{"id":4405,"date":"2023-06-01T06:44:00","date_gmt":"2023-06-01T06:44:00","guid":{"rendered":"https:\/\/wibmo.com\/bin-attack-fraud\/"},"modified":"2024-06-04T06:00:19","modified_gmt":"2024-06-04T06:00:19","slug":"bin-attack-fraud","status":"publish","type":"post","link":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/","title":{"rendered":"BIN Attack Fraud"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"4405\" class=\"elementor elementor-4405\">\n\t\t\t\t<div class=\"elementor-element elementor-element-788db563 e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-parent\" data-id=\"788db563\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-45f15cbe elementor-widget elementor-widget-text-editor\" data-id=\"45f15cbe\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\tCard not present (CNP) transactions are those where the purchase is made without presenting the physical card to the merchant at the point of sale. As more and more physical stores are using EMV-compliant terminals, Javelin Strategy &amp; Research credit card fraud statistics report that card-not-present fraud is now 81% more likely to happen than card-present fraud. Card-not-present transactions can be done via online merchants, telephone orders, or mail. There are various modus operandi to commit CNP fraud, such as account takeover using phishing scams, malware infection to capture keystrokes, or friendly fraud. In such scenarios, the cardholder is involved in the fraud, and it is kind of a personalised attack. However, today we will talk about an impersonal attack where a fraudster exploits a BIN (bank identification number) and uses distributed computing power to automatically generate the remaining numbers and test these combinations to see which card numbers are correct and if the cards are active. This kind of attack is called BIN attack fraud. The subtlety of BIN Attack fraud is that it does not involve any data breach or ID theft; it is just a pure random coincidence that a victim\u2019s card number is chosen.\n\nThe compromised cards can have a significant impact on issuing banks in terms of chargebacks, call c entre volume spikes, and re-issuance expenses. Furthermore, any cardholder disruption or friction during this tenure leads to a loss of interchange revenues. The damage to the bank\u2019s reputation could lead to cardholders switching the bank\u2019s services to another, more secure bank.\n\nA merchant involved in BIN attack fraud faces increased disputes or chargebacks, additional fees, and regulatory fines. Depending on the nature of the attack and risk profile, the acquiring bank may choose to suspend support for the merchant\u2019s site. The cardholder\u2019s bank may restrict purchases from your site, resulting in further financial losses. Refunding any fraudulent transactions is an operational challenge, not to mention the reputational loss.\n\nThus, BIN attack fraud is a problem both for issuers and merchants.\n<h4 id=\"a435\" class=\"agw agx sr be agy agz aha dq lz ahb ahc ds md ws ahd adm ado ww ahe adp ads xa ahf adt adw ahg bj\">Preventing a BIN Attack Fraud<\/h4>\n<p id=\"4ece\" class=\"pw-post-body-paragraph wh wi sr wj b wk ahh wm wn wo ahi wq wr ws ahj wu wv ww ahk wy wz xa ahl xc xd xe fv bj\" data-selectable-paragraph=\"\">To prevent BIN attack fraud, the merchant or the issuing bank can deploy a few techniques:<\/p>\n\n<ol class=\"\">\n \t<li id=\"fdb2\" class=\"wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe afz aga agb bj\" data-selectable-paragraph=\"\">Enable 3D security. The latest version of EMV 3DS 2.x is an additional security layer for online credit and debit card transactions that aims to achieve a balance between security and user convenience.<\/li>\n \t<li id=\"b8e7\" class=\"wh wi sr wj b wk agc wm wn wo agd wq wr ws age wu wv ww agf wy wz xa agg xc xd xe afz aga agb bj\" data-selectable-paragraph=\"\">As a merchant, enable a CAPTCHA test to tell humans and bots apart. While this may create friction for genuine customers, it\u2019s an effective deterrent against BOT scripts.<\/li>\n \t<li id=\"dbf5\" class=\"wh wi sr wj b wk agc wm wn wo agd wq wr ws age wu wv ww agf wy wz xa agg xc xd xe afz aga agb bj\" data-selectable-paragraph=\"\">Deploy an anti-fraud solution that can look at many aspects and block transactions or alert your fraud analyst. A good anti-fraud solution should have:<\/li>\n<\/ol>\n<ul class=\"\">\n \t<li id=\"269d\" class=\"wh wi sr wj b wk wl wm wn wo wp wq wr ws wt wu wv ww wx wy wz xa xb xc xd xe agn aga agb bj\" data-selectable-paragraph=\"\">Ability to spot multiple low-value transactions (unusually low for the merchant\u2019s business).