Mastercard SPME §6.2 · Feb 2024 → Sep 2024

Mastercard Fraud Loss Control Program Standards

substantive

The update adds recommended temporary BIN attack mitigation measures for Acquirers in Europe (excluding certain countries), including use of CVC2, CAPTCHA, and merchant blocking. It also introduces enhanced ongoing monitoring guidelines for e-commerce, recurring payments, and Sponsored Merchants, especially in Europe, plus clarifies some wording around attack analysis and monitoring parameters.

Sources Mastercard SPME · Feb 2024 · page 59 PDF Mastercard SPME · Sep 2024 · page 60 PDF ATO Detection current
Why these edits? The update introduces recommended temporary BIN attack mitigation measures including use of CVC2, CAPTCHA, and merchant blocking specifically for Acquirers in Europe, enhancing account takeover detection and response obligations under section 6.2.
Mastercard SPME §6.2
Security Rules and Procedures—Merchant Edition • 6 February August 2024 Recommendations An Acquirer is recommended to implement the following with each of its Merchants and Payment Facilitators: • The authentication recommendations listed in Mastercard Identity Check Program Guide • Implement MDES for Merchant (M4M) to replace real card Card data by tokenized and digitized payment credentials (tokensTokens) • EMV Chip Terminals with PIN Capability capability (refer to existing mandates in specific countries) The MCC submitted at the time of authentication should match the MCC submitted at the time of the authorization except when a single authentication relates to multiple authorizations for different merchants. Merchants. Addressing BIN Attacks BIN attacks either detected by the Acquirer or communicated to the Acquirer by Mastercard, must be mitigated by the Acquirer, its processor(s) or the concerned Merchant(s) within 72 hours (or within a timeframe time frame approved by Mastercard) of detection by the Acquirer, its Service Provider, or the Merchant or notification by Mastercard. By way of example, an attack will be qualified as a BIN attack when the following two conditions are met: 1. At least 100 authorization requests or authentication requests are sent within one hour for the BIN or BIN Account range from one or more Merchants. 2. The Issuer, its Service Provider, or Mastercard (using a network fraud detection tool) declined fifty percent (50%) or more of the authorization requests or authentication requests within one hour. An Acquirer must also analyze each BIN or BIN Account range attack to identify its modus ¶ operandi method of operation and implement corrective measures to prevent future attacks using the same technique(s). An Acquirer in the Europe Region, excluding Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan, Kyrgyzstan, Moldova, Tajikistan, Turkey, Turkmenistan, Ukraine, and Uzbekistan, is recommended to mitigate BIN attacks by employing the following temporary measures until the attack stops: Sending CVC 2 in the Authorization Request/0100 message (refer to Section 3.12.4 "Acquirer Requirements for CVC 2") Applying CAPTCHA Blocking merchants Where necessary, the Acquirer may need to work with their Merchant Payment Gateway in order to deploy the above measures. Suspicious ATM Activity Each ATM Terminal Acquirer and its Service Providers or other agents acting on its behalf must have sufficient controls, resources and monitoring systems for the prompt detection and reporting of suspicious ATM activity as required by Mastercard Rule 1.2. Fraud Loss Control Standards Addressing BIN Attacks Security Rules and Procedures—Merchant Edition • 6 August 2024 ATM Terminal Acquirers are obligated under Mastercard Rule 1.2 to monitor and report suspicious ATM Transaction activity, regardless if the issuer has or has not reported the activity as fraud. Suspicious money laundering activity may include, but is not limited to: • Out-of-pattern ATM withdrawal volume and/or velocity at an individual ATM or groups of ATMs • Sequential or consecutive high volumes of ATM withdrawals at the same ATM(s) by multiple cards from the same issuer • Significantly high volumes of repetitive ATM withdrawal amount consistently over time • Excessive ATM withdrawals at maximum Transaction limits of ATM in a short period of time • Out-of-pattern excessive or high volumes of ATM deposits Fraud Loss Control Standards ¶ Addressing BIN Attacks ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 ¶ ATM Authorization Controls and Cash-out Attack Management Each ATM Terminal Acquirer and its Service Providers must, upon detecting a cash-out attack or receiving notification from Mastercard or a Mastercard solution (for example, Safety Net Alert) of a confirmed cash-out attack: • Block acceptance of the BIN under attack at the ATM Terminal within five hours (unless Mastercard notifies the Acquirer that Mastercard has taken action to stop the attack) • If requested by Mastercard, following issuer confirmation of an attack, acquirer is recommended to contact law enforcement for initiating an investigation of the on-going attack, including if possible, the detection and communication of ATM address in real-time (or quasi-real time) to Law Enforcement. • If the ATMs are equipped with a camera, acquirers are recommended to safeguard the video recording for sharing with Law Enforcement where legally allowed. An Acquirer of ATM Transactions must ensure that each Service Provider acting on its behalf has the capability, upon detection of suspected fraud, to adjust (typically reduce) the maximum withdrawal amount per Transaction at individual ATM Terminals to mitigate potential losses. 