Mastercard SPME §6.2
Security Rules and Procedures—Merchant Edition • 6 February August 2024
Recommendations
An Acquirer is recommended to implement the following with each of its Merchants and
Payment Facilitators:
•
The authentication recommendations listed in Mastercard Identity Check Program Guide
•
Implement MDES for Merchant (M4M) to replace real card Card data by tokenized and digitized
payment credentials (tokensTokens)
•
EMV Chip Terminals with PIN Capability capability (refer to existing mandates in specific countries)
The MCC submitted at the time of authentication should match the MCC submitted at the time
of the authorization except when a single authentication relates to multiple authorizations for
different merchants. Merchants.
Addressing BIN Attacks
BIN attacks either detected by the Acquirer or communicated to the Acquirer by Mastercard,
must be mitigated by the Acquirer, its processor(s) or the concerned Merchant(s) within 72
hours (or within a timeframe time frame approved by Mastercard) of detection by the Acquirer, its Service
Provider, or the Merchant or notification by Mastercard.
By way of example, an attack will be qualified as a BIN attack when the following two
conditions are met:
1.
At least 100 authorization requests or authentication requests are sent within one hour for
the BIN or BIN Account range from one or more Merchants.
2.
The Issuer, its Service Provider, or Mastercard (using a network fraud detection tool)
declined fifty percent (50%) or more of the authorization requests or authentication
requests within one hour.
An Acquirer must also analyze each BIN or BIN Account range attack to identify its modus ¶ operandi method of
operation and implement corrective measures to prevent future attacks using the same
technique(s).
An Acquirer in the Europe Region, excluding Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan,
Kyrgyzstan, Moldova, Tajikistan, Turkey, Turkmenistan, Ukraine, and Uzbekistan, is recommended
to mitigate BIN attacks by employing the following temporary measures until the attack stops:
•
Sending CVC 2 in the Authorization Request/0100 message (refer to Section 3.12.4
"Acquirer Requirements for CVC 2")
•
Applying CAPTCHA
•
Blocking merchants
Where necessary, the Acquirer may need to work with their Merchant Payment Gateway in
order to deploy the above measures.
Suspicious ATM Activity
Each ATM Terminal Acquirer and its Service Providers or other agents acting on its behalf must
have sufficient controls, resources and monitoring systems for the prompt detection and
reporting of suspicious ATM activity as required by Mastercard Rule 1.2.
Fraud Loss Control Standards
Addressing BIN Attacks
Security Rules and Procedures—Merchant Edition • 6 August 2024
ATM Terminal Acquirers are obligated under Mastercard Rule 1.2 to monitor and report
suspicious ATM Transaction activity, regardless if the issuer has or has not reported the activity
as fraud. Suspicious money laundering activity may include, but is not limited to:
•
Out-of-pattern ATM withdrawal volume and/or velocity at an individual ATM or groups of
ATMs
•
Sequential or consecutive high volumes of ATM withdrawals at the same ATM(s) by multiple
cards from the same issuer
•
Significantly high volumes of repetitive ATM withdrawal amount consistently over time
•
Excessive ATM withdrawals at maximum Transaction limits of ATM in a short period of time
•
Out-of-pattern excessive or high volumes of ATM deposits
Fraud Loss Control Standards ¶ Addressing BIN Attacks ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 ¶ ATM Authorization Controls and Cash-out Attack Management
Each ATM Terminal Acquirer and its Service Providers must, upon detecting a cash-out attack or
receiving notification from Mastercard or a Mastercard solution (for example, Safety Net Alert)
of a confirmed cash-out attack:
•
Block acceptance of the BIN under attack at the ATM Terminal within five hours (unless
Mastercard notifies the Acquirer that Mastercard has taken action to stop the attack)
•
If requested by Mastercard, following issuer confirmation of an attack, acquirer is
recommended to contact law enforcement for initiating an investigation of the on-going
attack, including if possible, the detection and communication of ATM address in real-time
(or quasi-real time) to Law Enforcement.
•
If the ATMs are equipped with a camera, acquirers are recommended to safeguard the video
recording for sharing with Law Enforcement where legally allowed.
An Acquirer of ATM Transactions must ensure that each Service Provider acting on its behalf has
the capability, upon detection of suspected fraud, to adjust (typically reduce) the maximum
withdrawal amount per Transaction at individual ATM Terminals to mitigate potential losses.
