Visa Releases Fall 2024 Biannual Threats Report
Visa has released its Fall 2024 Biannual Threats Report which provides an overview of the top threats to the payments ecosystem as identified by its payment fraud disruption team (Visa PFD). The report covers the six-month period January – June 2024.
Visa notes that threat actors are becoming more organized and sophisticated, using advanced tactics and cutting-edge technology to facilitate large-scale fraud operations. During the six-month period that is the focus of the study, Visa observed that threat actors were targeting system misconfigurations/vulnerabilities and cardholders, in particular.
During the January – June 2024 period, there was an increase in Purchase Return Authorization Attacks (PRA), with Visa PFD opening a record number of PRA investigations, 81% more than during the prior six-month period. Enumeration attacks continued to be a major threat, with the US being the most highly targeted region. Compared with the prior six-month period, ransomware and data breach attacks were down, and while the number of compromised websites was relatively consistent, skimming attacks remained an ongoing threat.
Visa observed that threat actors are increasingly turning their focus to cardholders and are using advanced social engineering techniques to facilitate scams. Visa PFD identified new scam tactics targeting retailers’ digital wallet programs, complex impersonation scams, and continued targeting of authentication data, such as onetime passcodes.
To read the full report:
Payment Enumeration Attacks Explained
Enumeration attacks are a type of cyberattack used to discover data in a system or application. For example, a malicious actor may use an API to submit numerous “guesses” against user login information, eventually guessing correctly and storing that information.
These types of attacks are also one of the top threats to the payments ecosystem, harming payment card issuers, merchants, and consumers. According to Visa, enumeration attacks inflict operational expenses and $1.1B annually in fraud losses, accounting for a significant portion of global fraud.
Here is an overview of how payment enumeration attacks work, why they are harmful to merchants, and the signs that merchants can watch for indicating they may be the victim of an enumeration attack.
What is a payment enumeration attack?
A payment enumeration attack, a type of brute force attack, occurs when a criminal uses software or bots to validate payment card information by submitting a series of transaction attempts. By iterating through combinations of credentials (e.g., primary account number, expiration date, zip code, etc.) the criminal seeks to derive legitimate payment account details. When a transaction goes through, it indicates the combination of credentials is valid. Criminals then sell this information or use it themselves to initiate fraudulent transactions.
A BIN attack is a type of enumeration attack that focuses on a specific payment card issuer. The criminal takes the first six to eight digits of a card number – the Bank Identification Number, or BIN − and uses software to generate the remaining card numbers and other credentials (e.g., expiration dates, CVVs, etc.) for testing.
What types of businesses are targeted?
Merchants across a variety of industries have been victims of enumeration attacks. Businesses that process a high volume of card-not-present transactions are most susceptible to these attacks. Smaller businesses with less robust fraud protections are also targeted.
How do enumeration attacks harm merchants?
Enumeration attacks harm merchants in a number of ways including:
- Increased processing fees: Every attempted transaction incurs fees. When hundreds or thousands of card numbers are tested, fees can add up quickly.
- Increased chargebacks: Consumers whose cards were charged as a result of the attack will likely file chargeback claims, which incur fees for the merchant.
- Operational expenses: Additional expense may be incurred to manage the repercussions of the attack.
- Risk exposure: There may be exposure to compliance risk, regulatory risk, and reputational risk.
How can a merchant determine if it is the victim of an enumeration attack?
The following patterns can indicate an enumeration attack is underway:
- Abnormally high number of low-value transactions
- Frequent card declines in a brief period
- Spikes in transactions that are otherwise not explainable
- Odd transaction times (e.g., your customers normally conduct business during the day but suddenly numerous transactions are placed at 3 AM)
Can enumeration attacks be prevented?
Yes, there are steps a merchant can take to guard against and thwart enumeration attacks. The precise methods you should employ to protect your business will vary based on numerous factors, but can include: altering transaction error messaging, transaction throttling, and advanced fraud detection systems.
In the coming weeks, we will be publishing a separate article going into more detail on these preventative measures.
In the meantime, if you are concerned about enumeration attacks and would like to discuss further, please contact Verisave and we will be happy to help.
Litigation over Illinois Interchange Fee Prohibition Act Escalates
In June 2024, the Illinois Interchange Fee Prohibition Act (IFPA) was signed into law. It prohibits the collection of interchange fees on sales taxes, excise taxes, and tips if a merchant separates those charges from the price of a purchase. The act also prohibits banks and other entities from using transaction data for purposes other than processing a transaction, except as required by law.
In August, the American Bankers Association (ABA), America’s Credit Unions, the Illinois Banker Association, and the Illinois Credit Union League filed a suit seeking an injunction, arguing that the law will disrupt the payment system, and that it interferes with the federal government’s regulatory authority over federally chartered financial institutions.
In October, both the Office of the Comptroller of the Currency (OCC) and the Illinois Attorney General filed briefs with the court.
The OCC’s amicus brief in support of the banking associations argues that the IFPA’s restrictions on interchange fees and data usage significantly interfere with national banks’ federally authorized powers under the National Bank Act. It also asserts that state-level restrictions, such as the IFPA, could fragment the nationwide payments system, undermining its ability to function effectively. Furthermore, the brief says the act would impose substantial operational burdens on national banks that will likely be passed on to consumers in the form of higher fees, reduced services, and weakened fraud protection.
Shortly after the OCC filed its brief, the Illinois Attorney General filed a combined memorandum opposing the banking association’s motion for a preliminary injunction and supporting his motion to dismiss. Specifically, the Attorney General argues that the IFPA is not preempted by any federal statute and that the plaintiffs have failed to establish the necessary elements for preliminary injunctive relief. The Attorney General also contends that the plaintiffs have not shown that their members will suffer irreparable harm.
For more information on the litigation:
Senate Committee Holds Hearing on Credit Card Fees
Senator Dick Durbin (D-IL) is apparently making an effort to revive the stalled Credit Card Competition Act (CCCA) which has been languishing since he introduced the bill two years ago with co-sponsor Senator Roger Marshall (R-KS).
On November 19th, the Senate Judiciary Committee held a hearing “Breaking the Visa-Mastercard Duopoly: Bringing Competition and Lower Fees to the Credit Card System”, which was announced by Durbin only a week earlier. The move was perceived as an attempt to raise the profile of the bill before he loses his position as chairman of the Judiciary Committee when the GOP takes control of the Senate in January 2025.
Several key individuals testified: the senior advisor to the CEO of Visa, Mastercard’s President of the Americas, a Notre Dame Law Professor, the owner of a small bookstore, and the general counsel for the National Association of Convenience Stores. Notably, the hearing did not include any banking or credit union representatives − groups that assert they will be hurt by the bill.
A number of Judiciary Committee members expressed concerns about credit card fees, but the bill is not expected to pass this year.
The CCCA seeks to drive down merchant fees by increasing competition among US credit card networks, weakening Visa’s and Mastercard’s market dominance. It directs the Federal Reserve to issue regulations covering issuing banks with over $100 billion in assets. Under the proposed regulations, these banks will not be allowed to restrict the number of networks, on which an electronic credit transaction may be processed, to fewer than two unaffiliated networks (at least one of which cannot be one of the two largest networks). Merchants will have the right to choose the network through which their payments are processed.
For more information on card network rules:




