Hackers Can Expose $999,999.99 Vulnerability in Visa Contactless Payment Cards

Security Flaw in Visa Contactless Payment Cards Exposes Users to Fraud

In a significant cybersecurity revelation, researchers from Newcastle University in the UK have discovered a vulnerability within Visa’s contactless payment card system that could allow hackers to siphon up to $999,999.99 from each card. This breach leverages a flaw in the contactless payment protocol, enabling unauthorized transactions using only a mobile device.

Contactless payment cards utilize a combination of cryptographic processors and RFID technology to conduct secure transactions without necessitating a physical card insertion. While they provide convenience for consumers—allowing purchases by simply tapping their cards on a reader—there are defined limit restrictions, particularly in the UK, where users can spend up to £20 without entering a PIN. However, the researchers have highlighted that cybercriminals could exploit the existing protocols to circumvent these limitations.

At the recent 21st ACM Conference on Computer and Communications Security, the researchers unveiled a method involving a “rogue POS terminal” that can be operated through a mobile phone. This fraudulent terminal can be configured to request substantial amounts, allowing attackers to initiate wireless transfers into their accounts. This illicit activity arises from the card’s reliance on embedded security measures, which primarily validate the card itself, rather than the terminal initiating the transaction. As a result, the transaction can occur without raising immediate red flags.

Martin Emms, the lead researcher, explained that this method enables an attacker to discreetly initiate a transaction by simply being in proximity to a victim’s card, even when it is inside a wallet. In experimental scenarios, transactions were approved in less than a second—a stark indication of how quickly such a breach can occur.

Despite these alarming findings, the research team has not yet assessed how Visa’s monitoring systems would respond to an influx of high-value foreign currency transactions, raising questions regarding potential fraud detection capabilities. However, cybersecurity experts are concerned about the implications of this vulnerability, suggesting that the flawed system could be manipulated to execute numerous smaller transactions, thus evading detection.

The potential tactics and techniques outlined by the MITRE ATT&CK framework suggest that adversaries may exploit this security gap through initial access by using mobile devices designed to impersonate legitimate terminals. They may also employ tactics such as deception to manipulate transaction limits and evade detection through fragmentation of larger transactions.

In response to these findings, Visa Europe has acknowledged the researchers’ insights and stated that they continue to prioritize security within their systems. Company representatives emphasized that multiple safeguards exist within the Visa framework and indicated that replicating this type of attack outside a controlled environment would be challenging. Furthermore, Visa is taking steps to enhance security measures by demanding more robust authentication for transactions, thereby complicating the execution of such attacks.

For businesses and consumers alike, this discovery serves as a stark reminder of the evolving landscape of cybersecurity threats and the need for ongoing vigilance in the protection of financial transactions. Efforts by Visa to adapt and upgrade their security protocols will be crucial in safeguarding against the growing sophistication of cybercriminals targeting contactless payment systems.

Source link