Mastercard SPME §6.2 · May 2023 → Sep 2023
Mastercard Fraud Loss Control Program Standards
The update clarifies that several fraud control measures are recommended but not always mandatory. It introduces specific thresholds and detailed monitoring requirements, especially regarding BIN attacks, ATM fraud, negative option billing, 3-D Secure monitoring, and ongoing fraud and transaction monitoring. Additional recommended tools and policies for acquirers are also detailed.
Security Rules and Procedures—Merchant Edition • 7 February 2023
- Implement MDES for Merchant (M4M) to replace real card data by tokenized and digitized payment credentials (tokens)
- EMV Chip Terminals with PIN Capability (Please refer to existing mandates in specific countries) The MCC submitted at the time of authentication should match the MCC submitted at the time of the authorization except when a single authentication relates to multiple authorizations for different merchants. Addressing BIN Attacks BIN attacks either detected by the Acquirer or communicated to the Acquirer by Mastercard, must be mitigated by the Acquirer, its processor(s) or the concerned Merchant(s) within 72 hours (or within a timeframe approved by Mastercard) of detection by the Acquirer, its Service Provider, the Merchant or notification by Mastercard. By way of example, an attack will be qualified as a BIN attack when the following two conditions are met:
Security Rules and Procedures—Merchant Edition • 1 August 2023
Recommendations An Acquirer is recommended to implement the following with each of its Merchants and Payment Facilitators:
- The authentication recommendations listed in Mastercard Identity Check™ Program Guide
- Implement MDES for Merchant (M4M) to replace real card data by tokenized and digitized payment credentials (tokens)
- EMV Chip Terminals with PIN Capability (Please refer to existing mandates in specific countries) The MCC submitted at the time of authentication should match the MCC submitted at the time of the authorization except when a single authentication relates to multiple authorizations for different merchants. Addressing BIN Attacks BIN attacks either detected by the Acquirer or communicated to the Acquirer by Mastercard, must be mitigated by the Acquirer, its processor(s) or the concerned Merchant(s) within 72 hours (or within a timeframe approved by Mastercard) of detection by the Acquirer, its Service Provider, the Merchant or notification by Mastercard. By way of example, an attack will be qualified as a BIN attack when the following two conditions are met:
- At least 100 authorization requests or authentication requests are sent within one hour for the BIN or BIN Account range from one or more Merchants.
- The Issuer, its Service Provider, or Mastercard (using a network fraud detection tool) declined fifty percent (50%) or more of the authorization requests or authentication requests within one hour. An Acquirer must also analyze each BIN or BIN Account range attack to identify its modus operandi and implement corrective measures to prevent future attacks using the same technique(s). Suspicious ATM Activity Each ATM Terminal Acquirer and its Service Providers or other agents acting on its behalf must have sufficient controls, resources and monitoring systems for the prompt detection and reporting of suspicious ATM activity as required by Mastercard Rule 1.2. ATM Terminal Acquirers are obligated under Mastercard Rule 1.2 to monitor and report suspicious ATM Transaction activity, regardless if the issuer has or has not reported the activity as fraud. Suspicious money laundering activity may include, but is not limited to:
- Out-of-pattern ATM withdrawal volume and/or velocity at an individual ATM or groups of ATMs
- Sequential or consecutive high volumes of ATM withdrawals at the same ATM(s) by multiple cards from the same issuer
- Significantly high volumes of repetitive ATM withdrawal amount consistently over time Fraud Loss Control Standards Addressing BIN Attacks Security Rules and Procedures—Merchant Edition • 1 August 2023
- Excessive ATM withdrawals at maximum Transaction limits of ATM in a short period of time
- Out-of-pattern excessive or high volumes of ATM deposits ATM Authorization Controls and Cash-out Attack Management Each ATM Terminal Acquirer and its Service Providers must, upon detecting a cash-out attack or receiving notification from Mastercard or a Mastercard solution (for example, Safety Net Alert) of a confirmed cash-out attack:
- Block acceptance of the BIN under attack at the ATM Terminal within five hours (unless Mastercard notifies the Acquirer that Mastercard has taken action to stop the attack)
- If requested by Mastercard, following issuer confirmation of an attack, acquirer is recommended to contact law enforcement for initiating an investigation of the on-going attack, including if possible, the detection and communication of ATM address in real-time (or quasi-real time) to Law Enforcement.
