That expired Visa card in your junk drawer may not be as dead as it looks.

Researchers at the University of Massachusetts Amherst found that some expired Visa cards can be made to work again for contactless purchases if they fall into the wrong hands and certain security checks fail.

The finding sounds like a plot point from a movie about Frankenstein’s wallet. But the security vulnerability is real, and it could expose cardholders to fraud when an expired physical card falls into the wrong hands.

The findings were presented at the USENIX Security Symposium, held Aug. 12–14 in Baltimore.

Researchers found that a thief who obtained a cardholder’s expired physical Visa card could potentially use it even after the cardholder received a replacement.

Taqi Raza, an assistant professor of electrical and computer engineering at UMass Amherst, wondered whether an expired card could still be used to make a payment. After all, replacing an expired card does not necessarily close the underlying account.

To understand the vulnerability, think of a credit card as a key with an expiration date. Once that date has passed, the key should stop unlocking the door, just as the card should stop working after it expires.

But the UMass Amherst researchers found that, during some Visa contactless transactions, the expiration date shown to a store’s card reader could be changed.

The researchers used two off-the-shelf smartphones in their study. The first phone communicated with the expired physical card and prompted it to provide the data needed to initiate a contactless transaction, including its expiration date.

See also  AmEx Says Its $895 Platinum Portfolio Is Fastest-Growing

The two phones then relayed communications between the expired card and the store’s card reader. During that exchange, the researchers used their software to replace the expiration date shown to the reader with a future date.

Photo of a smartphone and contactless payment terminal
Researchers used one smartphone to communicate with an expired Visa card and another to relay altered data to a contactless payment terminal. (Shutterstock.com)

Notably, the thief would not need to know the expiration date on the cardholder’s replacement card. The researchers found that any arbitrary future date could be used.

The second phone, relaying the altered expiration date, could then be tapped against a store’s card reader to make a purchase.

The researchers found that the process worked in the laboratory. It also worked during real-world tests at grocery stores and local dining facilities.

Raja Hasnain Anwar is a doctoral candidate at UMass Amherst and served as the study’s lead author. CardRates caught up with Anwar to learn more about the research and who could be affected by the issue his team explored.

He told us that, based on the researchers’ analysis, the vulnerability stems from how Visa contactless transactions work.

“All Visa credit cards are effectively at risk,” Anwar explained. “The only thing preventing these attacks is the bank’s transaction security.”

The researchers found that the Visa contactless protocol was susceptible to this type of manipulation, but the attack would not work with every expired Visa card. It succeeded only when the card issuer did not perform sufficient security checks. Mastercard and Discover cards resisted the attack in the researchers’ tests.

“The only thing preventing these attacks is the bank’s transaction security.” — Raja Hasnain Anwar, UMass Amherst

But even banks that use up-to-date and robust security measures can encounter unexpected vulnerabilities. Anwar said some of the banks his team tested had inefficient transaction security.

See also  Upgrade’s New OneCard Offers Four Ways to Pay and 3% Back

That means the risk is not confined to a particular type of payment or cardholder, he said. It can affect Visa cards issued by U.S. banks that do not perform sufficient transaction security checks, including some of the banks the researchers tested.

Fixing the issue may not be as simple as flipping a switch. Anwar said Visa would need to update its contactless payment protocol, which “would require an extensive change.”

The affected banks told the researchers that their teams were working on a fix, Anwar said, but neither the banks nor Visa shared the specific measures they had implemented.

CardRates asked Visa whether it agreed with the researchers’ findings, what protections it had implemented, and whether cardholders would receive zero-liability protection for unauthorized purchases resulting from the attack. Visa did not respond by publication time.

In the meantime, consumers can reduce the risk by properly destroying expired cards. Anwar said people getting rid of expired cards should use the highest level of caution.

Cardholders who suspect fraudulent charges on their accounts should contact their banks as soon as possible.

The UMass article advised cardholders to slowly run a magnet across a card’s magnetic stripe before disposing of it, then use a tool such as a hammer or scissors to destroy the embedded chip.

Cards can be run through a shredder to further destroy them. Cardholders can also place the pieces in separate trash bins to reduce the chance that someone will collect and reassemble them.


Source link

Author

Shin John
Shin JohnYtv Market News
Share-market news writer and analyst with deep experience covering equities, commodities, forex, and cryptocurrencies for readers in the USA, UK, Canada, and Australia. Ytv Market News delivers timely market updates, practical trading insights, and clear explanations of macro and company-level catalysts that move prices. Combines on-the-ground financial reporting with technical analysis, using concise charts and actionable ideas to help investors and traders make smarter decisions.
See also  Walmart Finally Adds Tap to Pay, Apple Pay and Google Pay
Latest entries