AI Weekly Malaysia

Back to items Summaries

Expired credit cards revived by researchers to make unauthorized payments

ID
15382
Status
summarized
Published
19 Aug 2026, 4:20 AM
Fetched
19 Aug 2026, 6:08 AM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/08/18/expired-credit-cards-revived-by-researchers-to-make-unauthorized-payments/5289229
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
6.5
Created
19 Aug 2026, 6:11 AM
Tags
Audience
developerssaas_founders

What happened

Researchers from UMass Amherst demonstrated at USENIX Security 2026 that expired Visa contactless credit cards can be revived to make unauthorized payments via a man-in-the-middle attack using mobile phones as NFC proxies. The vulnerability stems from Visa's EMV kernel not cryptographically binding the expiration date, unlike American Express, Discover, and Mastercard kernels, and from wallet Card Transaction Qualifiers steering transactions toward online authorization rather than immediate rejection.

Why it matters

If you build or integrate payment systems in Southeast Asia—where contactless card and wallet adoption is near-universal—this is a concrete protocol-level flaw in Visa's contactless kernel, not a configuration mistake. Fintech builders should verify whether their issuer-side authorization logic independently checks card expiration rather than trusting the POS terminal's evaluation, since the attack exploits exactly that delegation gap.

Discussion angle

Visa's kernel is specifically called out as more permissive than Mastercard/Amex/Discover—does this mean merchants and issuers on Visa are carrying asymmetric risk, and should Malaysian payment processors push for issuer-side expiration enforcement rather than relying on terminal checks?

Top