- If the ATMs are equipped with a camera, acquirers are recommended to safeguard the video recording for sharing with Law Enforcement where legally allowed. An Acquirer of ATM Transactions must ensure that each Service Provider acting on its behalf has the capability, upon detection of suspected fraud, to adjust (typically reduce) the maximum withdrawal amount per Transaction at individual ATM Terminals to mitigate potential losses. 6.2.2.2.1 Additional Acquirer Authorization Monitoring Requirements for Negative Option Billing Merchants In addition to the Acquirer authorization monitoring requirements listed in section 6.2.2.2 of this manual, an Acquirer of a negative option billing Merchant must monitor authorization Transaction messages to identify when the same Account number appears among different negative option billing Merchant IDs in the Acquirer’s Portfolio within 60 calendar days. When the Acquirer identifies such an Account, the Acquirer must take reasonable steps to verify that each Transaction conducted by the valid Cardholder with the associated negative option billing Merchant is a bona fide Transaction. This verification may include, but is not limited to, an electronic copy or hard copy of the Transaction information document (TID). All such verification information must be:
- Retained by the Acquirer for a period of at least one year from the verification date; and
- Made available to Mastercard upon request. 6.2.2.2 Acquirer Authorization Monitoring Requirements An Acquirer must implement real-time or near-real time alerts to monitor Merchant authorization messages on at least all of the following parameters:
- Number of authorization requests above a threshold set by the Acquirer for that Merchant
- An authorization approval rate that falls below a threshold set by the Acquirer for that Merchant
- Ratio of non-Card-read to Card-read Transactions that is above the threshold set by the Acquirer for that Merchant
- PAN key entry ratio that is above the threshold set by the Acquirer for that Merchant Fraud Loss Control Standards ATM Authorization Controls and Cash-out Attack Management Security Rules and Procedures—Merchant Edition • 1 August 2023
- Repeated authorization requests for the same amount or the same Cardholder Account
- Ratio of technical fallback above a threshold set by the Acquirer for that Merchant
- Merchant authorization reversals that do not match a previous purchase Transaction
- Value of Merchant authorization refund that is above the threshold set by the Acquirer for that Merchant
- Out-of-pattern Transaction volume and/or velocity at a Merchant, Payment Facilitator, or ATM Terminal, including all of the following: – Repeated authorization requests – High velocity authorizations – Technical fallback of chip to magnetic stripe – High volume of Contactless Transactions – Sequential Account generated attacks – An abnormal increase in authorization requests received – An abnormal increase in the average Transaction amount – BIN attacks, defined as Account testing or highly unusual activity in connection with the use of Cards or Accounts issued under one or more BINs – An abnormally high number of authorization request responses indicating invalid PAN, CVC 1 or CVC 2 failure, invalid expiration date, incorrect PIN, Address Verification Service (AVS) mismatch, invalid Authorization Request Cryptogram (ARQC), or invalid Accountholder authentication value (AAV). – Transaction decline rate: – An excessive number of magnetic stripe Transactions occurring or attempted in a short period of time – An excessive number of ATM cash withdrawals occurring or attempted at the maximum cash withdrawal Transaction limit for that ATM in a short period of time 6.2.2.3 Acquirer Merchant Deposit Monitoring Requirements A deposit is defined as a file of Transactions performed offline or online at a Merchant and submitted to the Merchant’s Acquirer for payment. If deposit files are not used, the Acquirer should still monitor the total payment made to each Merchant. Daily reports or real-time alerts monitoring Merchant deposits must be generated at the latest on the day following the deposit, and must be based on the following parameters:
- Increases in Merchant deposit volume
- Increase in a Merchant’s average ticket size and number of Transactions for each deposit
- Change in frequency of deposits
- Change in technical fallback rates, or a technical fallback rate that exceeds five percent of a Merchant’s total Transaction volume NOTE: Any report generated by the Acquirer relating to the investigation of a Merchant whose rate of technical fallback exceeds five percent of its total Transaction volume must be made available to Mastercard upon request.
- Force-posted Transactions (i.e., a Transaction that has been declined by the Issuer or the chip or any Transaction for which authorization was required but not obtained) Fraud Loss Control Standards 6.2.2.3 Acquirer Merchant Deposit Monitoring Requirements Security Rules and Procedures—Merchant Edition • 1 August 2023
- Frequency of Transactions on the same Account, including credit (refund) Transactions
- Unusual number of credits, or credit dollar volume, exceeding a level of sales dollar volume appropriate to the Merchant category
- Large credit Transaction amounts, significantly greater than the average ticket size for the Merchant’s sales
- Credit (refund) Transaction volume that exceeds purchase Transaction volume
- Credits issued by a Merchant subsequent to the Acquirer’s receipt of a chargeback with the same PAN
- Credits issued by a Merchant to a PAN not previously used to effect a Transaction at the Merchant location
- Increases in Merchant chargeback volume 90-day Rule: Monitoring of Merchant Daily Volumes The Acquirer must monitor the daily Transaction count and value at each Merchant in view of detecting abnormal or suspicious increase of Merchant activity. To this effect, the daily Transactions count and value will be compared against the average daily Transaction count and amount for a period of at least 90 days, to lessen the effect of normal variances in a Merchant’s business. For a new Merchant, the Acquirer should set monitoring parameters to detect significant deviation from the Merchant’s expected turnover as detailed in its business plan. The Acquirer may also compare the Merchant’s average Transaction count and amount to those of other Merchants within the same MCC. In the event that suspicious credit or refund Transaction activity is identified, if appropriate, the Acquirer should consider the suspension of Transactions pending further investigation. 6.2.2.4 Acquirer Channel Management Requirements Mastercard requires Acquirers to monitor, on a regular basis, each parent Member ID/ICA number, child Member ID/ICA number, and individual Merchant, Payment Facilitator, and Staged Digital Wallet Operator in its Portfolio for the following:
- Total Transaction fraud basis points
- Domestic Transaction fraud basis points
- Cross-border Transaction fraud basis points (both Intraregional Transactions and Interregional Transactions)
- Fraud basis points at the parent Member ID/ICA level for the following: – Card-present Transactions – POS – Mobile POS (MPOS) – Cardholder-activated Terminal (CAT) (for example, CAT 1, CAT 2, and CAT 3) – Card-not-present (CNP) Transactions – E-commerce, including separate monitoring of non-authenticated, attempted authentication, and fully authenticated Transactions Fraud Loss Control Standards 6.2.2.4 Acquirer Channel Management Requirements Security Rules and Procedures—Merchant Edition • 1 August 2023 – Mail order/telephone order (MO/TO) – Recurring payment Transactions 6.2.2.5 3-D Secure Service Provider and Payment Gateway Monitoring Requirements and Recommendations Acquirers must implement fraud detection capabilities at any 3-D Secure Service Provider providing access to a 3-D Secure (3DS) server or Third Party Processor (TPP) performing payment gateway services to monitor all the following:
- Fraudulent attempts to connect to a 3DS server or payment gateway as a Merchant or Payment Facilitator (for example, a connection attempt from an unknown IP address or the use of an invalid credential)
- 3DS server or payment gateway Denial of Service (DoS) attack
- The authentication message flow indicating a PAN or BIN testing attack. This includes but is not limited to detection of (and capability to block) bot attacks using captcha, behavioral analytic tools or other available solutions. Bot attacks are defined as the use of automated web requests to test PANs through a 3DS Server payment gateway or more generally defined as web requests to manipulate, defraud, or disrupt a web site.
- Ensure Merchant names used in authentication messages match registered Merchant names
- Out-of-pattern number of single or multiple PAN Transactions associated to same customer account identifier or originating source (for example, the same email, telephone number, delivery address, browser fingerprint, or device identification number) An Acquirer is recommended to implement fraud detection capabilities at 3DS Server payment gateways to monitor all the following:
- Receipt of confirmed fraud from Acquirers in view of creating a gray or negative listing of related IP and delivery address
- Additional monitoring recommendations and best practices as detailed in “Risk-based Authentication” section of the Mastercard Identity Check™ Program Guide Upon detection of a 3DS Server payment gateway fraud attack by the Acquirer or upon notification from Mastercard of such an attack, the Acquirer must implement the necessary controls at the 3DS Server payment gateway to stop the attack within 72 hours (or within a timeframe approved by Mastercard) of detection or notification by Mastercard. An Acquirer and its 3DS Server payment gateway must also analyze each attack to identify its modus operandi and implement corrective measures to prevent future attacks using the same technique(s). 6.2.2.6 Recommended Additional Acquirer Monitoring Mastercard recommends that Acquirers additionally monitor the following parameters:
- Mismatch of Merchant name, MCC, Merchant ID, and/or Terminal ID
- Mismatch of e-commerce Merchant Internet Protocol (IP) addresses
- Transactions conducted at Merchant, Sponsored Merchants, and other entities registered in the Specialty Merchant Registration Program (refer to Chapter 9) Fraud Loss Control Standards 6.2.2.5 3-D Secure Service Provider and Payment Gateway Monitoring Security Rules and Procedures—Merchant Edition • 1 August 2023
- Abnormal hours (i.e., outside of normal business hours) or seasons
- Sudden start of activity by an inactive/dormant Merchant (i.e., a Merchant that has not yet started to accept Cards or has ceased to accept Cards)
- Inconsistent authorization and clearing data elements for the same Transactions
- Mastercard SecureCode/Identity Check™ authentication rate
- Any Merchant exceeding the Acquirer’s total Merchant average for fraud by 150 percent or more Geographic volume variances (i.e., abnormal increase of Merchant activity with some Issuer countries)
- Monitor the value, if any, returned in DE 48 subelement 84 (Merchant Advice Code) of authorization request response messages. An Acquirer is recommended to cease resending the same authorization request message when the MAC value is equal to 03 (Do Not Try Again) or 21 (Payment Cancellation). 6.2.2.7 Recommended Fraud Detection Tool Implementation An Acquirer is recommended to implement a fraud detection tool that appropriately complements the fraud strategy deployed by the Acquirer. The combination of the authorization requirements, Merchant deposit monitoring requirements, and fraud detection tool should ensure that an Acquirer controls fraud to an acceptable level. 6.2.2.8 Ongoing Merchant Monitoring An Acquirer must implement procedures for the conduct of periodic ongoing reviews of a Merchant's, Payment Facilitator's, or Staged Digital Wallet Operator's Transaction activity, for the purpose of detecting changes over time, including but not limited to:
- Monthly Transaction volume with respect to: – Total Transaction count and amount – Number of credit (refund) Transactions – Number of fraudulent Transactions – Average ticket size – Number of chargebacks and basis points
- Activity inconsistent with the Merchant’s business model
- Transaction laundering
- Activity that is or may potentially be illegal or brand-damaging As a best practice, Mastercard recommends that Acquirers use a Merchant monitoring solution for e-commerce Merchant activity so as to avoid processing illegal or brand-damaging Transactions. For more information on ongoing Merchant monitoring requirements, refer to section 7.2. 6.2.2.9 Communicating Fraud and Chargeback Data to Merchants and Payment Facilitators An Acquirer must be able, upon request from its Merchants and Payment Facilitators, to provide them with their fraud and chargeback data on a regular basis and at least monthly. Fraud Loss Control Standards 6.2.2.7 Recommended Fraud Detection Tool Implementation Security Rules and Procedures—Merchant Edition • 1 August 2023 6.2.2.10 Fraud and Loss Control Internal Policies, Tracking, and Reporting Tools Acquirers must establish internal policies, tracking and reporting tools covering all the following:
- Identification of individual Merchants and Payment Facilitators having a monthly average fraud, chargeback or decline rate exceeding thresholds set by the Acquirer, above which, an investigation of Merchant activities should be conducted to identify and implement any practices that require corrective actions. In all cases, these thresholds should be set to levels that maintain Merchant and payment facilitator compliance with Mastercard programs.
- Systematic investigation of any Standard violation by a Merchant, Payment Facilitator, Stage Digital Wallet Operator or ATM owner, either identified by the Acquirer or communicated by Mastercard. Each investigation must be followed by the identification and timely implementation of corrective actions to re-establish compliance with the Standards. An Acquirer is recommended (unless mandated by Mastercard for a specific program) to create an internal report (the “investigation report”) for each of the above events or exceeded thresholds and must include the following minimum information:
- Investigation number
- Investigation type
- Investigation date
- Detailed event description and analysis
- Description of the corrective actions
- Date the corrective action(s) was/were implemented
- Name of responsible person 6.2.2.11 Acquirer Recommendation to Report Suspected Fraud An Acquirer is recommended to report Transactions to the Fraud and Loss Database that the Acquirer deems to be fraudulent as suspected fraud Transactions. 6.2.2.12 Acquirer Response to High Impact/Critical Fraud Alerts Raised by Issuers An Acquirer approached by an Issuer with a High Impact/Critical Fraud management request is recommended to collaborate with the Issuer to the best of its ability. Fraud Loss Control Standards 6.2.2.10 Fraud and Loss Control Internal Policies, Tracking, and Reporting Tools Security Rules and Procedures—Merchant Edition • 1 August 2023 Chapter 7 Merchant, Sponsored Merchant, and ATM Owner Screening and Monitoring Standards This chapter may be of particular interest to Customer personnel responsible for screening and monitoring Merchants, Sponsored Merchants, and ATM owners.