6.2.2.2 Acquirer Authorization Monitoring Requirements An Acquirer must implement real-time or near-real time alerts to monitor Merchant authorization messages on at least all of the following parameters: • Number of authorization requests above a threshold set by the Acquirer for that Merchant • An authorization approval rate that falls below a threshold set by the Acquirer for that Merchant • Ratio of non-Card-read to Card-read Transactions that is above the threshold set by the Acquirer for that Merchant • PAN key entry ratio that is above the threshold set by the Acquirer for that Merchant • Repeated authorization requests for the same amount or the same Cardholder Account • Ratio of technical fallback above a threshold set by the Acquirer for that Merchant • Merchant authorization reversals that do not match a previous purchase Transaction Fraud Loss Control Standards ATM Authorization Controls and Cash-out Attack Management Security Rules and Procedures—Merchant Edition • 6 August 2024 • Value of Merchant authorization refund that is above the threshold set by the Acquirer for that Merchant • Out-of-pattern Transaction volume and/or velocity at a Merchant, Payment Facilitator, or ATM Terminal, including all of the following: – Repeated authorization requests – High velocity authorizations – Technical fallback of chip to magnetic stripe – High volume of Contactless Transactions – Sequential Account generated attacks – An abnormal increase in authorization requests received – An abnormal increase in the average Transaction amount – BIN attacks, defined as Account testing or highly unusual activity in connection with the use of Cards or Accounts issued under one or more BINs ¶ Fraud Loss Control Standards ¶ ATM Authorization Controls and Cash-out Attack Management ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 – An abnormally high number of authorization request responses indicating invalid PAN, CVC 1 or CVC 2 failure, invalid expiration date, incorrect PIN, Address Verification Service (AVS) mismatch, invalid Authorization Request Cryptogram (ARQC), or invalid Accountholder authentication value (AAV). – Transaction decline rate: – An excessive number of magnetic stripe Transactions occurring or attempted in a short period of time – An excessive number of ATM cash withdrawals occurring or attempted at the maximum cash withdrawal Transaction limit for that ATM in a short period of time Additional Requirements for Negative Option Billing Merchants The Acquirer of a negative option billing Merchant must additionally monitor authorization Transaction messages to identify when the same Account number appears among different negative option billing Merchant IDs in the Acquirer’s Portfolio within 60 calendar days. When the Acquirer identifies such an Account, the Acquirer must take reasonable steps to verify that each Transaction conducted by the valid Cardholder with the associated negative option billing Merchant is a bona fide Transaction. This verification may include, but is not limited to, an electronic copy or hard copy of the Transaction information document (TID). All such verification information must be: • Retained by the Acquirer for a period of at least one year from the verification date; and • Made available to Mastercard upon request. 6.2.2.3 Acquirer Merchant Deposit Monitoring Requirements A deposit is defined as a file of Transactions performed offline or online at a Merchant and submitted to the Merchant's Acquirer for payment. If deposit files are not used, the Acquirer should still monitor the total payment made to each Merchant. Daily reports or real-time alerts monitoring Merchant deposits must be generated at the latest on the day following the deposit, and must be based on the following parameters: • Increases in Merchant deposit volume Fraud Loss Control Standards Additional Requirements for Negative Option Billing Merchants Security Rules and Procedures—Merchant Edition • 6 August 2024 • Increase in a Merchant's average ticket size and number of Transactions for each deposit • Change in frequency of deposits • Change in technical fallback rates, or a technical fallback rate that exceeds two percent of a Merchant's total Transaction volume NOTE: Any report generated by the Acquirer relating to the investigation of a Merchant whose rate of technical fallback exceeds five percent of its total Transaction volume must be made available to Mastercard upon request. • Force-posted Transactions (i.e., a Transaction that has been declined by the Issuer or the chip or any Transaction for which authorization was required but not obtained) • Frequency of Transactions on the same Account, including credit (refund) Transactions • Unusual number of credits, or credit dollar volume, exceeding a level of sales dollar volume appropriate to the Merchant category ¶ Fraud Loss Control Standards ¶ Additional Requirements for Negative Option Billing Merchants ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 • Large credit Transaction amounts, significantly greater than the average ticket size for the Merchant's sales • Credit (refund) Transaction volume that exceeds purchase Transaction volume • Credits issued by a Merchant subsequent to the Acquirer's receipt of a chargeback with the same PAN • Credits issued by a Merchant to a PAN not previously used to effect a Transaction at the Merchant location • Increases in Merchant chargeback volume 90-day Rule: Monitoring of Merchant Daily Volumes The Acquirer must monitor the daily Transaction count and value at each Merchant in view of detecting abnormal or suspicious increase of Merchant activity. To this effect, the daily Transactions count and value will be compared against the average daily Transaction count and amount for a period of at least 90 days, to lessen the effect of normal variances in a Merchant’s business. For a new Merchant, the Acquirer should set monitoring parameters to detect significant deviation from the Merchant's expected turnover as detailed in its business plan. The Acquirer may also compare the Merchant's average Transaction count and amount to those of other Merchants within the same MCC. In the event that suspicious credit or refund Transaction activity is identified, if appropriate, the Acquirer should consider the suspension of Transactions pending further investigation. If the Acquirer determines that an authorized refund Transaction will not be cleared, whether due to suspicious activity or any other reason, the Acquirer must reverse the refund Transaction authorization request. 6.2.2.4 Acquirer Channel Management Requirements Mastercard requires Acquirers to monitor, on a regular basis, each parent Member Customer ID/ICA number, child Member Customer ID/ICA number, and individual Merchant, Payment Facilitator, and Staged Digital Wallet Operator in its Portfolio for the following: Fraud Loss Control Standards 6.2.2.4 Acquirer Channel Management Requirements Security Rules and Procedures—Merchant Edition • 6 August 2024 • Total Transaction fraud basis points • Domestic Transaction fraud basis points • Cross-border Transaction fraud basis points (both Intraregional Transactions and Interregional Transactions) • Fraud basis points at the parent Member Customer ID/ICA level for the following: – Card-present Transactions – POS – Mobile POS (MPOS) – Cardholder-activated Terminal (CAT) (for example, CAT 1, CAT 2, and CAT 3) – Card-not-present (CNP) Transactions – E-commerce, including separate monitoring of non-authenticated, attempted authentication, and fully authenticated Transactions ¶ Fraud Loss Control Standards ¶ 6.2.2.4 Acquirer Channel Management Requirements ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 – Mail order/telephone order (MO/TO) – Recurring payment Transactions 6.2.2.5 3-D Secure Service Provider and Payment Gateway Monitoring Requirements and Recommendations Acquirers must implement fraud detection capabilities at any 3-D Secure Service Provider providing access to a 3-D Secure (3DS) server or Third Party Processor (TPP) performing payment gateway services to monitor all the following: • Fraudulent attempts to connect to a 3DS server or payment gateway as a Merchant or Payment Facilitator (for example, a connection attempt from an unknown IP address or the use of an invalid credential) • 3DS server or payment gateway Denial of Service (DoS) attack • The authentication message flow indicating a PAN or BIN testing attack. This includes but is not limited to detection of (and capability to block) bot attacks using captcha, behavioral analytic tools or other available solutions. Bot attacks are defined as the use of automated web requests to test PANs through a 3DS Server payment gateway or more generally defined as web requests to manipulate, defraud, or disrupt a web site. • Ensure Merchant names used in authentication messages match registered Merchant names • Out-of-pattern number of single or multiple PAN Transactions associated to same customer account identifier or originating source (for example, the same email, telephone number, delivery address, browser fingerprint, or device identification number) An Acquirer is recommended to implement fraud detection capabilities at 3DS Server payment gateways to monitor all the following: • Receipt of confirmed fraud from Acquirers in view of creating a gray or negative listing of related IP and delivery address • Additional monitoring recommendations and best practices as detailed in “Risk-based Authentication” section of the Mastercard Identity Check Program Guide Upon detection of a 3DS Server payment gateway fraud attack by the Acquirer or upon notification from Mastercard of such an attack, the Acquirer must implement the necessary Fraud Loss Control Standards 6.2.2.5 3-D Secure Service Provider and Payment Gateway Monitoring Security Rules and Procedures—Merchant Edition • 6 August 2024 controls at the 3DS Server payment gateway to stop the attack within 72 hours (or within a timeframe approved by Mastercard) of detection or notification by Mastercard. An Acquirer and its 3DS Server payment gateway must also analyze each attack to identify its modus operandi and implement corrective measures to prevent future attacks using the same technique(s). 6.2.2.6 Recommended Additional Acquirer Monitoring Mastercard recommends that Acquirers additionally monitor the following parameters: • Mismatch of Merchant name, MCC, Merchant ID, and/or Terminal ID • Mismatch of e-commerce Merchant Internet Protocol (IP) addresses • Transactions conducted at Merchant, Sponsored Merchants, and other entities registered in the Specialty Merchant Registration Program (refer to Chapter 9) Fraud Loss Control Standards ¶ 6.2.2.5 3-D Secure Service Provider and Payment Gateway Monitoring ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 ¶ • Abnormal hours (i.e., outside of normal business hours) or seasons • Sudden start of activity by an inactive/dormant Merchant (i.e., a Merchant that has not yet started to accept Cards or has ceased to accept Cards) • Inconsistent authorization and clearing data elements for the same Transactions • Mastercard SecureCode/Identity Check authentication rate • Any Merchant exceeding the Acquirer’s total Merchant average for fraud by 150 percent or more Geographic volume variances (i.e., abnormal increase of Merchant activity with some Issuer countries) • Monitor the value, if any, returned in DE 48 subelement 84 (Merchant Advice Code) of authorization request response messages. An Acquirer is recommended to cease resending the same authorization request message when the MAC value is equal to 03 (Do Not Try Again) or 21 (Payment Cancellation). 6.2.2.7 Recommended Fraud Detection Tool Implementation An Acquirer is recommended to implement a fraud detection tool that appropriately complements the fraud strategy deployed by the Acquirer. The combination of the authorization requirements, Merchant deposit monitoring requirements, and fraud detection tool should ensure that an Acquirer controls fraud to an acceptable level. 6.2.2.8 Ongoing Merchant Monitoring An Acquirer must implement procedures for the conduct of periodic ongoing reviews of a Merchant's, Payment Facilitator's, or Staged Digital Wallet Operator's Transaction activity, for the purpose of detecting changes over time, including but not limited to: • Monthly Transaction volume with respect to: – Total Transaction count and amount – Number of credit (refund) Transactions – Number of fraudulent Transactions – Average ticket size – Number of chargebacks and basis points Fraud Loss Control Standards 6.2.2.6 Recommended Additional Acquirer Monitoring Security Rules and Procedures—Merchant Edition • 6 August 2024 • Activity inconsistent with the Merchant’s Merchant's business model • Transaction laundering • Activity that is or may potentially be illegal or brand-damaging As a best practice, Mastercard recommends that Acquirers use a Merchant monitoring solution for e-commerce Merchant activity so as to avoid processing illegal or brand-damaging Transactions. For more information on ongoing Merchant monitoring requirements, refer to section 7.2. Section 7.2 "Ongoing Monitoring" of this manual. Transaction Laundering An Acquirer in the Europe Region, excluding Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan, Kyrgyzstan, Moldova, Tajikistan, Turkey, Turkmenistan, Ukraine, and Uzbekistan, is recommended to perform the following checks on e-commerce Merchants: During onboarding and regular rescreening, as appropriate, the presence of: – Unrealistic promotions (including the use of countdown timers) – Products unrelated to the Merchant's business or MCC – Customer service contact information that is unreachable or is unanswered or that does not include the Merchant name (using generic email addresses or help-desk websites) As part of Transaction monitoring: – Very low authorization approval rate – High number of authorizations that do not include CVC 2 – Low CVC 2 match rate – No 3DS authentication used for adding a Card on file except where mandated pursuant to PSD2 or its successor – Significant authorization volumes in specific Issuer countries that do not match the Merchant's target market based on the Acquirer's understanding of their business model Where such alerts are triggered, the Acquirer should take measures, such as pausing payment to the Merchant and/or temporarily blocking such payment. For conditions relating to this measure, refer to Section 5.4.1 "Payment for Transactions" of the Mastercard Rules. Recurring Payments Merchants An Acquirer in the Europe Region, excluding Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan, Kyrgyzstan, Moldova, Tajikistan, Turkey, Turkmenistan, Ukraine, and Uzbekistan, is recommended to perform the following checks on Merchants performing recurring payment Transactions. These measures are intended to reduce the number of