<\/li>\n \t<li id=\"c0e6\" class=\"wh wi sr wj b wk agc wm wn wo agd wq wr ws age wu wv ww agf wy wz xa agg xc xd xe agn aga agb bj\" data-selectable-paragraph=\"\">Multiple declines within a short period<\/li>\n \t<li id=\"751b\" class=\"wh wi sr wj b wk agc wm wn wo agd wq wr ws age wu wv ww agf wy wz xa agg xc xd xe agn aga agb bj\" data-selectable-paragraph=\"\">The timing of transactions may be unusual for the merchant, business, or cardholder.<\/li>\n \t<li id=\"09a0\" class=\"wh wi sr wj b wk agc wm wn wo agd wq wr ws age wu wv ww agf wy wz xa agg xc xd xe agn aga agb bj\" data-selectable-paragraph=\"\">A large number of transactions from the same BIN were attempted in a short period of time (a few seconds apart).<\/li>\n \t<li id=\"189b\" class=\"wh wi sr wj b wk agc wm wn wo agd wq wr ws age wu wv ww agf wy wz xa agg xc xd xe agn aga agb bj\" data-selectable-paragraph=\"\">IP Velocity Checks: Even though these days, through proxy and spoofing, fraudsters can make it seem that the transactions are coming from different IPs, Use an anti-fraud solution that deploys good device fingerprinting techniques to solve this issue, as fingerprinting is impervious to IP proxies.<\/li>\n \t<li id=\"b8ae\" class=\"wh wi sr wj b wk agc wm wn wo agd wq wr ws age wu wv ww agf wy wz xa agg xc xd xe agn aga agb bj\" data-selectable-paragraph=\"\">Unusually large volume of international transactions for a given merchant or for a cardholder.<\/li>\n \t<li id=\"54cd\" class=\"wh wi sr wj b wk agc wm wn wo agd wq wr ws age wu wv ww agf wy wz xa agg xc xd xe agn aga agb bj\" data-selectable-paragraph=\"\">Look for patterns, cards with sequential numbers, the same card number but different expiration dates, or CVV codes.<\/li>\n \t<li id=\"2476\" class=\"wh wi sr wj b wk agc wm wn wo agd wq wr ws age wu wv ww agf wy wz xa agg xc xd xe agn aga agb bj\" data-selectable-paragraph=\"\">Ability to create a profile for the merchant and cardholder and alert in case of any significant deviations.<\/li>\n<\/ul>\nThere are a few additional measures that the industry could take, such as creating advisory, actionable intelligence, and a listing of sites that anti-fraud tools can take advantage of. EMV 3DS 2.x allows merchants and acquirers to do a risk assessment prior to making an EMV 3DS authentication call to the issuer. A combined risk assessment from both the acquiring and issuing sides acts as a strong deterrent to fraudsters. Both issuers and acquirers can pool their intelligence and create a shared intelligence pool of fraud markings to identify common points of fraud. Information on declines on the switch side during authorization when fed into 3DS authentication ACS gives actionable intelligence to anti-fraud tools.\n\nBIN attack fraud is still a crude brute-force attack vector that is detectable, and preventive measures can be taken to interrupt it. A well-informed merchant and bank implementing a defensive anti-fraud solution that keeps itself abreast of the latest advisories combined with continuous monitoring of anomalous behaviour can stay a step ahead of this kind of fraudulent attack.\n\n<strong class=\"na hj\">Author:<\/strong>\n\n<a class=\"af pd\" href=\"https:\/\/www.linkedin.com\/in\/ajitnair3108\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">Ajit Nair<\/a>, Director Product Management\n\n<a class=\"af pd\" href=\"https:\/\/www.wibmo.com\/\" target=\"_blank\" rel=\"noopener ugc nofollow\">Wibmo<\/a> A PayU\/Naspers FinTech Company\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t<div class=\"elementor-element elementor-element-cba5ef0 e-flex e-con-boxed wpr-particle-no wpr-jarallax-no wpr-parallax-no wpr-sticky-section-no wpr-equal-height-no e-con e-parent\" data-id=\"cba5ef0\" data-element_type=\"container\" data-e-type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-d986f8a wpr-post-info-align-center elementor-widget elementor-widget-wpr-post-info\" data-id=\"d986f8a\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"wpr-post-info.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<ul class=\"wpr-post-info wpr-post-info-vertical\"><li class=\"wpr-post-info-taxonomy\"><a href=\"https:\/\/wibmo.com\/blogs\/tag\/cnp\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Cnp<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/fraud-2\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Fraud<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/fraud-prevention-2\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Fraud Prevention<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/payment-fraud\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Payment Fraud<span class=\"tax-sep\">, <\/span><\/a><a href=\"https:\/\/wibmo.com\/blogs\/tag\/payments-2\/\"><span class=\"wpr-post-info-text\"><svg aria-hidden=\"true\" class=\"e-font-icon-svg e-fas-tag\" viewBox=\"0 0 512 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M0 252.118V48C0 21.49 21.49 0 48 0h204.118a48 48 0 0 1 33.941 14.059l211.882 211.882c18.745 18.745 18.745 49.137 0 67.882L293.823 497.941c-18.745 18.745-49.137 18.745-67.882 0L14.059 286.059A48 48 0 0 1 0 252.118zM112 64c-26.51 0-48 21.49-48 48s21.49 48 48 48 48-21.49 48-48-21.49-48-48-48z\"><\/path><\/svg><\/span>Payments<\/a><\/li><\/ul>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Card not present (CNP) transactions are those where the purchase is made without presenting the physical card to the merchant at the point of sale. As more and more physical stores are using EMV-compliant terminals, Javelin Strategy &amp; Research credit card fraud statistics report that card-not-present fraud is now 81% more likely to happen than card-present fraud. Card-not-present transactions can be done via online merchants, telephone orders, or mail. There are various modus operandi to commit CNP fraud, such as account takeover using phishing scams, malware infection to capture keystrokes, or friendly fraud. In such scenarios, the cardholder is involved in the fraud, and it is kind of a personalised attack. However, today we will talk about an impersonal attack where a fraudster exploits a BIN (bank identification number) and uses distributed computing power to automatically generate the remaining numbers and test these combinations to see which card numbers are correct and if the cards are active. This kind of attack is called BIN attack fraud. The subtlety of BIN Attack fraud is that it does not involve any data breach or ID theft; it is just a pure random coincidence that a victim\u2019s card number is chosen. The compromised cards can have a significant impact on issuing banks in terms of chargebacks, call c entre volume spikes, and re-issuance expenses. Furthermore, any cardholder disruption or friction during this tenure leads to a loss of interchange revenues. The damage to the bank\u2019s reputation could lead to cardholders switching the bank\u2019s services to another, more secure bank. A merchant involved in BIN attack fraud faces increased disputes or chargebacks, additional fees, and regulatory fines. Depending on the nature of the attack and risk profile, the acquiring bank may choose to suspend support for the merchant\u2019s site. The cardholder\u2019s bank may restrict purchases from your site, resulting in further financial losses. Refunding any fraudulent transactions is an operational challenge, not to mention the reputational loss. Thus, BIN attack fraud is a problem both for issuers and merchants. Preventing a BIN Attack Fraud To prevent BIN attack fraud, the merchant or the issuing bank can deploy a few techniques: Enable 3D security. The latest version of EMV 3DS 2.x is an additional security layer for online credit and debit card transactions that aims to achieve a balance between security and user convenience. As a merchant, enable a CAPTCHA test to tell humans and bots apart. While this may create friction for genuine customers, it\u2019s an effective deterrent against BOT scripts. Deploy an anti-fraud solution that can look at many aspects and block transactions or alert your fraud analyst. A good anti-fraud solution should have: Ability to spot multiple low-value transactions (unusually low for the merchant\u2019s business). Multiple declines within a short period The timing of transactions may be unusual for the merchant, business, or cardholder. A large number of transactions from the same BIN were attempted in a short period of time (a few seconds apart). IP Velocity Checks: Even though these days, through proxy and spoofing, fraudsters can make it seem that the transactions are coming from different IPs, Use an anti-fraud solution that deploys good device fingerprinting techniques to solve this issue, as fingerprinting is impervious to IP proxies. Unusually large volume of international transactions for a given merchant or for a cardholder. Look for patterns, cards with sequential numbers, the same card number but different expiration dates, or CVV codes. Ability to create a profile for the merchant and cardholder and alert in case of any significant deviations. There are a few additional measures that the industry could take, such as creating advisory, actionable intelligence, and a listing of sites that anti-fraud tools can take advantage of. EMV 3DS 2.x allows merchants and acquirers to do a risk assessment prior to making an EMV 3DS authentication call to the issuer. A combined risk assessment from both the acquiring and issuing sides acts as a strong deterrent to fraudsters. Both issuers and acquirers can pool their intelligence and create a shared intelligence pool of fraud markings to identify common points of fraud. Information on declines on the switch side during authorization when fed into 3DS authentication ACS gives actionable