program: Fraud Monitoring- authority: Mastercard SPME §3.7, §11.1.1+ authority: Mastercard SPME §3.7, §6.2, §11.1.1fraud_to_sales_ratio_threshold: 0.015min_count_per_month: 100monitoring_cadence: monthlyescalation_actions:- escalate_to_human_review- notify_acquirerlookback_period_months: 1remediation_review_interval_days: 30agent_owner: fraud_ops_agent- # MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1.+ # MATCH fraud detection features remain limited to principal owners only, with associate owners and Service Provider name reporting removed as per SPME §11.1.1.# Acquirers may add and search for information on up to five principal owners per Merchant.- # Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays.+ # Multiple data fields are used to determine matches, supporting editing and error notification to reduce delays.# Retroactive alert processing is supported for data up to 360 days old.# Acquirers control receipt and detail of inquiry match information.# Real-time access via MATCH Online and API, and batch operations remain available.# Merchant URL information may be added and searched.- # Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements.+ # Upon obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted.++ # Enhanced Fraud Monitoring Requirements (per Mastercard SPME §6.2)+ # Acquirers must implement real-time or near-real-time monitoring covering:+ # - Authorization request volume exceeding Merchant-specific thresholds+ # - Authorization approval rates falling below defined thresholds+ # - Non-Card-read to Card-read transaction ratios above thresholds+ # - PAN key entry ratio anomalies+ # - Repeated authorization requests for the same amount or Cardholder Account+ # - Technical fallback ratio anomalies+ # - Authorization reversals without matching prior purchase transactions+ # - Excessive authorization refund values+ # - Out-of-pattern transaction volume and velocity, including high velocity authorizations, high volume contactless transactions, sequential account attacks+ # - BIN attacks defined by rapid volume and high decline rates requiring mitigation within 72 hours+ # Acquirers must analyze BIN attacks to identify techniques and implement corrective actions.+ # ATM terminal acquirers must monitor for suspicious ATM activity including unusual withdrawal volumes, sequential high volumes, and excessive deposits.+ # Upon detection or notification of cash-out attacks, prompt blocking of affected BINs at the ATM (within five hours) is mandated.+ # Acquirers are advised to engage law enforcement and preserve video evidence where legally permissible.+ # Negative option billing Merchants require additional monitoring to detect shared Account numbers across Merchant IDs within 60 days and verify bona fide transactions, retaining evidence for at least one year.+ # These enhanced monitoring measures supplement existing MATCH and fraud detection tools to strengthen Fraud Monitoring program effectiveness.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
After accessing MATCH data, conduct a comprehensive risk assessment
to determine whether furtherincorporating new Mastercard acquirer monitoring recommendations, including real-time alerts for unusual authorization patterns, BIN attack indicators, and ATM transaction anomalies.
5. Escalate investigation or additional and fraud mitigation measures are warranted. ¶ 5. in response to detected BIN attacks or suspicious ATM activities, ensuring timely response within Mastercard-specified timeframes.
6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
6. 7. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7 §3.7, §6.2, and §11.1.1.
Fraud Monitoring
Halyard Pay monitors merchant fraud activity and leverages Mastercard's MATCH system for enhanced fraud risk assessment on merchants processed through our platform.
When this policy applies
This policy applies to all merchants processed by Halyard Pay where Mastercard is the applicable network, covering both card-present and card-not-present transactions.
Required actions
-
Compute the merchant's rolling fraud-to-sales ratio each calendar month.
-
If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately.
-
Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments.
-
After accessing MATCH data, conduct a comprehensive risk assessment
to determine whether furtherincorporating new Mastercard acquirer monitoring recommendations, including real-time alerts for unusual authorization patterns, BIN attack indicators, and ATM transaction anomalies.
5. Escalate investigation or additional and fraud mitigation measures are warranted. ¶ 5. in response to detected BIN attacks or suspicious ATM activities, ensuring timely response within Mastercard-specified timeframes.
6. Notify the acquiring compliance officer and document the case ID with supporting transaction data.
6. 7. Track case progress until the account returns to threshold compliance or is terminated.
Source authority: Mastercard SPME §3.7 §3.7, §6.2, and §11.1.1.