Cardholder complaints relating to deceptive subscription billing practices. During onboarding and regular rescreening, as appropriate: – Verify payment pages to ensure that they correctly display the terms of the recurring payment in according with all Standards, including free or low-cost trials and negative options, where applicable, without using small print As part of Transaction monitoring both in authentication and authorization: Fraud Loss Control Standards 6.2.2.8 Ongoing Merchant Monitoring Security Rules and Procedures—Merchant Edition • 6 August 2024 – Correct and consistent setting of recurring payment flags – Increase in refund rates – Approval rates – Proportion of recurring payments that stop after three months Where such alerts are triggered, the Acquirer should perform/re-perform screening checks, as appropriate, to ensure that they are still compliant with the Standards. For additional information, refer to Section 5.4 "Recurring Payment Transactions" of the Transaction Processing Rules. Additional Monitoring for Sponsored Merchants of Payment Facilitators An Acquirer in the Europe Region, excluding Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan, Kyrgyzstan, Moldova, Tajikistan, Turkey, Turkmenistan, Ukraine, and Uzbekistan, is recommended to ensure that the Payment Facilitator performs the following checks on their e-commerce Sponsored Merchants: Sponsored Merchants having a large number of URLs (where possible, it is recommended for the Acquirer and/or Payment Facilitator to limit the number of different URLs used per Sponsored Merchant). Some web crawlers are able to detect clone websites to achieve this. For more information on ongoing Merchant monitoring requirements, refer to Section 7.2 "Ongoing Monitoring" of this manual. 6.2.2.9 Communicating Fraud and Chargeback Data to Merchants and Payment Facilitators An Acquirer must be able, upon request from its Merchants and Payment Facilitators, to provide them with their fraud and chargeback data on a regular basis and at least monthly. ¶ Fraud Loss Control Standards ¶ 6.2.2.7 Recommended Fraud Detection Tool Implementation ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 6.2.2.10 Fraud and Loss Control Internal Policies, Tracking, and Reporting Tools Acquirers must establish internal policies, tracking and reporting tools covering all the following: • Identification of individual Merchants and Payment Facilitators having a monthly average fraud, chargeback or decline rate exceeding thresholds set by the Acquirer, above which, an investigation of Merchant activities should be conducted to identify and implement any practices that require corrective actions. In all cases, these thresholds should be set to levels that maintain Merchant and payment facilitator compliance with Mastercard programs. • Systematic investigation of any Standard violation by a Merchant, Payment Facilitator, Stage Digital Wallet Operator or ATM owner, either identified by the Acquirer or communicated by Mastercard. Each investigation must be followed by the identification and timely implementation of corrective actions to re-establish compliance with the Standards. An Acquirer is recommended (unless mandated by Mastercard for a specific program) to create an internal report (the “investigation report”) for each of the above events or exceeded thresholds and must include the following minimum information: • Investigation number • Investigation type • Investigation date Fraud Loss Control Standards 6.2.2.9 Communicating Fraud and Chargeback Data to Merchants and Payment Facilitators Security Rules and Procedures—Merchant Edition • 6 August 2024 • Detailed event description and analysis • Description of the corrective actions • Date the corrective action(s) was/were implemented • Name of responsible person 6.2.2.11 Acquirer Recommendation to Report Suspected Fraud An Acquirer is recommended to report Transactions to the Fraud and Loss Database that the Acquirer deems to be fraudulent as suspected fraud Transactions. 6.2.2.12 Acquirer Response to High Impact/Critical Fraud Alerts Raised by Issuers An Acquirer approached by an Issuer with a High Impact/Critical Fraud management request is recommended to collaborate with the Issuer to the best of its ability. Fraud Loss Control Standards 6.2.2.10 6.2.2.11 Acquirer Recommendation to Report Suspected Fraud and Loss Control Internal Policies, Tracking, and Reporting Tools Security Rules and Procedures—Merchant Edition • 6 February August 2024 Chapter 7 Merchant, Sponsored Merchant, and ATM Owner Screening and Monitoring Standards This chapter may be of particular interest to Customer personnel responsible for screening and monitoring Merchants, Sponsored Merchants, and ATM owners.
Halyard Pay · 2 files
program: ATO Detection
- authority: Mastercard SPME §10.6.2.1
+ authority: Mastercard SPME 6.2
risk_threshold_for_3ds_challenge: 0.5
risk_score_range: [0.0, 1.0]
signals:
- geo_anomaly
- device_fingerprint_change
- velocity_breach
- credential_stuffing
challenge_method: 3ds_v2
persistent_risk_escalation_threshold: 3
persistent_risk_lookback_days: 7
agent_owner: ato_agent
 
