What To Do If Compromised - Visa Supplemental Requirements
What To Do If Compromised Visa Supplemental Requirements
Version 10.0
Effective: 25 June 2026
Important Note on Copyright
This document is protected by copyright restricting its use, copying, distribution, and decompilation. No part of this document may be reproduced in any form by any means without prior written authorization of Visa.
Visa and other trademarks are trademarks or registered trademarks of Visa.
All other product names mentioned herein are the trademarks of their respective owners.
About Visa Supplemental Requirements
This document is a supplement of the Visa Core Rules and Visa Product and Service Rules. In the event of any conflict between any content in this document, any document referenced herein, any exhibit to this document, or any communications concerning this document, and any content in the Visa Core Rules and Visa Product and Service Rules, the Visa Core Rules and Visa Product and Service Rules shall govern and control.
Summary
Visa is dedicated to promoting the safe and sound long-term prosperity of the Visa payment ecosystem. To that end, Visa aims to ensure the timely resolution of external data compromise events, drive notification of at-risk accounts to stem fraud impacts, and synthesize forensic evidence, intelligence, and fraud analysis to formulate remediation plans that strengthen payment system security.
Protecting the payment ecosystem is a shared responsibility. Any entity that stores, processes, or transmits payment card data or has access to those systems or data, is required to adhere to and maintain compliance with all Payment Card Industry Data Security Standard (PCI DSS) requirements and (PCI) – PIN Security Requirements.
Visa’s What to Do if Compromised (WTDIC) document is a requirements-based guide that applies to entities that suspect or have experienced an event that leverages, impacts, or compromises their payment systems, or payment systems they service or support. This document reflects the risks of current and future threats to the payment ecosystem and is designed to provide guidance on each parties' obligations throughout a suspected or confirmed payment environment incident (“Compromise Event”).
WTDIC establishes procedures and timelines for reporting and responding to a Compromise Event. To mitigate payment system risk during a Compromise Event, prompt action is required to prevent additional exposure, including ensuring containment actions and remediation such as the existence and proper functioning of PCI DSS and PCI PIN Security controls.
Section A: Requirements for Entities that Suspect or Have Confirmed a Compromise Event
Any entity that suspects or confirms unauthorized access to and/or misuse of any Visa cardholder data, including any entity that stores, processes, or transmits cardholder data or has access to a payments environment or systems, is required to adhere to the WTDIC requirements.
This includes, but is not limited to Merchants, Processors, Gateways, Agents, Service Providers, Third-Party Vendors, Integrator Resellers, FinTechs, Blockchain / Crypto or Digital Currency participants, and any other entities operating or accessing a payments environment.
Entities are required to report compromise events that involve payment systems or data. Visa requires an incident report for any suspected or confirmed Compromise Event that involves the potential or actual unauthorized access to payment system or data of any Visa payment ecosystem participant.
1. Submit Notification to Visa Within Three (3) Calendar Days
1.1 An entity that suspects or confirms unauthorized access to any Visa payment account data, or to any payment system that stores, processes, or transmits Visa payment account data, is required to ensure that the Compromise Event is reported to Visa’s Global Risk Investigations group within three (3) calendar days of either:
a. The discovery of evidence sufficient to raise a reasonable suspicion of a Compromise Event,
b. The discovery of evidence sufficient to confirm the existence of a Compromise Event.
Visa Members are responsible for ensuring compliance with this requirement by their affiliates, agents, and customers.
1.2 Visa Acquirers and Third-Party Processors with access to Visa’s Global Investigation Management Tool (GIMT) must provide notice via GIMT.
1.3 All other notifications must be provided to the appropriate regional Visa Global Risk Investigations group listed in Table 1.1.
Regional Contact Information - Table 1.1
| Region | Contact Email |
|---|---|
| Asia Pacific(AP) | APFraud@visa.com |
| Central and Eastern Europe, Middle East and Africa(CEMEA) | CEMEAFraudControl@Visa.com |
| Latin America&Caribbean(LAC) | LACFraudInvestigations@visa.com |
| North America(NA) | USFraudControl@visa.com |
| Europe(EU) | DataCompromise@visa.com |
| Risk Operations Center 24/7 Emergency Assistance | Toll-Free: 1-844-847-2106 International 1-650-432-3379 ROC@Visa.com |
2 Perform Initial Investigation and Provide Incident Report
2.1 Within three (3) calendar days of notifying Visa in accordance with Section A-1 (above), provide a report describing the event (the “Incident Report”) to Visa and the Acquiring bank (if applicable). Please refer to Attachment A at the end of the document for an editable copy of the Incident Report. Entities should also provide supporting Payment Card Industry Data Security Standards (PCI DSS) compliance documentation when available or requested.
2.2 The information provided in the Incident Report aids Visa in understanding the compromised entity's network environment, potential scope of the incident, potential payment card data at risk, estimated financial exposure where known, and containment status of the Compromise Event.
2.3 Visa Acquirers and Third-Party Processors with access to Visa’s Global Investigation Management Tool (GIMT) must provide notice and relevant or requested documentation via GIMT.
All other Incident Reports must be provided to the appropriate regional Visa Global Risk Investigations group listed in Section A, Table 1.1.
3 Provide Notice to Other Relevant Parties
3.1 Immediately notify all relevant parties, including but not limited to the Issuing/Acquiring Bank (if applicable).
3.2 If the name and/or contact information for your Acquiring Bank is unknown, contact the appropriate regional Visa Global Risk Investigations group listed in Section A, Table 1.1.
3.3 It is strongly recommended that you also immediately notify:
3.3.1 Your internal incident response team and information security group.
3.3.2 Your PIN Entry Device (PED) manufacturer, your Point-of-Sale (POS) manufacturer or POS reseller/integrator, or shopping cart manufacturer if it is determined the incident involves a vulnerability in your payment processing system.
