AI

Expired Visa Cards Can Be Exploited for Contactless Payments, Researchers Warn

Researchers have revealed that expired Visa credit cards can be “zombified” and used to make contactless payments, even after they have been discarded or left unattended. The finding was presented at…

WIRED

Researchers have revealed that expired Visa credit cards can be “zombified” and used to make contactless payments, even after they have been discarded or left unattended. The finding was presented at the Usenix Cybersecurity Conference in August 2026 by researchers at the University of Massachusetts Amherst.

The technique works by proxying an expired card’s data through a man-in-the-middle app that relays information between two phones. The researchers found that a flaw in Visa’s authentication chain meant expired cards could pass its verification check. Visa did not respond to requests for comment from tech outlet The Register, which reported on the research.

The researchers explained that Visa effectively delegated the task of authenticating these transactions to individual cardholder banks. While some banks blocked the fraudulent payments, others did not — meaning a fraudster could retrieve a discarded card and use it to charge purchases from the original owner’s account, particularly at unattended point-of-sale terminals. The practical advice from researchers: cut up expired Visa cards before disposing of them.

The expired-card vulnerability was one of several security developments reported this week. Apple sent spyware alerts to potential hacking targets in 110 countries, with the number of warnings reaching levels more than 30 percent higher than previous rounds, according to TechCrunch. Security investigators at Access Now described the spike as “unprecedented.” At least one Ukrainian soldier was among those who received an alert, and researchers at iVerify and Google have already uncovered two iOS mass-hacking tools this year, known as DarkSword and Coruna.

Ukraine’s military also claimed it carried out a cyberattack against Russian ecommerce company Wildberries — described as Russia’s equivalent of Amazon — while drone strikes simultaneously destroyed portions of the company’s warehouse infrastructure. Russian media reported the company lost nearly 13 million square feet of warehouse space to drone attacks.

Separately, US agencies including the NSA, FBI, and CISA warned that AI-assisted exploitation software is being used to target Siemens programmable logic controllers — devices that digitally control physical systems in manufacturing, energy, water, food, and agriculture facilities. The advisory noted that AI tools dramatically reduce the technical expertise and time required to develop working industrial control system exploits.