack not only in the laboratory but also at real dining and grocery locations. Not every credit card was vulnerable, and digital wallets had additional protections that made this particular attack more difficult.

The discovery highlights a broader problem with modern payment systems. Security decisions are spread among the card, payment terminal, card network and bank. When these different parts do not check the same information consistently, attackers may find gaps between them.

The researchers have informed major payment card companies about the vulnerability. For consumers, the findings provide a simple warning: don’t casually throw old cards away. Destroy the chip, magnetic strip, numbers and other identifying information before disposal. Metal cards should generally be returned according to the card issuer’s instructions.

And even after an account is closed, it is worth watching for unexpected transactions. An expired card, it turns out, may not always be completely dead.