intelligence to anti-fraud tools. BIN attack fraud is still a crude brute-force attack vector that is detectable, and preventive measures can be taken to interrupt it. A well-informed merchant and bank implementing a defensive anti-fraud solution that keeps itself abreast of the latest advisories combined with continuous monitoring of anomalous behaviour can stay a step ahead of this kind of fraudulent attack. Author: Ajit Nair, Director Product Management Wibmo A PayU\/Naspers FinTech Company Cnp, Fraud, Fraud Prevention, Payment Fraud, Payments<\/p>\n","protected":false},"author":9,"featured_media":4453,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"set","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[85,83],"tags":[124,125,90,126,127],"class_list":["post-4405","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-reading-list","category-stories","tag-cnp","tag-fraud-2","tag-fraud-prevention-2","tag-payment-fraud","tag-payments-2"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>BIN Attack Fraud - Digital Payments, Payment Security and Lending - Wibmo<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"BIN Attack Fraud - Digital Payments, Payment Security and Lending - Wibmo\" \/>\n<meta property=\"og:description\" content=\"Card not present (CNP) transactions are those where the purchase is made without presenting the physical card to the merchant at the point of sale. As more and more physical stores are using EMV-compliant terminals, Javelin Strategy &amp; Research credit card fraud statistics report that card-not-present fraud is now 81% more likely to happen than card-present fraud. Card-not-present transactions can be done via online merchants, telephone orders, or mail. There are various modus operandi to commit CNP fraud, such as account takeover using phishing scams, malware infection to capture keystrokes, or friendly fraud. In such scenarios, the cardholder is involved in the fraud, and it is kind of a personalised attack. However, today we will talk about an impersonal attack where a fraudster exploits a BIN (bank identification number) and uses distributed computing power to automatically generate the remaining numbers and test these combinations to see which card numbers are correct and if the cards are active. This kind of attack is called BIN attack fraud. The subtlety of BIN Attack fraud is that it does not involve any data breach or ID theft; it is just a pure random coincidence that a victim\u2019s card number is chosen. The compromised cards can have a significant impact on issuing banks in terms of chargebacks, call c entre volume spikes, and re-issuance expenses. Furthermore, any cardholder disruption or friction during this tenure leads to a loss of interchange revenues. The damage to the bank\u2019s reputation could lead to cardholders switching the bank\u2019s services to another, more secure bank. A merchant involved in BIN attack fraud faces increased disputes or chargebacks, additional fees, and regulatory fines. Depending on the nature of the attack and risk profile, the acquiring bank may choose to suspend support for the merchant\u2019s site. The cardholder\u2019s bank may restrict purchases from your site, resulting in further financial losses. Refunding any fraudulent transactions is an operational challenge, not to mention the reputational loss. Thus, BIN attack fraud is a problem both for issuers and merchants. Preventing a BIN Attack Fraud To prevent BIN attack fraud, the merchant or the issuing bank can deploy a few techniques: Enable 3D security. The latest version of EMV 3DS 2.x is an additional security layer for online credit and debit card transactions that aims to achieve a balance between security and user convenience. As a merchant, enable a CAPTCHA test to tell humans and bots apart. While this may create friction for genuine customers, it\u2019s an effective deterrent against BOT scripts. Deploy an anti-fraud solution that can look at many aspects and block transactions or alert your fraud analyst. A good anti-fraud solution should have: Ability to spot multiple low-value transactions (unusually low for the merchant\u2019s business). Multiple declines within a short period The timing of transactions may be unusual for the merchant, business, or cardholder. A large number of transactions from the same BIN were attempted in a short period of time (a few seconds apart). IP Velocity Checks: Even though these days, through proxy and spoofing, fraudsters can make it seem that the transactions are coming from different IPs, Use an anti-fraud solution that deploys good device fingerprinting techniques to solve this issue, as fingerprinting is impervious to IP proxies. Unusually large volume of international transactions for a given merchant or for a cardholder. Look for patterns, cards with sequential numbers, the same card number but different expiration dates, or CVV codes. Ability to create a profile for the merchant and cardholder and alert in case of any significant deviations. There are a few additional measures that the industry could take, such as creating advisory, actionable intelligence, and a listing of sites that anti-fraud tools can take advantage of. EMV 3DS 2.x allows merchants and acquirers to do a risk assessment prior to making an EMV 3DS authentication call to the issuer. A combined risk assessment from both the acquiring and issuing sides acts as a strong deterrent to fraudsters. Both issuers and acquirers can pool their intelligence and create a shared intelligence pool of fraud markings to identify common points of fraud. Information on declines on the switch side during authorization when fed into 3DS authentication ACS gives actionable intelligence to anti-fraud tools. BIN attack fraud is still a crude brute-force attack vector that is detectable, and preventive measures can be taken to interrupt it. A well-informed merchant and bank implementing a defensive anti-fraud solution that keeps itself abreast of the latest advisories combined with continuous monitoring of anomalous behaviour can stay a step ahead of this kind of fraudulent attack. Author: Ajit Nair, Director Product Management Wibmo A PayU\/Naspers FinTech Company Cnp, Fraud, Fraud Prevention, Payment Fraud, Payments\" \/>\n<meta property=\"og:url\" content=\"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/\" \/>\n<meta property=\"og:site_name\" content=\"Digital Payments, Payment Security and Lending - Wibmo\" \/>\n<meta property=\"article:published_time\" content=\"2023-06-01T06:44:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-06-04T06:00:19+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/BIN.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1400\" \/>\n\t<meta property=\"og:image:height\" content=\"782\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Wibmo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Wibmo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/\"},\"author\":{\"name\":\"Wibmo\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/person\\\/b40d974b488414d9d2fc9790e585454b\"},\"headline\":\"BIN Attack Fraud\",\"datePublished\":\"2023-06-01T06:44:00+00:00\",\"dateModified\":\"2024-06-04T06:00:19+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/\"},\"wordCount\":788,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/BIN.webp\",\"keywords\":[\"Cnp\",\"Fraud\",\"Fraud Prevention\",\"Payment Fraud\",\"Payments\"],\"articleSection\":[\"Reading List\",\"Stories\"],\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/\",\"name\":\"BIN Attack Fraud - Digital Payments, Payment Security and Lending - Wibmo\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/BIN.webp\",\"datePublished\":\"2023-06-01T06:44:00+00:00\",\"dateModified\":\"2024-06-04T06:00:19+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/#primaryimage\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/BIN.webp\",\"contentUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/05\\\/BIN.webp\",\"width\":1400,\"height\":782},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/bin-attack-fraud\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"BIN Attack Fraud\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#website\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/\",\"name\":\"Digital Payments, Payment Security and Lending - Wibmo\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#organization\",\"name\":\"Digital Payments, Payment Security and Lending - Wibmo\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/cropped-New-Project.png\",\"contentUrl\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/wp-content\\\/uploads\\\/2024\\\/08\\\/cropped-New-Project.png\",\"width\":220,\"height\":45,\"caption\":\"Digital Payments, Payment Security and Lending - Wibmo\"},\"image\":{\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/#\\\/schema\\\/person\\\/b40d974b488414d9d2fc9790e585454b\",\"name\":\"Wibmo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4e0292824dccdc846c40f4b0f69060297bdf937f87f4393fe7ce4e84df38685e?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4e0292824dccdc846c40f4b0f69060297bdf937f87f4393fe7ce4e84df38685e?