6.2.2.2 Acquirer Authorization Monitoring Requirements
An Acquirer must implement real-time or near-real time alerts to monitor Merchant
authorization messages on at least all of the following parameters:
•
Number of authorization requests above a threshold set by the Acquirer for that Merchant
•
An authorization approval rate that falls below a threshold set by the Acquirer for that
Merchant
•
Ratio of non-Card-read to Card-read Transactions that is above the threshold set by the
Acquirer for that Merchant
•
PAN key entry ratio that is above the threshold set by the Acquirer for that Merchant
•
Repeated authorization requests for the same amount or the same Cardholder Account
•
Ratio of technical fallback above a threshold set by the Acquirer for that Merchant
•
Merchant authorization reversals that do not match a previous purchase Transaction
Fraud Loss Control Standards
ATM Authorization Controls and Cash-out Attack Management
Security Rules and Procedures—Merchant Edition • 6 August 2024
•
Value of Merchant authorization refund that is above the threshold set by the Acquirer for
that Merchant
•
Out-of-pattern Transaction volume and/or velocity at a Merchant, Payment Facilitator, or
ATM Terminal, including all of the following:
– Repeated authorization requests
– High velocity authorizations
– Technical fallback of chip to magnetic stripe
– High volume of Contactless Transactions
– Sequential Account generated attacks
– An abnormal increase in authorization requests received
– An abnormal increase in the average Transaction amount
– BIN attacks, defined as Account testing or highly unusual activity in connection with the
use of Cards or Accounts issued under one or more BINs ¶ Fraud Loss Control Standards ¶ ATM Authorization Controls and Cash-out Attack Management ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024
– An abnormally high number of authorization request responses indicating invalid PAN,
CVC 1 or CVC 2 failure, invalid expiration date, incorrect PIN, Address Verification Service
(AVS) mismatch, invalid Authorization Request Cryptogram (ARQC), or invalid
Accountholder authentication value (AAV).
– Transaction decline rate:
– An excessive number of magnetic stripe Transactions occurring or attempted in a short
period of time
– An excessive number of ATM cash withdrawals occurring or attempted at the
maximum cash withdrawal Transaction limit for that ATM in a short period of time
Additional Requirements for Negative Option Billing Merchants
The Acquirer of a negative option billing Merchant must additionally monitor authorization
Transaction messages to identify when the same Account number appears among different
negative option billing Merchant IDs in the Acquirer’s Portfolio within 60 calendar days.
When the Acquirer identifies such an Account, the Acquirer must take reasonable steps to verify
that each Transaction conducted by the valid Cardholder with the associated negative option
billing Merchant is a bona fide Transaction. This verification may include, but is not limited to, an
electronic copy or hard copy of the Transaction information document (TID). All such verification
information must be:
•
Retained by the Acquirer for a period of at least one year from the verification date; and
•
Made available to Mastercard upon request.
6.2.2.3 Acquirer Merchant Deposit Monitoring Requirements
A deposit is defined as a file of Transactions performed offline or online at a Merchant and
submitted to the Merchant's Acquirer for payment. If deposit files are not used, the Acquirer
should still monitor the total payment made to each Merchant.
Daily reports or real-time alerts monitoring Merchant deposits must be generated at the latest
on the day following the deposit, and must be based on the following parameters:
•
Increases in Merchant deposit volume
Fraud Loss Control Standards
Additional Requirements for Negative Option Billing Merchants
Security Rules and Procedures—Merchant Edition • 6 August 2024
•
Increase in a Merchant's average ticket size and number of Transactions for each deposit
•
Change in frequency of deposits
•
Change in technical fallback rates, or a technical fallback rate that exceeds two percent of a
Merchant's total Transaction volume
NOTE: Any report generated by the Acquirer relating to the investigation of a Merchant whose rate
of technical fallback exceeds five percent of its total Transaction volume must be made available to
Mastercard upon request.
•
Force-posted Transactions (i.e., a Transaction that has been declined by the Issuer or the chip
or any Transaction for which authorization was required but not obtained)
•
Frequency of Transactions on the same Account, including credit (refund) Transactions
•
Unusual number of credits, or credit dollar volume, exceeding a level of sales dollar volume
appropriate to the Merchant category ¶ Fraud Loss Control Standards ¶ Additional Requirements for Negative Option Billing Merchants ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024
•
Large credit Transaction amounts, significantly greater than the average ticket size for the
Merchant's sales
•
Credit (refund) Transaction volume that exceeds purchase Transaction volume
•
Credits issued by a Merchant subsequent to the Acquirer's receipt of a chargeback with the
same PAN
•
Credits issued by a Merchant to a PAN not previously used to effect a Transaction at the
Merchant location
•
Increases in Merchant chargeback volume
90-day Rule: Monitoring of Merchant Daily Volumes
The Acquirer must monitor the daily Transaction count and value at each Merchant in view of
detecting abnormal or suspicious increase of Merchant activity.