Source authority: Mastercard SPME §6.2.
--- a/policies/fraud_monitoring/rules.yaml +++ b/policies/fraud_monitoring/rules.yaml @@ -1,5 +1,5 @@ program: Fraud Monitoring -authority: Mastercard SPME §3.7, §11.1.1 +authority: Mastercard SPME §3.7, §6.2, §11.1.1 fraud_to_sales_ratio_threshold: 0.015 min_count_per_month: 100 monitoring_cadence: monthly @@ -10,11 +10,30 @@ remediation_review_interval_days: 30 agent_owner: fraud_ops_agent -# MATCH fraud detection features are limited to principal owners only; associate owners and Service Provider name reporting are removed per SPME §11.1.1. +# MATCH fraud detection features remain limited to principal owners only, with associate owners and Service Provider name reporting removed as per SPME §11.1.1. # Acquirers may add and search for information on up to five principal owners per Merchant. -# Multiple data fields are used to determine matches; MATCH supports editing and error notification to reduce delays. +# Multiple data fields are used to determine matches, supporting editing and error notification to reduce delays. # Retroactive alert processing is supported for data up to 360 days old. # Acquirers control receipt and detail of inquiry match information. # Real-time access via MATCH Online and API, and batch operations remain available. # Merchant URL information may be added and searched. -# Crucially, after obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted, per updated SPME requirements. +# Upon obtaining MATCH inquiry results, Acquirers must assess whether further investigation or risk mitigation actions are warranted. + +# Enhanced Fraud Monitoring Requirements (per Mastercard SPME §6.2) +# Acquirers must implement real-time or near-real-time monitoring covering: +# - Authorization request volume exceeding Merchant-specific thresholds +# - Authorization approval rates falling below defined thresholds +# - Non-Card-read to Card-read transaction ratios above thresholds +# - PAN key entry ratio anomalies +# - Repeated authorization requests for the same amount or Cardholder Account +# - Technical fallback ratio anomalies +# - Authorization reversals without matching prior purchase transactions +# - Excessive authorization refund values +# - Out-of-pattern transaction volume and velocity, including high velocity authorizations, high volume contactless transactions, sequential account attacks +# - BIN attacks defined by rapid volume and high decline rates requiring mitigation within 72 hours +# Acquirers must analyze BIN attacks to identify techniques and implement corrective actions. +# ATM terminal acquirers must monitor for suspicious ATM activity including unusual withdrawal volumes, sequential high volumes, and excessive deposits. +# Upon detection or notification of cash-out attacks, prompt blocking of affected BINs at the ATM (within five hours) is mandated. +# Acquirers are advised to engage law enforcement and preserve video evidence where legally permissible. +# Negative option billing Merchants require additional monitoring to detect shared Account numbers across Merchant IDs within 60 days and verify bona fide transactions, retaining evidence for at least one year. +# These enhanced monitoring measures supplement existing MATCH and fraud detection tools to strengthen Fraud Monitoring program effectiveness. --- a/policies/fraud_monitoring/policy.md +++ b/policies/fraud_monitoring/policy.md @@ -11,8 +11,9 @@ 1. Compute the merchant's rolling fraud-to-sales ratio each calendar month. 2. If the ratio meets or exceeds 1.5% and the fraud count reaches at least 100 transactions in that month, escalate the merchant account to human review immediately. 3. Utilize Mastercard's MATCH system data focusing on principal owners only, as per the updated Mastercard SPME guidelines. Do not consider associate owners or Service Provider names in fraud assessments. -4. After accessing MATCH data, conduct a risk assessment to determine whether further investigation or additional measures are warranted. -5. Notify the acquiring compliance officer and document the case ID with supporting transaction data. -6. Track case progress until the account returns to threshold compliance or is terminated. +4. After accessing MATCH data, conduct a comprehensive risk assessment incorporating new Mastercard acquirer monitoring recommendations, including real-time alerts for unusual authorization patterns, BIN attack indicators, and ATM transaction anomalies. +5. Escalate investigation and fraud mitigation measures in response to detected BIN attacks or suspicious ATM activities, ensuring timely response within Mastercard-specified timeframes. +6. Notify the acquiring compliance officer and document the case ID with supporting transaction data. +7. Track case progress until the account returns to threshold compliance or is terminated. -Source authority: Mastercard SPME §3.7 and §11.1.1. +Source authority: Mastercard SPME §3.7, §6.2, and §11.1.1.