What To Do If Compromised - Visa Supplemental Requirements

What To Do If Compromised Visa Supplemental Requirements

Version 10.0

Effective: 25 June 2026

Visa Public


Important Note on Copyright

This document is protected by copyright restricting its use, copying, distribution, and decompilation. No part of this document may be reproduced in any form by any means without prior written authorization of Visa.

Visa and other trademarks are trademarks or registered trademarks of Visa.

All other product names mentioned herein are the trademarks of their respective owners.

About Visa Supplemental Requirements

This document is a supplement of the Visa Core Rules and Visa Product and Service Rules. In the event of any conflict between any content in this document, any document referenced herein, any exhibit to this document, or any communications concerning this document, and any content in the Visa Core Rules and Visa Product and Service Rules, the Visa Core Rules and Visa Product and Service Rules shall govern and control.


Contents


Summary

Visa is dedicated to promoting the safe and sound long-term prosperity of the Visa payment ecosystem. To that end, Visa aims to ensure the timely resolution of external data compromise events, drive notification of at-risk accounts to stem fraud impacts, and synthesize forensic evidence, intelligence, and fraud analysis to formulate remediation plans that strengthen payment system security.

Protecting the payment ecosystem is a shared responsibility. Any entity that stores, processes, or transmits payment card data or has access to those systems or data is required to adhere to and maintain compliance with all Payment Card Industry Data Security Standard (PCI DSS) requirements and (PCI) – PIN Security Requirements.

Visa’s What to Do if Compromised (WTDIC) document is a requirements-based guide that applies to entities that suspect or have experienced an event that leverages, impacts, or compromises their payment systems, or payment systems they service or support. This document reflects the risks of current and future threats to the payment ecosystem and is designed to provide guidance on each parties' obligations throughout a suspected or confirmed payment environment incident (“Compromise Event”).

WTDIC establishes procedures and timelines for reporting and responding to a Compromise Event. To mitigate payment system risk during a Compromise Event, prompt action is required to prevent additional exposure, including ensuring containment actions and remediation such as the existence and proper functioning of PCI DSS and PCI PIN Security controls.


Section A: Requirements for Entities that Suspect or Have Confirmed a Compromise Event

Any entity that suspects or confirms unauthorized access to and/or misuse of any Visa cardholder data, including any entity that stores, processes, or transmits cardholder data or has access to a payments environment or systems, is required to adhere to the WTDIC requirements.

This includes, but is not limited to Merchants, Processors, Gateways, Agents, Service Providers, Third-Party Vendors, Integrator Resellers, FinTechs, Blockchain / Crypto or Digital Currency participants, and any other entities operating or accessing a payments environment.

Entities are required to report compromise events that involve payment systems or data. Visa requires an incident report for any suspected or confirmed Compromise Event that involves the potential or actual unauthorized access to payment system or data of any Visa payment ecosystem participant.

1. Submit Notification to Visa Within Three (3) Calendar Days

1.1. An entity that suspects or confirms unauthorized access to any Visa payment account data, or to any payment system that stores, processes, or transmits Visa payment account data, is required to ensure that the Compromise Event is reported to Visa’s Global Risk Investigations group within three (3) calendar days of either:

Visa Members are responsible for ensuring compliance with this requirement by their affiliates, agents, and customers.

1.2 Visa Acquirers and Third-Party Processors with access to Visa’s Global Investigation Management Tool (GIMT) must provide notice via GIMT.

Visa’s Global Investigations Management Tool (GIMT) is an end-to-end case management solution that serves as the central repository for receiving and distributing investigation information for Compromise Events and other fraud schemes. Acquirers and their designated Third-Party Processors (TPPs) are required to use GIMT when managing or creating Visa cases.


1.3 All other notifications must be provided to the appropriate regional Visa Global Risk Investigations group.

2 Perform Initial Investigation and Provide Incident Report

2.1 Within three (3) calendar days of notifying Visa in accordance with Section A-1 (above), provide a report describing the event (the “Incident Report”) to Visa and the Acquiring bank (if applicable). Please refer to Attachment A at the end of the document for an editable copy of the Incident Report. Entities should also provide supporting Payment Card Industry Data Security Standards (PCI DSS) compliance documentation when available or requested.

2.2 The information provided in the Incident Report aids Visa in understanding the compromised entity's network environment, potential scope of the incident, potential payment card data at risk, estimated financial exposure where known, and containment status of the Compromise Event. Documentation must include any steps taken to contain and remediate the Compromise Event, including the dates of the containment or remediation steps.

2.3 Visa Acquirers and Third-Party Processors with access to Visa’s Global Investigation Management Tool (GIMT) must provide notice and relevant or requested documentation via GIMT.