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/4e0292824dccdc846c40f4b0f69060297bdf937f87f4393fe7ce4e84df38685e?s=96&d=mm&r=g\",\"caption\":\"Wibmo\"},\"url\":\"https:\\\/\\\/wibmo.com\\\/blogs\\\/author\\\/wibmo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"BIN Attack Fraud - Digital Payments, Payment Security and Lending - Wibmo","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/","og_locale":"en_US","og_type":"article","og_title":"BIN Attack Fraud - Digital Payments, Payment Security and Lending - Wibmo","og_description":"Card not present (CNP) transactions are those where the purchase is made without presenting the physical card to the merchant at the point of sale. As more and more physical stores are using EMV-compliant terminals, Javelin Strategy &amp; Research credit card fraud statistics report that card-not-present fraud is now 81% more likely to happen than card-present fraud. Card-not-present transactions can be done via online merchants, telephone orders, or mail. There are various modus operandi to commit CNP fraud, such as account takeover using phishing scams, malware infection to capture keystrokes, or friendly fraud. In such scenarios, the cardholder is involved in the fraud, and it is kind of a personalised attack. However, today we will talk about an impersonal attack where a fraudster exploits a BIN (bank identification number) and uses distributed computing power to automatically generate the remaining numbers and test these combinations to see which card numbers are correct and if the cards are active. This kind of attack is called BIN attack fraud. The subtlety of BIN Attack fraud is that it does not involve any data breach or ID theft; it is just a pure random coincidence that a victim\u2019s card number is chosen. The compromised cards can have a significant impact on issuing banks in terms of chargebacks, call c entre volume spikes, and re-issuance expenses. Furthermore, any cardholder disruption or friction during this tenure leads to a loss of interchange revenues. The damage to the bank\u2019s reputation could lead to cardholders switching the bank\u2019s services to another, more secure bank. A merchant involved in BIN attack fraud faces increased disputes or chargebacks, additional fees, and regulatory fines. Depending on the nature of the attack and risk profile, the acquiring bank may choose to suspend support for the merchant\u2019s site. The cardholder\u2019s bank may restrict purchases from your site, resulting in further financial losses. Refunding any fraudulent transactions is an operational challenge, not to mention the reputational loss. Thus, BIN attack fraud is a problem both for issuers and merchants. Preventing a BIN Attack Fraud To prevent BIN attack fraud, the merchant or the issuing bank can deploy a few techniques: Enable 3D security. The latest version of EMV 3DS 2.x is an additional security layer for online credit and debit card transactions that aims to achieve a balance between security and user convenience. As a merchant, enable a CAPTCHA test to tell humans and bots apart. While this may create friction for genuine customers, it\u2019s an effective deterrent against BOT scripts. Deploy an anti-fraud solution that can look at many aspects and block transactions or alert your fraud analyst. A good anti-fraud solution should have: Ability to spot multiple low-value transactions (unusually low for the merchant\u2019s business). Multiple declines within a short period The timing of transactions may be unusual for the merchant, business, or cardholder. A large number of transactions from the same BIN were attempted in a short period of time (a few seconds apart). IP Velocity Checks: Even though these days, through proxy and spoofing, fraudsters can make it seem that the transactions are coming from different IPs, Use an anti-fraud solution that deploys good device fingerprinting techniques to solve this issue, as fingerprinting is impervious to IP proxies. Unusually large volume of international transactions for a given merchant or for a cardholder. Look for patterns, cards with sequential numbers, the same card number but different expiration dates, or CVV codes. Ability to create a profile for the merchant and cardholder and alert in case of any significant deviations. There are a few additional measures that the industry could take, such as creating advisory, actionable intelligence, and a listing of sites that anti-fraud tools can take advantage of. EMV 3DS 2.x allows merchants and acquirers to do a risk assessment prior to making an EMV 3DS authentication call to the issuer. A combined risk assessment from both the acquiring and issuing sides acts as a strong deterrent to fraudsters. Both issuers and acquirers can pool their intelligence and create a shared intelligence pool of fraud markings to identify common points of fraud. Information on declines on the switch side during authorization when fed into 3DS authentication ACS gives actionable intelligence to anti-fraud tools. BIN attack fraud is still a crude brute-force attack vector that is detectable, and preventive measures can be taken to interrupt it. A well-informed merchant and bank implementing a defensive anti-fraud solution that keeps itself abreast