To this effect, the daily Transactions count and value will be compared against the average daily
Transaction count and amount for a period of at least 90 days, to lessen the effect of normal
variances in a Merchant’s business.
For a new Merchant, the Acquirer should set monitoring parameters to detect significant
deviation from the Merchant's expected turnover as detailed in its business plan. The Acquirer
may also compare the Merchant's average Transaction count and amount to those of other
Merchants within the same MCC.
In the event that suspicious credit or refund Transaction activity is identified, if appropriate, the
Acquirer should consider the suspension of Transactions pending further investigation. If the
Acquirer determines that an authorized refund Transaction will not be cleared, whether due to
suspicious activity or any other reason, the Acquirer must reverse the refund Transaction
authorization request.
6.2.2.4 Acquirer Channel Management Requirements
Mastercard requires Acquirers to monitor, on a regular basis, each parent Member Customer ID/ICA
number, child Member Customer ID/ICA number, and individual Merchant, Payment Facilitator, and
Staged ¶ Digital Wallet Operator in its Portfolio for the following:
Fraud Loss Control Standards
6.2.2.4 Acquirer Channel Management Requirements
Security Rules and Procedures—Merchant Edition • 6 August 2024
•
Total Transaction fraud basis points
•
Domestic Transaction fraud basis points
•
Cross-border Transaction fraud basis points (both Intraregional Transactions and
Interregional Transactions)
•
Fraud basis points at the parent Member Customer ID/ICA level for the following:
– Card-present Transactions
– POS
– Mobile POS (MPOS)
– Cardholder-activated Terminal (CAT) (for example, CAT 1, CAT 2, and CAT 3)
– Card-not-present (CNP) Transactions
– E-commerce, including separate monitoring of non-authenticated, attempted
authentication, and fully authenticated Transactions ¶ Fraud Loss Control Standards ¶ 6.2.2.4 Acquirer Channel Management Requirements ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024
– Mail order/telephone order (MO/TO)
– Recurring payment Transactions
6.2.2.5 3-D Secure Service Provider and Payment Gateway Monitoring
Requirements and Recommendations
Acquirers must implement fraud detection capabilities at any 3-D Secure Service Provider
providing access to a 3-D Secure (3DS) server or Third Party Processor (TPP) performing
payment gateway services to monitor all the following:
•
Fraudulent attempts to connect to a 3DS server or payment gateway as a Merchant or
Payment Facilitator (for example, a connection attempt from an unknown IP address or the
use of an invalid credential)
•
3DS server or payment gateway Denial of Service (DoS) attack
•
The authentication message flow indicating a PAN or BIN testing attack. This includes but is
not limited to detection of (and capability to block) bot attacks using captcha, behavioral
analytic tools or other available solutions. Bot attacks are defined as the use of automated
web requests to test PANs through a 3DS Server payment gateway or more generally
defined as web requests to manipulate, defraud, or disrupt a web site.
•
Ensure Merchant names used in authentication messages match registered Merchant names
•
Out-of-pattern number of single or multiple PAN Transactions associated to same customer
account identifier or originating source (for example, the same email, telephone number,
delivery address, browser fingerprint, or device identification number)
An Acquirer is recommended to implement fraud detection capabilities at 3DS Server payment
gateways to monitor all the following:
•
Receipt of confirmed fraud from Acquirers in view of creating a gray or negative listing of
related IP and delivery address
•
Additional monitoring recommendations and best practices as detailed in “Risk-based
Authentication” section of the Mastercard Identity Check Program Guide
Upon detection of a 3DS Server payment gateway fraud attack by the Acquirer or upon
notification from Mastercard of such an attack, the Acquirer must implement the necessary
Fraud Loss Control Standards
6.2.2.5 3-D Secure Service Provider and Payment Gateway Monitoring
Security Rules and Procedures—Merchant Edition • 6 August 2024
controls at the 3DS Server payment gateway to stop the attack within 72 hours (or within a
timeframe approved by Mastercard) of detection or notification by Mastercard.
