Skip to content
Tech News
← Back to articles

Your Expired Visa Card Could Be ‘Zombified’ to Make Contactless Payments

read original more articles
Why This Matters

This article highlights emerging security risks associated with expired credit cards, which can be exploited through new 'zombification' techniques to access bank accounts. It underscores the importance for consumers and the industry to stay vigilant about evolving fraud methods and the need for improved security measures. The broader context of AI and surveillance tools also emphasizes the ongoing challenges in privacy and cybersecurity.

Key Takeaways

As the controversial vehicle surveillance giant Flock Safety continues to expand, WIRED got the code for the company’s new AI policing tool and reconstructed the software to show that its capabilities go far beyond reading license plates and tracking vehicles. We also published the story this week of a Rhode Island police officer who was subjected to five internal affairs investigations in less than two years after he publicly questioned his department’s use of Flock cameras.

Following incidents of high-profile rogue activity by some of its AI agents, OpenAI said this week that it is halting model training runs and overhauling internal safety protocols. The company said that its upcoming Astra model may represent a turning point of “critical” cyber capabilities.

A reverse-lookup identification service exposed millions of photos of people’s faces in a database accessible through the open internet. Meanwhile, Meta ran advertisements for an app that promised to nudify female politicians, including one ad featuring a pornographic video that included a deepfake resembling a well-known US politician. Apple removed the app from the App Store after WIRED’s inquiry.

And WIRED spoke with Andy Yen, CEO of the privacy-focused digital services company Proton, about the privacy implications of AI and how access to encryption can continue to expand in this new technological era.

But wait, there’s more! Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.

Many people know that any active credit card represents a fraud risk the minute a card is lost, stolen, or otherwise gets out of their hands. Less expected is that an expired Visa card, too, could serve as an errant key into their bank account if it’s left unattended or discarded intact, discovered by a fraudster, and “zombified” using a new technique researchers recently revealed.

At the Usenix Cybersecurity Conference last week, researchers at the University of Massachusetts Amherst warned that fraudsters could make contactless payments using expired credit cards issued by Visa by proxying them through a man-in-the-middle app that relays the credit card’s data through a pair of phones. Due to issues in the authentication chain of contactless payments, the researchers found that whether an expired card’s transaction would be disallowed was left to cryptography implemented differently by various card issuers. Visa’s had a particular flaw allowing out-of-date cards to pass its check. (Visa didn’t respond to requests for comment from tech news outlet the Register, which reported on the research this week.)

In fact, as the researchers describe it, Visa’s essentially passed on the task of authenticating these transactions to the cardholder’s bank—and while some banks prevented the use of the zombified cards, others didn’t. The result is that fraudsters could in some cases dumpster dive for an expired card and use it to make payments from the unwitting owner’s account—particularly at point-of-sale terminals where no human is present to look askance at their phone-based proxy setup.

The lesson: When that Visa card expires, a pair of scissors can ensure it doesn’t reanimate in someone else’s hands.

Apple has long sent out notification to the owners of iPhones and other devices it’s detected may be the target of what it calls “mercenary spyware”—sophisticated, stealthy malware installed by a government or state-sponsored hacker-for-hire. Last weekend, the number of those alerts sent to potential victims spiked to an “unprecedented” number, according to TechCrunch, which spoke to security analysts who investigate potential spyware intrusions. The alerts, which were sent out to potential hacking targets in 110 countries, reached numbers of users more than 30 percent higher than previous rounds of these alerts, by the estimate of Mohammed Al-Maskati, who leads a team of security investigators at Access Now, a digital rights group that Apple refers victims to in its spyware alerts. At least one target, TechCrunch noted, was a Ukrainian soldier, who said that others in the Ukrainian military had also received the alert. Sophisticated iPhone hacking campaigns may well be on the rise: Just this year, researchers at iVerify and Google uncovered two iOS mass-hacking tools known as DarkSword and Coruna.

... continue reading