Mastercard SPME §10.6 · Feb 2024 → Sep 2024

Mastercard Determination of ADC Event or Potential ADC Event

substantive
⚠ Extraction warning — review against source PDF. One side of the Mastercard SPME text below appears to contain only the page-running header, not body content. This usually means the section heading fell on a page boundary and the body was attributed to a neighbouring section in the source PDF. The AI summary and proposed edit below may be misleading. Verify in: Feb 2024 · page 122 ↗ · Sep 2024 · page 126 ↗.

The updated section clarifies detailed requirements for terminal servicer compliance and reporting related to ADC events, including PCI DSS validation, timely registration through Mastercard Connect, notification protocols, forensic investigation timing, and measures for reducing financial responsibility. It stresses the need for complete customer contact data and cooperation with investigations.

Sources Mastercard SPME · Feb 2024 · page 122 PDF Mastercard SPME · Sep 2024 · page 126 PDF ATO Detection current
Also in §10.x this release breaking §10.2 Policy Concerning Account Data Compromise Events and Potential Account Data breaking §10.3.1 Time-Specific Procedures for ADC Events and Potential ADC Events breaking §10.3.2 Ongoing Procedures for ADC Events and Potential ADC Events breaking §10.5 Alternative Acquirer Investigation (AAI) Standards substantive §10 Should the responsible Customer cause a PFI to conduct an examination, the responsible substantive §10.1 Applicability and Defined Terms substantive §10.3 Responsibilities in Connection with ADC Events and Potential ADC Events substantive §10.4 Forensic Report substantive §10.6.2 Potential Reduction of Financial Responsibility substantive §10.6.4 Determination of Operational Reimbursement (OR) substantive §10.7 Assessments and/or Disqualification for Noncompliance
Why these edits? The updated section 10.6 introduces detailed requirements related to Account Data Compromise (ADC) events, including investigation timelines, notification, and cooperation protocols, which directly impact the Account-Takeover Detection policy obligations.
Mastercard SPME §10.6
This section was substantively restructured between versions (2% text overlap). Compare the texts directly below.
Before · Feb 2024 · page 122

Security Rules and Procedures—Merchant Edition • 6 February 2024

After · Sep 2024 · page 126

Security Rules and Procedures—Merchant Edition • 6 August 2024

Application Data Security Standard or the Payment Card Industry Secure Software Standard, as applicable. The applicability of the PCI PA-DSS to third party-provided payment applications is defined in the PCI PA-DSS Program Guide and the applicability of the PCI Secure Software Standard to third party-provided payment software is defined in the PCI Secure Software Program Guide, found at www.pcisecuritystandards.org.