3.3.3 Your legal department, particularly if applicable law mandates customer notification.
3.3.4 The appropriate local or national law enforcement agencies.
The United States Secret Service Electronic Crimes Task Forces (ECTF) if the Compromise Event is in the United States. The ECTF focuses on investigating financial crimes and can assist with incident response and mitigation of a Compromise Event.
Visit www.secretservice.gov/investigation/ for ECTF field office contact information.
4 Provide At-Risk Payment Account Data to Visa
4.1 Entities are required to ensure that all compromised Visa account numbers (known or suspected) are provided to Visa’s Global Risk Investigations group via Visa’s Global Investigation Management Tool (GIMT) or Compromised Account Management System (CAMS) within three (3) calendar days of any of the following scenarios:
a. Discovery of compromised account data.
b. The date Visa requests at-risk account numbers; or
c. A Window of Exposure (WOE) is determined.
4.1.1. Entities must work with their Acquirer of Record or Third-Party Processor to upload accounts to GIMT or CAMS, if applicable.
4.1.2. For more information or assistance, contact the appropriate regional Visa Global Risk Investigations group listed in Section A, Table 1.1.
5 Conduct PCI Forensic Investigation (PFI)
5.1 Visa may, at its discretion, require a potentially compromised entity to engage a Payment Card Industry (PCI) Forensic Investigator (PFI) to perform an investigation.
5.1.1. Within five (5) business days, execute a contract retaining a PFI to perform a PCI forensic investigation and inform Visa of the PFI company and lead investigator.
5.1.2. Provide thorough logistical and technical support to the PFI to facilitate timely completion of the investigation, including, but not limited to, providing access to system logs, images, and requested documentation.
5.1.3. Within five (5) business days from when the entity has retained a PFI and signed a contract, provide Visa with the initial forensic (i.e., preliminary) report.
5.1.4. Within ten (10) business days of completion of the PFI investigation, provide Visa and its affected Acquirers with a final forensic report.
5.2 Visa will review, but not recognize forensic reports from a non-approved PFI company when a PFI investigation is required.
Section B: Requirements for Visa Members
The Visa Core Rules and Product and Service Rules (Visa Rules available on Visa Access) and this What To Do If Compromised document requires all Visa Members (e.g., Issuers, Acquirers) to conduct a thorough investigation of suspected or confirmed loss, theft, or compromise of Visa account or cardholder information.
1 Submit Notification to Visa
1.1 Within three (3) calendar days, report to the Visa Global Risk Investigations group any suspected or confirmed unauthorized access to any Visa cardholder data or systems.
1.2 All other notifications must be provided to the appropriate regional Visa Global Risk Investigations group.
2 Perform Initial Investigation and Provide Incident Report
2.1 Within three (3) calendar days of notification of a suspected or confirmed Compromise Event, provide the Incident Report to Visa. Please refer to Attachment A for an editable copy of the Incident Report.
Attachment A: Incident Report
| Visa Incident Report Page 1 | ||||
|---|---|---|---|---|
| Legal Entity Name: | ||||
| DBA Entity Name: | ||||
| Type of Entity: | ||||
| List any direct processing relationships with Visa: | ||||
| Services, Solutions, or Product Provided by Entity: | ||||
| Entity Address: | City: | State/Province: | Postal/Zip code: | Country: |
| Primary Contact Name: | Phone: | Email: | ||
| Detailed Description of the Incident: | ||||
| List Window(s) of Intrusion and/or Exposure: | ||||
| List Data Elements At Risk: | ||||
| Detail all actions taken to investigate: | ||||
| Have you enlisted the expertise of a third-party in this matter? Yes/No | ||||
| What type of remote access solution is used? | ||||
| Is two-factor authentication in use for remote access? Yes/No | ||||
| Has the entity received complaints regarding fraudulent transactions from their customers? Yes/No |
| Visa Incident Report Page 2 | ||||
|---|---|---|---|---|
| Has the entity been contacted by law enforcement? Yes/No | ||||
| Has the entity contacted law enforcement regarding the incident? Yes/No | ||||
| Has the Compromise Event been contained? Yes/No | ||||
| If Merchant Please Include Details Below: | ||||
| Merchant ID: | MCC: | PCI DSS Level: | Annual Transactions Volume: | Corporate or Franchisee: |
| PCI Compliant Yes/No | ||||
| Acquiring Identifier, Issuing Identifier, or VSS Processor: | ||||
| List processor(s): | ||||
| Is the Point of Sale (POS) device EMV enabled? Yes/No | ||||
| Is the POS solution enabled with end to end encryption? Yes/No | ||||
| Is the ecommerce website hosted? Yes/No | ||||
| Identify responsible party(s) for the configuration and support of the Point of Sale (POS) solution: | NAME | TITLE | ||
| Report Completed By: | ||||
| Name | Title | Role | ||
| Phone | Date Completed |
Attachment B: Incident Report (Fraud Schemes)
| Visa Fraud Schemes Incident Report Page 1 | ||||
|---|---|---|---|---|
| Legal Entity Name: | ||||
| DBA Entity Name: | ||||
| Type of Entity: | ||||
| Services, Solutions, or Products Provided by Entity: | ||||
| Duration of Fraud Scheme: | ||||
| Number of Visa Accounts Impacted: |
| Visa Fraud Schemes Incident Report Page 2 | ||||
|---|---|---|---|---|
| What data was impacted? | ||||
| Report Completed By: | ||||
| Company Name | ||||
| Name | Title | Role | ||
| Phone | Date Completed |