Skip to main content

BankingCard fraud9 of 28

BIN attacks

Generating card numbers from a known issuer prefix (BIN) and guessing expiry dates and security codes until authorizations succeed.

Unusual concentrationEVENTS BY TIME AND LOCATION
Illustrative patternAuthorization attempts bunch tightly on one BIN range over a short period while other ranges stay at normal volume.

How it works

The bank identification number (BIN) is the opening digits of a card number and identifies the issuer and card product. Because the remaining digits follow a predictable structure, including a check digit, attackers can generate large ranges of valid-looking numbers under one BIN and submit them for authorization with guessed expiry dates and security codes.

Attacks are scripted and run through merchants or payment pages that do not limit retries, sometimes spread across many merchants so that no single one sees a large volume. The issuer, by contrast, sees a concentrated wave of authorization requests for sequential or closely spaced card numbers in one BIN range, many of them for numbers that were never issued or with mismatched details.

Successful guesses are used for card-not-present fraud or sold. Because the cardholder never exposed their details, there is no prior compromise to trace, which makes BIN attacks hard to link to a point of compromise and easy to mistake for unrelated fraud.

Red flags

  • A sudden rise in authorization requests on one BIN range, many for card numbers that are not issued or not active
  • Sequential or closely spaced card numbers attempted in a short window
  • A high rate of declines for invalid card number, expiry date or security code across the range
  • Approved attempts that share a merchant, amount or IP pattern with the failed ones
  • Card-not-present fraud on cards with no history of online use and no known compromise

Signals the engine evaluates

  • Authorization requests per BIN range per minute, against the range's normal volume
  • Share of requests for unissued, closed or inactive card numbers
  • Proximity of attempted card numbers within the range, flagging sequential enumeration
  • Mix of decline reasons, and the merchants and channels the attempts arrive from

Investigation and response

  1. 01Apply temporary restrictions on the affected BIN range, such as tighter card-not-present controls, while the attack is active.
  2. 02Identify cards approved during the attack window and block, reissue or closely monitor them.
  3. 03Share the attacking merchants, amounts and timing with the card scheme and acquirers so the entry points can be closed.
  4. 04Record the event as one case so that later fraud on cards in the range is linked back to the attack.
Get started

Catch bin attacks before the loss

See how FinCrimes scores this pattern against your own historical data in a backtest, before anything goes live.

Browse the library