A study conducted by researchers at the University of Massachusetts Amherst and presented at the USENIX Security 2026 conference has revealed a fact that is in some ways disturbing. According to the study, even old expired cards can potentially be reused to make fraudulent payments. It is no coincidence that researchers have defined them as “zombie” credit cards: even after replacement, they can in some cases come back to “life” and be used by a cyber criminal for fraudulent purposes.
The problem arises from the fact that it is the physical card that expires, but not the account associated with it. This is demonstrated by the fact that, if you purchase a product and then return it, the refund can reach your account even when the card used for payment, associated with the latter, has now expired. This is where the researchers’ question began: if an old card can still receive a refund, can it also be used to make a payment? For some cards, the answer is yes. The team led by Professor Taqi Raza has demonstrated that it is possible to build a system capable of convincing a POS terminal that an expired card is still valid. Let’s see how this particular attack works in more detail.
How the “zombie” credit card attack works
The attack is fundamentally based on the use of NFC technology, the same one that allows you to pay by bringing a card or smartphone close to the terminal. The researchers use two normal smartphones and software capable of emulating the behavior necessary for the transaction. The first phone activates the card and initiates the payment request, also transmitting its expiration date. The second phone intercepts this data through a Wi-Fi connection and changes the date, replacing the expired one with any subsequent date.
Technically this is a “man-in-the-middle” attack, i.e. an attack in which a subject inserts himself between two devices that are communicating, intercepting and, in this case, modifying the information exchanged. The second smartphone is then connected to the store’s reader: from the outside, the operation may appear similar to a normal payment made via a digital wallet.
Most worryingly, the criminal does not necessarily need to know the true expiration date of the replacement card. According to the researchers, it may be sufficient to enter any future date. This is possible because the expiration date that the POS reads from the card is not cryptographically protected. At this point you might expect the bank to automatically block the transaction. But it is precisely here that a major vulnerability emerges. Not all banking institutions verify the expiry date received from the terminal by comparing it with the information authenticated by the card. If there is no further check on the card status, the fraudulent payment can therefore be successful.
In fact, the payment system contains another element that can cause confusion. The card has a security key that protects communication with the bank and which is associated with a digital certificate, i.e. a sort of electronic credential used to verify the authenticity of the communication. The researchers found that the expiration of this certificate may be later than that shown on the card. Consequently, checking the key is not enough to establish whether the physical card has actually expired or not. The vulnerability was verified both in the laboratory and in actual commercial establishments, such as restaurants and supermarkets. However, not all cards are exposed in the same way and digital wallets have additional protections that make them more resistant to this specific attack.
How to dispose of them safely to avoid scams
To sleep reasonably soundly, therefore, you need to learn how to safely dispose of expired credit cards. Researchers recommend destroying them even when you receive a replacement or your account has been permanently closed. First, you can slowly pass a magnet over the magnetic stripe and then damage the chip with a hammer or scissors. Finally, you should cut the paper into several parts, also eliminating raised numbers and letters. It is also advisable to distribute the fragments in several garbage containers. For metal cards, however, it is better to contact the customer service of the bank that issued the card directly, so as to know what to do.