of the latest advisories combined with continuous monitoring of anomalous behaviour can stay a step ahead of this kind of fraudulent attack. Author: Ajit Nair, Director Product Management Wibmo A PayU\/Naspers FinTech Company Cnp, Fraud, Fraud Prevention, Payment Fraud, Payments","og_url":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/","og_site_name":"Digital Payments, Payment Security and Lending - Wibmo","article_published_time":"2023-06-01T06:44:00+00:00","article_modified_time":"2024-06-04T06:00:19+00:00","og_image":[{"width":1400,"height":782,"url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/BIN.webp","type":"image\/webp"}],"author":"Wibmo","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Wibmo","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/#article","isPartOf":{"@id":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/"},"author":{"name":"Wibmo","@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/person\/b40d974b488414d9d2fc9790e585454b"},"headline":"BIN Attack Fraud","datePublished":"2023-06-01T06:44:00+00:00","dateModified":"2024-06-04T06:00:19+00:00","mainEntityOfPage":{"@id":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/"},"wordCount":788,"commentCount":0,"publisher":{"@id":"https:\/\/wibmo.com\/blogs\/#organization"},"image":{"@id":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/#primaryimage"},"thumbnailUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/BIN.webp","keywords":["Cnp","Fraud","Fraud Prevention","Payment Fraud","Payments"],"articleSection":["Reading List","Stories"],"inLanguage":"en","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/","url":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/","name":"BIN Attack Fraud - Digital Payments, Payment Security and Lending - Wibmo","isPartOf":{"@id":"https:\/\/wibmo.com\/blogs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/#primaryimage"},"image":{"@id":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/#primaryimage"},"thumbnailUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/BIN.webp","datePublished":"2023-06-01T06:44:00+00:00","dateModified":"2024-06-04T06:00:19+00:00","breadcrumb":{"@id":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/#primaryimage","url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/BIN.webp","contentUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/BIN.webp","width":1400,"height":782},{"@type":"BreadcrumbList","@id":"https:\/\/wibmo.com\/blogs\/bin-attack-fraud\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/wibmo.com\/blogs\/"},{"@type":"ListItem","position":2,"name":"BIN Attack Fraud"}]},{"@type":"WebSite","@id":"https:\/\/wibmo.com\/blogs\/#website","url":"https:\/\/wibmo.com\/blogs\/","name":"Digital Payments, Payment Security and Lending - Wibmo","description":"","publisher":{"@id":"https:\/\/wibmo.com\/blogs\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/wibmo.com\/blogs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":"Organization","@id":"https:\/\/wibmo.com\/blogs\/#organization","name":"Digital Payments, Payment Security and Lending - Wibmo","url":"https:\/\/wibmo.com\/blogs\/","logo":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/logo\/image\/","url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/08\/cropped-New-Project.png","contentUrl":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/08\/cropped-New-Project.png","width":220,"height":45,"caption":"Digital Payments, Payment Security and Lending - Wibmo"},"image":{"@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/wibmo.com\/blogs\/#\/schema\/person\/b40d974b488414d9d2fc9790e585454b","name":"Wibmo","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/4e0292824dccdc846c40f4b0f69060297bdf937f87f4393fe7ce4e84df38685e?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/4e0292824dccdc846c40f4b0f69060297bdf937f87f4393fe7ce4e84df38685e?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4e0292824dccdc846c40f4b0f69060297bdf937f87f4393fe7ce4e84df38685e?s=96&d=mm&r=g","caption":"Wibmo"},"url":"https:\/\/wibmo.com\/blogs\/author\/wibmo\/"}]}},"jetpack_featured_media_url":"https:\/\/wibmo.com\/blogs\/wp-content\/uploads\/2024\/05\/BIN.webp","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/posts\/4405","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/comments?post=4405"}],"version-history":[{"count":0,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/posts\/4405\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/media\/4453"}],"wp:attachment":[{"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/media?parent=4405"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/categories?post=4405"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wibmo.com\/blogs\/wp-json\/wp\/v2\/tags?post=4405"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}