  • If the compromised entity is a Europe Region Merchant, a PFI has validated that the Merchant was compliant with milestones one and two of the PCI DSS Prioritized Approach at the time of the ADC Event or Potential ADC Event.
  • Registration of any TPP(s) or DSE(s) associated with the ADC Event through Mastercard Connect, in accordance with Chapter 7 of the Mastercard Rules.
  • Notification of an ADC Event or Potential ADC Event to and cooperation with Mastercard and, as appropriate, law enforcement authorities.
  • Verification that the PFI investigation was initiated within seventy-two (72) hours of the ADC Event or Potential ADC Event and completed as soon as practical.
  • Timely receipt by Mastercard of the unedited (by other than the forensic examiner) forensic examination findings.
  • Evidence that the ADC Event or Potential ADC Event was not foreseeable or preventable by commercially reasonable means and that, on a continuing basis, best security practices were applied. In connection with its evaluation of the Customer’s or its Agent’s actions, Mastercard will consider, and may draw adverse inferences from, evidence that a Customer or its Agent(s) deleted or altered data. As soon as practicable, Mastercard will contact the Customer’s Security Contact, Principal Contact, or Account Data Compromise Contact as they are listed in the My Company Manager application, notifying all impacted parties of the impending financial obligation or compensation, as applicable. It is the sole responsibility of each Customer, not Mastercard, to include current and complete information in the My Company Manager application. 10.6.2.1 Potential Reduction of Financial Responsibility for Terminal Servicer ADC Events Notwithstanding a Mastercard determination that an ADC Event occurred, Mastercard may consider the following actions taken by the compromised TS or the responsible Customer, as applicable, to establish, implement, and maintain procedures and support best practices to safeguard Account data prior to, during, and after the ADC Event or Potential ADC Event, in order to relieve, partially or fully, an otherwise responsible Customer of responsibility for any assessments, ADC operational reimbursement, and/or investigative costs. In determining whether to relieve a responsible Customer of any or all financial responsibility, Mastercard may consider whether the Terminal Servicer or the responsible Customer, as applicable, complied with all of the following requirements:
  • Substantiation to Mastercard from a PCI SSC-approved QSA of the compromised TS’s compliance with the PCI DSS at the time of the ADC Event or Potential ADC Event.
  • Reporting that certifies any Terminal Servicer(s) associated with the ADC Event or Potential ADC Event as compliant with the PCI DSS and all applicable Mastercard SDP Program Account Data Compromise Events 10.6.2.1 Potential Reduction of Financial Responsibility for Terminal Servicer ADC Events Security Rules and Procedures—Merchant Edition • 6 August 2024 requirements at the time of the ADC Event or Potential ADC Event in accordance with section 2.2.3 of this manual. Such reporting must also affirm that all third party-provided payment applications used by the Terminal Servicer(s) associated with the ADC Event or Potential ADC Event are compliant with the Payment Card Industry Payment Application Data Security Standard or the Payment Card Industry Secure Software Standard, as applicable. The applicability of the PCI PA-DSS to third party-provided payment applications is defined in the PCI PA-DSS Program Guide and the applicability of the PCI Secure Software Standard to third party-provided payment software is defined in the PCI Secure Software Program Guide, found at www.pcisecuritystandards.org.
  • Registration of any TS(s) associated with the ADC Event through Mastercard Connect, in accordance with Chapter 7 of the Mastercard Rules, within 10 calendar days of the TS or the responsible Customer being deemed aware of the ADC Event or Potential ADC Event.
  • Notification of an ADC Event or Potential ADC Event to and cooperation with Mastercard and, as appropriate, law enforcement authorities.
  • Verification that the PFI investigation was initiated within seventy-two (72) hours of the ADC Event or Potential ADC Event and completed as soon as practical.
  • Timely receipt by Mastercard of the unedited (by other than the forensic examiner) forensic examination findings.
  • Confirmation that any TS(s) associated with the ADC Event or Potential ADC Event completed all of the containment recommendations set forth in the forensic report, and that each such TS revalidated its compliance with the PCI DSS to Mastercard within 90 calendar days after the conclusion of the PFI’s investigation and has additionally demonstrated compliance with the DESV appendix of the PCI DSS within twelve (12) months from achieving full compliance with the PCI DSS. In connection with its evaluation of the Customer’s or its TS’s actions, Mastercard will consider, and may draw adverse inferences from, evidence that a Customer or its TS(s) deleted or altered data. As soon as practicable, Mastercard will contact the Customer’s Security Contact, Principal Contact, or Account Data Compromise Contact as they are listed in the My Company Manager application, notifying all impacted parties of the impending financial obligation or compensation, as applicable. It is the sole responsibility of each Customer, not Mastercard, to include current and complete information in the Company Contact Management application.
Halyard Pay · 2 files
program: ATO Detection
authority: Mastercard SPME §10.6.2.1
risk_threshold_for_3ds_challenge: 0.5
risk_score_range: [0.0, 1.0]
signals:
- geo_anomaly
- device_fingerprint_change
- velocity_breach
- credential_stuffing
challenge_method: 3ds_v2
persistent_risk_escalation_threshold: 3
persistent_risk_lookback_days: 7
agent_owner: ato_agent
 
- # This policy update reflects the expanded requirements in Mastercard SPME §10.6.2.1 for Terminal Servicers in Account Data Compromise (ADC) events,
- # including mandated PCI DSS compliance verification at event time, timely forensic investigations, and enforced containment measures with
- # a 90-day PCI DSS revalidation and a further 12-month PCI DESV appendix compliance period. These detailed steps support risk mitigation
- # aligned with Mastercard’s enhanced responsibility reductions during ADC events, reinforcing rigorous security controls within the ATO detection program.
+ # This policy update reflects the expanded Mastercard SPME §10.6.2.1 requirements for Terminal Servicers involved in Account Data Compromise (ADC) events,
+ # emphasizing mandatory PCI DSS compliance verification verified by a PCI SSC-approved QSA at the ADC event time, timely initiation and completion of
+ # forensic investigations within 72 hours, and rigorous containment including PCI DSS revalidation within 90 days and DESV appendix compliance within 12 months.
+ # Furthermore, prompt registration of affected Terminal Servicers via Mastercard Connect, full cooperation with Mastercard and law enforcement, and strict
+ # record integrity are required. These measures enhance the ATO detection program’s alignment with Mastercard’s criteria for possible financial responsibility relief.

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.

  4. Log all ATO signals and outcomes in the case management system.

  5. Escalate persistent high-risk accounts to the ATO response team for manual review.

  6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved revalidates promptly initiates a forensic investigation by a PCI Forensic Investigator (PFI) within 72 hours, and completes it as soon as practical.

7. Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after completion of a the conclusion of the forensic investigation, demonstrates investigation and demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent with the requirements outlined in per Mastercard SPME §10.6.2.1.

7. Require prompt initiation and 8. Assure registration of any Terminal Servicer(s) associated with the ADC Event through Mastercard Connect within 10 calendar days of awareness, and confirm full cooperation with Mastercard and law enforcement authorities.

9. Verify timely completion of receipt by Mastercard of unedited forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event. ¶ 8. Confirm examination findings.

10. Ensure that all identified required containment actions from identified in forensic reports have been are completed by involved the Terminal Servicers. Servicers involved.

These enhanced controls align with Mastercard's comprehensive approach reinforce Halyard Pay’s adherence to minimizing the risk and impact of Mastercard’s strengthened ADC events event protocols, supporting minimized risk and financial exposure through stringent compliance and timely response protocols. remediation.

Source authority: Mastercard SPME §6.2, §10.6.2.1.

policies/ato_detection/policy.md — after applying change

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.

  4. Log all ATO signals and outcomes in the case management system.

  5. Escalate persistent high-risk accounts to the ATO response team for manual review.

  6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved revalidates promptly initiates a forensic investigation by a PCI Forensic Investigator (PFI) within 72 hours, and completes it as soon as practical.

7. Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after completion of a the conclusion of the forensic investigation, demonstrates investigation and demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent with the requirements outlined in per Mastercard SPME §10.6.2.1.

7. Require prompt initiation and 8. Assure registration of any Terminal Servicer(s) associated with the ADC Event through Mastercard Connect within 10 calendar days of awareness, and confirm full cooperation with Mastercard and law enforcement authorities.

9. Verify timely completion of receipt by Mastercard of unedited forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event. ¶ 8. Confirm examination findings.

10. Ensure that all identified required containment actions from identified in forensic reports have been are completed by involved the Terminal Servicers. Servicers involved.

These enhanced controls align with Mastercard's comprehensive approach reinforce Halyard Pay’s adherence to minimizing the risk and impact of Mastercard’s strengthened ADC events event protocols, supporting minimized risk and financial exposure through stringent compliance and timely response protocols. remediation.

Source authority: Mastercard SPME §6.2, §10.6.2.1.

Source authority: Mastercard SPME §10.6.

--- a/policies/ato_detection/rules.yaml
+++ b/policies/ato_detection/rules.yaml
@@ -12,7 +12,8 @@
 persistent_risk_lookback_days: 7
 agent_owner: ato_agent
 
-# This policy update reflects the expanded requirements in Mastercard SPME §10.6.2.1 for Terminal Servicers in Account Data Compromise (ADC) events,
-# including mandated PCI DSS compliance verification at event time, timely forensic investigations, and enforced containment measures with
-# a 90-day PCI DSS revalidation and a further 12-month PCI DESV appendix compliance period. These detailed steps support risk mitigation
-# aligned with Mastercard’s enhanced responsibility reductions during ADC events, reinforcing rigorous security controls within the ATO detection program.
+# This policy update reflects the expanded Mastercard SPME §10.6.2.1 requirements for Terminal Servicers involved in Account Data Compromise (ADC) events,
+# emphasizing mandatory PCI DSS compliance verification verified by a PCI SSC-approved QSA at the ADC event time, timely initiation and completion of
+# forensic investigations within 72 hours, and rigorous containment including PCI DSS revalidation within 90 days and DESV appendix compliance within 12 months.
+# Furthermore, prompt registration of affected Terminal Servicers via Mastercard Connect, full cooperation with Mastercard and law enforcement, and strict
+# record integrity are required. These measures enhance the ATO detection program’s alignment with Mastercard’s criteria for possible financial responsibility relief.

--- a/policies/ato_detection/policy.md
+++ b/policies/ato_detection/policy.md
@@ -13,11 +13,12 @@
 3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.
 4. Log all ATO signals and outcomes in the case management system.
 5. Escalate persistent high-risk accounts to the ATO response team for manual review.
-6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved revalidates PCI DSS compliance within 90 calendar days after completion of a forensic investigation, demonstrates compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent with the requirements outlined in Mastercard SPME §10.6.2.1.
+6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved promptly initiates a forensic investigation by a PCI Forensic Investigator (PFI) within 72 hours, and completes it as soon as practical.
+7. Confirm that all involved Terminal Servicers revalidate PCI DSS compliance within 90 calendar days after the conclusion of the forensic investigation and demonstrate compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, per Mastercard SPME §10.6.2.1.
+8. Assure registration of any Terminal Servicer(s) associated with the ADC Event through Mastercard Connect within 10 calendar days of awareness, and confirm full cooperation with Mastercard and law enforcement authorities.
+9. Verify timely receipt by Mastercard of unedited forensic examination findings.
+10. Ensure that all required containment actions identified in forensic reports are completed by the Terminal Servicers involved.
 
-7. Require prompt initiation and timely completion of forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event.
-8. Confirm that all identified containment actions from forensic reports have been completed by involved Terminal Servicers.
-
-These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events through stringent compliance and timely response protocols.
+These enhanced controls reinforce Halyard Pay’s adherence to Mastercard’s strengthened ADC event protocols, supporting minimized risk and financial exposure through compliance and timely remediation.
 
 Source authority: Mastercard SPME §6.2, §10.6.2.1.