3. Provide Notice to Other Relevant Parties

3.1. Immediately notify all relevant parties, including but not limited to the Issuing/Acquiring Bank (if applicable).

3.2. If the name and/or contact information for your Acquiring Bank is unknown, contact the appropriate regional Visa Global Risk Investigations group.

3.3. It is strongly recommended that you also immediately notify:

4. Provide At-Risk Payment Account Data to Visa

4.1 Entities are required to ensure that all compromised Visa account numbers (known or suspected) are provided to Visa’s Global Risk Investigations group within three (3) calendar days.

4.1.1. Entities must work with their Acquirer of Record or Third-Party Processor to upload accounts to GIMT or CAMS, if applicable.


5. Conduct PCI Forensic Investigation (PFI)

5.1. Visa may, at its discretion, require a potentially compromised entity to engage a Payment Card Industry (PCI) Forensic Investigator (PFI) to perform an investigation.

6. Conduct Independent Investigation

6.1. Not all Compromise Events necessitate a PFI. Visa may require the entity to conduct an Independent Investigation in lieu of, or prior to, a PFI-led forensic investigation.

7. Preserve Evidence

7.1. To identify the root cause of a potential Compromise Event, facilitate investigations, and ensure the integrity of the system components and environment, it is critical to preserve all evidence.


Section B: Requirements for Visa Members

The Visa Core Rules and Product and Service Rules (Visa Rules) requires all Visa Members to conduct a thorough investigation of suspected or confirmed loss, theft, or compromise of Visa account or cardholder information involving either their own network environment or that of their Merchants.

1 Submit Notification to Visa

1.1 Within three (3) calendar days, report to the Visa Global Risk Investigations group any suspected or confirmed unauthorized access to any Visa cardholder data or systems.

1.2 Visa Acquirers and Third-Party Processors must provide notice via GIMT.

2. Perform Initial Investigation and Provide Incident Report

2.1. Within three (3) calendar days of notification of a suspected or confirmed Compromise Event, provide the Incident Report to Visa.

2.2. A Member of Record is responsible for engaging and managing its Merchants, Processors, Gateways, Agents, Service Providers, Third-Party vendors, Integrator Resellers, and other entities.

3. Provide At-Risk Payment Account Data

3.1. Visa Members are required to ensure that all compromised Visa account numbers are provided to Visa’s Global Risk Investigations group within three (3) calendar days.

4. Manage PCI Forensic Investigation (PFI)

4.1. Visa may require a potentially compromised entity to conduct a PCI Forensic Investigation. Should Visa require a PFI, Members will receive formal notification from Visa.

5. Manage Independent Investigation

5.1. Not all Compromise Events necessitate a PFI. Visa may require a potentially compromised entity to conduct an Independent Investigation.

6. Requirements for a Suspected or Confirmed Compromise Event of Visa Members

6.1 Visa has observed an increase in attacks against Member financial institutions. Any Member that suspects or confirms unauthorized access to any Visa cardholder data must comply with this Section B-6.


Section B1: Requirements for Members: Fraud Scheme Cases

7. Managing Payment Ecosystem Attacks and Fraud Scheme Cases

Visa has observed an increase in attacks that impact participants in the Visa payments ecosystem. Entities are required to report compromise events that involve payment systems or data, including incidents that could include a payment system or data of a Visa payment ecosystem participant.

The Incident Report should include a timeline of events, including a description of the event, root cause, data impacted, containment and remediation actions taken.


Section B2: Investigation Fees and Non-Compliance Assessments for Members

8. Investigation Fees

Visa aims to ensure the timely resolution of Complaints Events and to drive notification of at-risk accounts to stem fraud impacts. In support of these objectives, Visa has developed Investigation Fees to incentivize cooperation.

PFI-led investigations may be subject to applicable fees.

9. Non-Compliance Assessments

A Member is subject to a non-compliance assessment of up to USD 100,000 per incident for failing to adhere to specific requirements.


Attachment A: Incident Report

Visa Incident Report Page 1
Legal Entity Name:
DBA Entity Name:
Type of Entity:
List any direct processing relationships with Visa:
Services, Solutions, or Product Provided by Entity:
Entity Address:
Primary Contact Name:
Detailed Description of the Incident:
List Window(s) of Intrusion and/or Exposure:
List Data Elements At Risk:
Detail all actions taken to investigate the incident:

Visa Incident Report Page 2
Identify responsible party(s) for the configuration and support of the Point of Sale (POS) solution:
Report Completed By:

Attachment B: Incident Report (Fraud Schemes)

Visa Fraud Schemes Incident Report Page 1
Legal Entity Name:
DBA Entity Name:
Type of Entity:
Services, Solutions, or Product Provided by Entity:
Primary Contact Name:
Report Completed By: