Transcript
Hey, GonzoBankers. Tony DeSanctis back with another hot take. One of the biggest topics of 2025 is fraud.
Specifically, we want to talk today about BIN attacks, where fraudsters identify specific account numbers and/or sequences of account numbers. I’ve asked Lindsay Hooks to join us from the fraud side of things to tell us a little bit about how exactly these BIN attacks are happening and how we identify them.
So, Lindsay, tell us a little bit about how we can see these BIN attacks, what they look like and how to identify them.
Hopefully your processor catches this quickly. But if not, what your teams might notice is a high volume of transactions from a certain merchant. It’s not going to be a big merchant. They’re looking for smaller, vulnerable merchants that don’t have fraud rules in place to catch this.
You’ll also notice a spike in invalid card denials, expiration date denials or CVV denials. And we’re talking fast. This is not one or two every minute. They’re going as fast as they possibly can to try to identify vulnerable card number, expiration date and CVV2 combinations.
In order to fight that, we’ve got a few layers. This is just the beginning, but there are some common ways you’ll be able to tackle this.
Make sure that your card numbers are randomized and not issued in sequence. That can be tricky, but it’s really important.
Then there’s 3D Secure. That could be Mastercard SecureCode or Verified by Visa to help with those e-commerce transactions. These are not in-person transactions.
Lastly, the next level would be dark web monitoring to make sure that your cards are not for sale on the dark web, so you can shut those down promptly and the fraudsters move on to the next card that they steal.
Got it. So make sure your card numbers and expiration dates aren’t sequential or obviously predictable by fraudsters. Leverage the tools from Visa and Mastercard that have that higher level of security, and do the dark web monitoring.
Let us know in the comments what you’re doing around BIN attacks and how you’re trying to address them.
Lindsay, thanks for joining us. And if you want to talk more about this, feel free to reach out about our fraud community.
Enjoying Hot Takes?
Subscribe on your favorite platform