An Acquirer and its 3DS Server payment gateway must also analyze each attack to identify its
modus operandi and implement corrective measures to prevent future attacks using the same
technique(s).
6.2.2.6 Recommended Additional Acquirer Monitoring
Mastercard recommends that Acquirers additionally monitor the following parameters:
•
Mismatch of Merchant name, MCC, Merchant ID, and/or Terminal ID
•
Mismatch of e-commerce Merchant Internet Protocol (IP) addresses
•
Transactions conducted at Merchant, Sponsored Merchants, and other entities registered in
the Specialty Merchant Registration Program (refer to Chapter 9)
Fraud Loss Control Standards ¶ 6.2.2.5 3-D Secure Service Provider and Payment Gateway Monitoring ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024 ¶ •
Abnormal hours (i.e., outside of normal business hours) or seasons
•
Sudden start of activity by an inactive/dormant Merchant (i.e., a Merchant that has not yet
started to accept Cards or has ceased to accept Cards)
•
Inconsistent authorization and clearing data elements for the same Transactions
•
Mastercard SecureCode/Identity Check authentication rate
•
Any Merchant exceeding the Acquirer’s total Merchant average for fraud by 150 percent or
more
Geographic volume variances (i.e., abnormal increase of Merchant activity with some Issuer
countries)
•
Monitor the value, if any, returned in DE 48 subelement 84 (Merchant Advice Code) of
authorization request response messages. An Acquirer is recommended to cease resending
the same authorization request message when the MAC value is equal to 03 (Do Not Try
Again) or 21 (Payment Cancellation).
6.2.2.7 Recommended Fraud Detection Tool Implementation
An Acquirer is recommended to implement a fraud detection tool that appropriately
complements the fraud strategy deployed by the Acquirer. The combination of the authorization
requirements, Merchant deposit monitoring requirements, and fraud detection tool should
ensure that an Acquirer controls fraud to an acceptable level.
6.2.2.8 Ongoing Merchant Monitoring
An Acquirer must implement procedures for the conduct of periodic ongoing reviews of a
Merchant's, Payment Facilitator's, or Staged Digital Wallet Operator's Transaction activity, for
the purpose of detecting changes over time, including but not limited to:
•
Monthly Transaction volume with respect to:
– Total Transaction count and amount
– Number of credit (refund) Transactions
– Number of fraudulent Transactions
– Average ticket size
– Number of chargebacks and basis points
Fraud Loss Control Standards
6.2.2.6 Recommended Additional Acquirer Monitoring
Security Rules and Procedures—Merchant Edition • 6 August 2024
•
Activity inconsistent with the Merchant’s Merchant's business model
•
Transaction laundering
•
Activity that is or may potentially be illegal or brand-damaging
As a best practice, Mastercard recommends that Acquirers use a Merchant monitoring solution
for e-commerce Merchant activity so as to avoid processing illegal or brand-damaging
Transactions.
For more information on ongoing Merchant monitoring requirements, refer to section 7.2. Section 7.2
"Ongoing Monitoring" of this manual.
Transaction Laundering
An Acquirer in the Europe Region, excluding Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan,
Kyrgyzstan, Moldova, Tajikistan, Turkey, Turkmenistan, Ukraine, and Uzbekistan, is recommended
to perform the following checks on e-commerce Merchants:
•
During onboarding and regular rescreening, as appropriate, the presence of:
– Unrealistic promotions (including the use of countdown timers)
– Products unrelated to the Merchant's business or MCC
– Customer service contact information that is unreachable or is unanswered or that does
not include the Merchant name (using generic email addresses or help-desk websites)
•
As part of Transaction monitoring:
– Very low authorization approval rate
– High number of authorizations that do not include CVC 2
– Low CVC 2 match rate
– No 3DS authentication used for adding a Card on file except where mandated pursuant
to PSD2 or its successor
– Significant authorization volumes in specific Issuer countries that do not match the
Merchant's target market based on the Acquirer's understanding of their business model
Where such alerts are triggered, the Acquirer should take measures, such as pausing payment to
the Merchant and/or temporarily blocking such payment. For conditions relating to this
measure, refer to Section 5.4.1 "Payment for Transactions" of the Mastercard Rules.
Recurring Payments Merchants
An Acquirer in the Europe Region, excluding Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan,
Kyrgyzstan, Moldova, Tajikistan, Turkey, Turkmenistan, Ukraine, and Uzbekistan, is recommended
to perform the following checks on Merchants performing recurring payment Transactions.
