Contactless credit card being tapped on a point-of-sale terminal, illustrating payment security and expired-card risk.
Security & Compliance5 min readWeekly briefing

“Zombie Cards” and Tap-to-Pay: What Small Businesses Should Know

Trailhead Payments EditorialPublished

Reviewed by a Trailhead payments advisor before publication

A research team from UMass Amherst presented a study at USENIX Security 2026 showing that, in certain Visa contactless configurations, an expired physical card could be made to appear unexpired during a tap-to-pay transaction. For most small businesses, the correct response is not to change how you accept payments — it is to make sure the basics behind your payment setup are actually being maintained.

The short version

  • Researchers at the University of Massachusetts Amherst demonstrated that some expired Visa contactless cards could still be used for tap-to-pay transactions under specific conditions.
  • It is a real security finding, but it is not a reason for merchants to disable contactless payments or panic.
  • The researchers reported the same technique did not succeed in their tested Mastercard and Discover configurations.
  • The practical response: keep payment equipment current, watch for unusual fraud or dispute patterns, and make sure your processor can explain how terminals and fraud controls are maintained.

What changed?

The study, “Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments,” tested contactless payments across multiple payment networks, point-of-sale terminals, merchants, and five major U.S. banks.

Their finding was unusual: in certain Visa contactless configurations, an expired physical card could be made to appear unexpired during a tap-to-pay transaction. The researchers used ordinary smartphones and NFC relay software to modify the expiration-date information seen by the payment terminal.

The important detail is that this was not a simple case of an expired card automatically working everywhere. Whether a transaction succeeded depended on the combination of card network, terminal rules, and the issuing bank's checks. The researchers reported that the same technique did not succeed in their tested Mastercard and Discover configurations.

UMass also says the issue had been disclosed to Visa and relevant banks before the research was made public. At the time the researchers published their findings, they said no mitigation had been publicly confirmed.

What it means for your business

For most small businesses, the correct takeaway is not “turn off tap-to-pay.” Contactless payments remain fast, widely used, and generally secure. Disabling them could create more checkout friction without meaningfully reducing your overall payment risk.

The bigger lesson is that payment security does not live in one device. A transaction passes through the card, POS terminal, processor or acquirer, card network, and issuing bank. When one part of that chain assumes another part has performed a security check, gaps can appear.

That is why the quality of your merchant-services setup matters beyond the headline processing rate. Terminal software, EMV certification, firmware updates, fraud settings, processor monitoring, and chargeback support can all become important when a new vulnerability is discovered.

This research also reinforces a point for businesses that accept a lot of card-present transactions: unusual fraud patterns should not be ignored simply because the terminal approved the card. Authorization means the transaction was accepted by the payment system; it does not guarantee the transaction can never become a fraud claim or chargeback later.

What to do next

There is no emergency action required for the average merchant. Instead, use this as a reason to make sure the basics are covered.

  • Keep equipment and software current
    Run supported versions of your POS and payment software. Avoid keeping old payment hardware simply because it still turns on, and ask your provider whether terminal and EMV updates are applied automatically.
  • Watch disputes and fraud patterns
    Review chargebacks and fraud activity periodically. A sudden change in card-present disputes, contactless fraud, or authorization behavior is worth investigating rather than accepting as normal processing noise.
  • Ask how security changes are communicated
    Find out how your merchant-services provider notifies you when a card-network rule changes or a vulnerability is disclosed, and who handles the update on your terminals.
  • Compare on more than basis points
    If you are already reviewing providers, ask about equipment lifecycle, security updates, fraud tools, and support response — not only the quoted rate.
None of this means you should switch providers. It means it is worth knowing what your own agreement and statement say. Often the right answer is to stay where you are.

Sources and references

Every factual claim above traces back to one of these primary or industry sources.

  1. When Zombie Credit Cards Attack: UMass Researchers Discover Loophole That Can Reanimate Expired Cards
    University of Massachusetts Amherst, Riccio College of Engineering ·
  2. Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments
    USENIX Security '26
  3. Expired card contactless research FAQ and disclosure notes
    Khwarizmi Lab

Want your statement, equipment, and payment setup looked at together before deciding whether anything needs to change?

Free Trailhead Review™. No obligation.

Get My Free Trailhead Review™

Get payments insights in your inbox

Occasional updates on rate trends, POS shifts, and new Trailhead articles. No spam — unsubscribe anytime.