- # This policy update reflects the expanded requirements in Mastercard SPME §10.6.2.1 for Terminal Servicers in Account Data Compromise (ADC) events,
- # including mandated PCI DSS compliance verification at event time, timely forensic investigations, and enforced containment measures with
- # a 90-day PCI DSS revalidation and a further 12-month PCI DESV appendix compliance period. These detailed steps support risk mitigation
- # aligned with Mastercard’s enhanced responsibility reductions during ADC events, reinforcing rigorous security controls within the ATO detection program.
+ # This policy is updated to reflect the revised Mastercard SPME 6.2 recommendations on BIN attack mitigation.
+ # Notably, Acquirers operating in the Europe Region, excluding specified countries, are recommended to apply additional
+ # temporary countermeasures against BIN attacks. These include sending CVC2 in authorization requests, implementing CAPTCHA,
+ # and blocking merchants as needed until attacks cease. These measures strengthen our ATO detection and prevention capabilities
+ # in alignment with Mastercard's enhanced security guidance focused on attack mitigation timelines and methodologies.

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity. activity, and BIN attack activity as outlined by Mastercard SPME §6.2.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.

  4. Log all ATO signals and outcomes in the case management system.

  5. Escalate persistent high-risk accounts to the ATO response team for manual review.

  6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved revalidates PCI DSS compliance within 90 calendar days after completion of a forensic investigation, demonstrates compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent with the requirements outlined in Mastercard SPME §10.6.2.1.

  7. Require prompt initiation and timely completion of forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event.

  8. Confirm that all identified containment actions from forensic reports have been completed by involved Terminal Servicers.

9. For Acquirers operating in the Europe Region (excluding certain countries specified by Mastercard), implement additional temporary BIN attack mitigation measures until the attack ceases, including requiring CVC2 data in authorization requests, deploying CAPTCHA challenges, and merchant blocking as recommended in Mastercard SPME §6.2.

These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events and BIN attacks through stringent compliance and compliance, timely response protocols. protocols, and strengthened account takeover detection measures.

Source authority: Mastercard SPME §6.2, §10.6.2.1.

policies/ato_detection/policy.md — after applying change

Account-Takeover (ATO) Detection

Account-takeover fraud occurs when a malicious actor gains unauthorized access to a cardholder's account and initiates transactions without the cardholder's consent. Halyard Pay implements real-time risk scoring on authentication events and enforces a mandatory 3DS (3-D Secure) challenge for any session where the computed risk score meets or exceeds the defined threshold.

Detection signals

The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity. activity, and BIN attack activity as outlined by Mastercard SPME §6.2.

Required actions

  1. Evaluate each authentication event against the defined signal list in real time.

  2. Compute a normalized risk score between 0.0 and 1.0.

  3. If the risk score is 0.5 or greater, trigger a mandatory 3DS challenge before authorizing the transaction.

  4. Log all ATO signals and outcomes in the case management system.

  5. Escalate persistent high-risk accounts to the ATO response team for manual review.

  6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved revalidates PCI DSS compliance within 90 calendar days after completion of a forensic investigation, demonstrates compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent with the requirements outlined in Mastercard SPME §10.6.2.1.

  7. Require prompt initiation and timely completion of forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event.

  8. Confirm that all identified containment actions from forensic reports have been completed by involved Terminal Servicers.

9. For Acquirers operating in the Europe Region (excluding certain countries specified by Mastercard), implement additional temporary BIN attack mitigation measures until the attack ceases, including requiring CVC2 data in authorization requests, deploying CAPTCHA challenges, and merchant blocking as recommended in Mastercard SPME §6.2.

These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events and BIN attacks through stringent compliance and compliance, timely response protocols. protocols, and strengthened account takeover detection measures.

Source authority: Mastercard SPME §6.2, §10.6.2.1.

Source authority: Mastercard SPME §6.2.

--- a/policies/ato_detection/rules.yaml
+++ b/policies/ato_detection/rules.yaml
@@ -1,5 +1,5 @@
 program: ATO Detection
-authority: Mastercard SPME §10.6.2.1
+authority: Mastercard SPME 6.2
 risk_threshold_for_3ds_challenge: 0.5
 risk_score_range: [0.0, 1.0]
 signals:
@@ -12,7 +12,8 @@
 persistent_risk_lookback_days: 7
 agent_owner: ato_agent
 
-# This policy update reflects the expanded requirements in Mastercard SPME §10.6.2.1 for Terminal Servicers in Account Data Compromise (ADC) events,
-# including mandated PCI DSS compliance verification at event time, timely forensic investigations, and enforced containment measures with
-# a 90-day PCI DSS revalidation and a further 12-month PCI DESV appendix compliance period. These detailed steps support risk mitigation
-# aligned with Mastercard’s enhanced responsibility reductions during ADC events, reinforcing rigorous security controls within the ATO detection program.
+# This policy is updated to reflect the revised Mastercard SPME 6.2 recommendations on BIN attack mitigation.
+# Notably, Acquirers operating in the Europe Region, excluding specified countries, are recommended to apply additional
+# temporary countermeasures against BIN attacks. These include sending CVC2 in authorization requests, implementing CAPTCHA,
+# and blocking merchants as needed until attacks cease. These measures strengthen our ATO detection and prevention capabilities
+# in alignment with Mastercard's enhanced security guidance focused on attack mitigation timelines and methodologies.
--- a/policies/ato_detection/policy.md
+++ b/policies/ato_detection/policy.md
@@ -4,7 +4,7 @@
 
 ## Detection signals
 
-The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, and indicators of credential-stuffing activity.
+The risk model incorporates multiple behavioral signals: geographic anomalies inconsistent with a cardholder's established pattern, changes to device fingerprint, transaction velocity breaches, indicators of credential-stuffing activity, and BIN attack activity as outlined by Mastercard SPME §6.2.
 
 ## Required actions
 
@@ -14,10 +14,10 @@
 4. Log all ATO signals and outcomes in the case management system.
 5. Escalate persistent high-risk accounts to the ATO response team for manual review.
 6. In the event of an Account Data Compromise (ADC), ensure that any Terminal Servicer (TS) involved revalidates PCI DSS compliance within 90 calendar days after completion of a forensic investigation, demonstrates compliance with the PCI DSS Data Encryption and Software Validation (DESV) appendix within 12 months, and cooperates fully with Mastercard and law enforcement, consistent with the requirements outlined in Mastercard SPME §10.6.2.1.
-
 7. Require prompt initiation and timely completion of forensic investigations by a PCI Forensic Investigator (PFI) within 72 hours of the ADC or Potential ADC Event.
 8. Confirm that all identified containment actions from forensic reports have been completed by involved Terminal Servicers.
+9. For Acquirers operating in the Europe Region (excluding certain countries specified by Mastercard), implement additional temporary BIN attack mitigation measures until the attack ceases, including requiring CVC2 data in authorization requests, deploying CAPTCHA challenges, and merchant blocking as recommended in Mastercard SPME §6.2.
 
-These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events through stringent compliance and timely response protocols.
+These enhanced controls align with Mastercard's comprehensive approach to minimizing the risk and impact of ADC events and BIN attacks through stringent compliance, timely response protocols, and strengthened account takeover detection measures.
 
 Source authority: Mastercard SPME §6.2, §10.6.2.1.