
“Zombie Cards” and Tap-to-Pay: What Small Businesses Should Know
Reviewed by a Trailhead payments advisor before publication
A research team from UMass Amherst presented a study at USENIX Security 2026 showing that, in certain Visa contactless configurations, an expired physical card could be made to appear unexpired during a tap-to-pay transaction. For most small businesses, the correct response is not to change how you accept payments — it is to make sure the basics behind your payment setup are actually being maintained.
The short version
- Researchers at the University of Massachusetts Amherst demonstrated that some expired Visa contactless cards could still be used for tap-to-pay transactions under specific conditions.
- It is a real security finding, but it is not a reason for merchants to disable contactless payments or panic.
- The researchers reported the same technique did not succeed in their tested Mastercard and Discover configurations.
- The practical response: keep payment equipment current, watch for unusual fraud or dispute patterns, and make sure your processor can explain how terminals and fraud controls are maintained.
What changed?
The study, “Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless Payments,” tested contactless payments across multiple payment networks, point-of-sale terminals, merchants, and five major U.S. banks.
Their finding was unusual: in certain Visa contactless configurations, an expired physical card could be made to appear unexpired during a tap-to-pay transaction. The researchers used ordinary smartphones and NFC relay software to modify the expiration-date information seen by the payment terminal.
The important detail is that this was not a simple case of an expired card automatically working everywhere. Whether a transaction succeeded depended on the combination of card network, terminal rules, and the issuing bank's checks. The researchers reported that the same technique did not succeed in their tested Mastercard and Discover configurations.
UMass also says the issue had been disclosed to Visa and relevant banks before the research was made public. At the time the researchers published their findings, they said no mitigation had been publicly confirmed.
What it means for your business
For most small businesses, the correct takeaway is not “turn off tap-to-pay.” Contactless payments remain fast, widely used, and generally secure. Disabling them could create more checkout friction without meaningfully reducing your overall payment risk.
The bigger lesson is that payment security does not live in one device. A transaction passes through the card, POS terminal, processor or acquirer, card network, and issuing bank. When one part of that chain assumes another part has performed a security check, gaps can appear.
That is why the quality of your merchant-services setup matters beyond the headline processing rate. Terminal software, EMV certification, firmware updates, fraud settings, processor monitoring, and chargeback support can all become important when a new vulnerability is discovered.
This research also reinforces a point for businesses that accept a lot of card-present transactions: unusual fraud patterns should not be ignored simply because the terminal approved the card. Authorization means the transaction was accepted by the payment system; it does not guarantee the transaction can never become a fraud claim or chargeback later.
What to do next
There is no emergency action required for the average merchant. Instead, use this as a reason to make sure the basics are covered.
- Keep equipment and software currentRun supported versions of your POS and payment software. Avoid keeping old payment hardware simply because it still turns on, and ask your provider whether terminal and EMV updates are applied automatically.
- Watch disputes and fraud patternsReview chargebacks and fraud activity periodically. A sudden change in card-present disputes, contactless fraud, or authorization behavior is worth investigating rather than accepting as normal processing noise.
- Ask how security changes are communicatedFind out how your merchant-services provider notifies you when a card-network rule changes or a vulnerability is disclosed, and who handles the update on your terminals.
- Compare on more than basis pointsIf you are already reviewing providers, ask about equipment lifecycle, security updates, fraud tools, and support response — not only the quoted rate.
None of this means you should switch providers. It means it is worth knowing what your own agreement and statement say. Often the right answer is to stay where you are.
Sources and references
Every factual claim above traces back to one of these primary or industry sources.
- When Zombie Credit Cards Attack: UMass Researchers Discover Loophole That Can Reanimate Expired CardsUniversity of Massachusetts Amherst, Riccio College of Engineering ·
- Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless PaymentsUSENIX Security '26
- Expired card contactless research FAQ and disclosure notesKhwarizmi Lab
Related from Trailhead
- EMV, contactless, and card-present securityWhy how a card is accepted changes cost and liability.
- Chargebacks 101 for business ownersHow disputes work and what evidence tends to matter.
- Payment and POS equipment Trailhead works withTerminals, countertop systems, and mobile acceptance.
- Compare payment processors and POS systemsNeutral profiles: best for, strengths, things to consider.
Want your statement, equipment, and payment setup looked at together before deciding whether anything needs to change?
Free Trailhead Review™. No obligation.
Get payments insights in your inbox
Occasional updates on rate trends, POS shifts, and new Trailhead articles. No spam — unsubscribe anytime.
Keep reading

When the Wi-Fi Drops in a Mountain Town, Your Register Shouldn't
In Crested Butte, Gunnison, and the surrounding valley, connectivity isn't a given. Here's how modern terminals stay online when your Wi-Fi doesn't.

Square's August POS Update: What Small Businesses Should Actually Notice
Square's August 13 release added new pricing, tax, booking, inventory, and restaurant workflow controls. The bigger lesson: when comparing payment processors, operational fit can matter more than a small rate difference.