These measures are intended to reduce the number of Cardholder complaints relating to
deceptive subscription billing practices.
•
During onboarding and regular rescreening, as appropriate:
– Verify payment pages to ensure that they correctly display the terms of the recurring
payment in according with all Standards, including free or low-cost trials and negative
options, where applicable, without using small print
•
As part of Transaction monitoring both in authentication and authorization:
Fraud Loss Control Standards
6.2.2.8 Ongoing Merchant Monitoring
Security Rules and Procedures—Merchant Edition • 6 August 2024
– Correct and consistent setting of recurring payment flags
– Increase in refund rates
– Approval rates
– Proportion of recurring payments that stop after three months
Where such alerts are triggered, the Acquirer should perform/re-perform screening checks,
as appropriate, to ensure that they are still compliant with the Standards.
For additional information, refer to Section 5.4 "Recurring Payment Transactions" of the
Transaction Processing Rules.
Additional Monitoring for Sponsored Merchants of Payment Facilitators
An Acquirer in the Europe Region, excluding Armenia, Azerbaijan, Belarus, Georgia, Kazakhstan,
Kyrgyzstan, Moldova, Tajikistan, Turkey, Turkmenistan, Ukraine, and Uzbekistan, is recommended
to ensure that the Payment Facilitator performs the following checks on their e-commerce
Sponsored Merchants:
•
Sponsored Merchants having a large number of URLs (where possible, it is recommended for
the Acquirer and/or Payment Facilitator to limit the number of different URLs used per
Sponsored Merchant). Some web crawlers are able to detect clone websites to achieve this.
For more information on ongoing Merchant monitoring requirements, refer to Section 7.2
"Ongoing Monitoring" of this manual.
6.2.2.9 Communicating Fraud and Chargeback Data to Merchants and Payment Facilitators
An Acquirer must be able, upon request from its Merchants and Payment Facilitators, to provide
them with their fraud and chargeback data on a regular basis and at least monthly. ¶ Fraud Loss Control Standards ¶ 6.2.2.7 Recommended Fraud Detection Tool Implementation ¶ Security Rules and Procedures—Merchant Edition • 6 February 2024
6.2.2.10 Fraud and Loss Control Internal Policies, Tracking, and Reporting Tools
Acquirers must establish internal policies, tracking and reporting tools covering all the following:
•
Identification of individual Merchants and Payment Facilitators having a monthly average
fraud, chargeback or decline rate exceeding thresholds set by the Acquirer, above which, an
investigation of Merchant activities should be conducted to identify and implement any
practices that require corrective actions. In all cases, these thresholds should be set to levels
that maintain Merchant and payment facilitator compliance with Mastercard programs.
•
Systematic investigation of any Standard violation by a Merchant, Payment Facilitator,
Stage Digital Wallet Operator or ATM owner, either identified by the Acquirer or
communicated by Mastercard. Each investigation must be followed by the identification and
timely implementation of corrective actions to re-establish compliance with the Standards.
An Acquirer is recommended (unless mandated by Mastercard for a specific program) to create
an internal report (the “investigation report”) for each of the above events or exceeded
thresholds and must include the following minimum information:
•
Investigation number
•
Investigation type
•
Investigation date
Fraud Loss Control Standards
6.2.2.9 Communicating Fraud and Chargeback Data to Merchants and Payment Facilitators
Security Rules and Procedures—Merchant Edition • 6 August 2024
•
Detailed event description and analysis
•
Description of the corrective actions
•
Date the corrective action(s) was/were implemented
•
Name of responsible person
6.2.2.11 Acquirer Recommendation to Report Suspected Fraud
An Acquirer is recommended to report Transactions to the Fraud and Loss Database that the
Acquirer deems to be fraudulent as suspected fraud Transactions.
6.2.2.12 Acquirer Response to High Impact/Critical Fraud Alerts Raised by Issuers
An Acquirer approached by an Issuer with a High Impact/Critical Fraud management request is
recommended to collaborate with the Issuer to the best of its ability.
Fraud Loss Control Standards
6.2.2.10 6.2.2.11 Acquirer Recommendation to Report Suspected Fraud and Loss Control Internal Policies, Tracking, and Reporting Tools
Security Rules and Procedures—Merchant Edition • 6 February August 2024
Chapter 7 Merchant, Sponsored Merchant, and ATM
Owner Screening and Monitoring Standards
This chapter may be of particular interest to Customer personnel responsible for screening and
monitoring Merchants, Sponsored Merchants, and ATM owners.