What To Do If Compromised - Visa Supplemental Requirements

What To Do If Compromised Visa Supplemental Requirements

Version 10.0

Effective: 25 June 2026

Visa Public


Important Note on Copyright

This document is protected by copyright restricting its use, copying, distribution, and decompilation. No part of this document may be reproduced in any form by any means without prior written authorization of Visa.

Visa and other trademarks are trademarks or registered trademarks of Visa.

All other product names mentioned herein are the trademarks of their respective owners.

About Visa Supplemental Requirements

This document is a supplement of the Visa Core Rules and Visa Product and Service Rules. In the event of any conflict between any content in this document, any document referenced herein, any exhibit to this document, or any communications concerning this document, and any content in the Visa Core Rules and Visa Product and Service Rules, the Visa Core Rules and Visa Product and Service Rules shall govern and control.


Contents


Summary

Visa is dedicated to promoting the safe and sound long-term prosperity of the Visa payment ecosystem. To that end, Visa aims to ensure the timely resolution of external data compromise events, drive notification of at-risk accounts to stem fraud impacts, and synthesize forensic evidence, intelligence, and fraud analysis to formulate remediation plans that strengthen payment system security.

Protecting the payment ecosystem is a shared responsibility. Any entity that stores, processes, or transmits payment card data or has access to those systems or data is required to adhere to and maintain compliance with all Payment Card Industry Data Security Standard (PCI DSS) requirements and (PCI) – PIN Security Requirements.

Visa’s What to Do if Compromised (WTDIC) document is a requirements-based guide that applies to entities that suspect or have experienced an event that leverages, impacts, or compromises their payment systems, or payment systems they service or support. This includes, but is not limited to, all Visa Members (e.g., Issuers, Acquirers), Merchants, Processors, Gateways, Agents, Service Providers, Third-Party Vendors, Integrator Resellers, Fin Techs, Blockchain / Crypto or Digital Currency participants, and any other entities that operate or access a payments environment. This document reflects the risks of current and future threats to the payment ecosystem and is designed to provide guidance on each parties' obligations throughout a suspected or confirmed payment environment incident (“Compromise Event”).

WTDIC establishes procedures and timelines for reporting and responding to a Compromise Event. To mitigate payment system risk during a Compromise Event, prompt action is required to prevent additional exposure, including ensuring containment actions and remediation such as the existence and proper functioning of PCI DSS and PCI PIN Security controls.


Section A: Requirements for Entities that Suspect or Have Confirmed a Compromise Event

Any entity that suspects or confirms unauthorized access to and/or misuse of any Visa cardholder data, including any entity that stores, processes, or transmits cardholder data or has access to a payments environment or systems, is required to adhere to the WTDIC requirements.

This includes, but is not limited to Merchants, Processors, Gateways, Agents, Service Providers, Third-Party Vendors, Integrator Resellers, FinTechs, Blockchain / Crypto or Digital Currency participants, and any other entities operating or accessing a payments environment.

Entities are required to report compromise events that involve payment systems or data. Visa requires an incident report for any suspected or confirmed Compromise Event that involves the potential or actual unauthorized access to payment system or data of any Visa payment ecosystem participant.

1. Submit Notification to Visa Within Three (3) Calendar Days

1.1 An entity that suspects or confirms unauthorized access to any Visa payment account data, or to any payment system that stores, processes, or transmits Visa payment account data, is required to ensure that the Compromise Event is reported to Visa’s Global Risk Investigations group within three (3) calendar days of either:

Visa Members are responsible for ensuring compliance with this requirement by their affiliates, agents, and customers.

1.2 Visa Acquirers and Third-Party Processors with access to Visa’s Global Investigation Management Tool (GIMT) must provide notice via GIMT.

Visa’s Global Investigations Management Tool (GIMT) is an end-to-end case management solution that serves as the central repository for receiving and distributing investigation information for Compromise Events and other fraud schemes.

1.3 All other notifications must be provided to the appropriate regional Visa Global Risk Investigations group listed in table 1.1 (below).

2. Perform Initial Investigation and Provide Incident Report

2.1 Within three (3) calendar days of notifying Visa in accordance with Section A-1 (above), provide a report describing the event (the “Incident Report”) to Visa and the Acquiring bank (if applicable).

2.2 The information provided in the Incident Report aids Visa in understanding the compromised entity's network environment, potential scope of the incident, potential payment card data at risk, estimated financial exposure where known, and containment status of the Compromise Event.

Documentation must include any steps taken to contain and remediate the Compromise Event, including the dates of the containment or remediation steps.

3. Provide Notice to Other Relevant Parties

3.1 Immediately notify all relevant parties, including but not limited to the Issuing/Acquiring Bank (if applicable).

3.2 If the name and/or contact information for your Acquiring Bank is unknown, contact the appropriate regional Visa Global Risk Investigations group listed in Section A, Table 1.1.

3.3 It is strongly recommended that you also immediately notify:

4. Provide At-Risk Payment Account Data to Visa

4.1 Entities are required to ensure that all compromised Visa account numbers (known or suspected) are provided to Visa’s Global Risk Investigations group via Visa’s Global Investigation Management Tool (GIMT) or Compromised Account Management System (CAMS) within three (3) calendar days of any of the following scenarios:

4.1.1 Entities must work with their Acquirer of Record or Third-Party Processor to upload accounts to GIMT or CAMS, if applicable.

5. Conduct PCI Forensic Investigation (PFI)

5.1 Visa may, at its discretion, require a potentially compromised entity to engage a Payment Card Industry (PCI) Forensic Investigator (PFI) to perform an investigation. Should Visa require an investigation by a PFI, Members or responsible parties will receive formal notification from Visa via the Global Investigations Management Tool (GIMT) or appropriate email channel.

5.2 Within five (5) business days, execute a contract retaining a PFI to perform a PCI forensic investigation and inform Visa of the PFI company and lead investigator.

5.3 Visa will review, but not recognize forensic reports from a non-approved PFI company when a PFI is required.

5.4 The PFI cannot be an organization that is affiliated with the compromised entity or has provided services to the compromised entity such as previous PFI investigation, Qualified Security Assessor (QSA), advisor, consultant, monitoring or network security support within the past 3 years.

6. Conduct Independent Investigation

6.1 Not all Compromise Events necessitate a PFI. Visa may require the entity to conduct an Independent Investigation in lieu of, or prior to, a PFI-led forensic investigation.

6.2 Within five (5) business days, execute a contract retaining an appropriately qualified investigator to perform the Independent Investigation and inform Visa of the investigation company and lead investigator.

7. Preserve Evidence

7.1 To identify the root cause of a potential Compromise Event, facilitate investigations, and ensure the integrity of the system components and environment, it is critical to preserve all evidence.

7.1.1 Do not access or alter compromised system(s) (e.g., do not log on to the compromised system(s) and change passwords; do not log in with administrative credentials).

7.1.2 Document containment and remediation actions taken, including dates/times (preferably in UTC), individuals involved, and detailed actions performed.


Section B: Requirements for Visa Members

The Visa Core Rules and Product and Service Rules (Visa Rules available on Visa Access) and this What To Do If Compromised document requires all Visa Members (e.g., Issuers, Acquirers) to conduct a thorough investigation of suspected or confirmed loss, theft, or compromise of Visa account or cardholder information involving either their own network environment or that of their Merchants, Processors, Gateways, Agents, Service Providers, Third-Party Vendors, Integrator Resellers, FinTechs, Blockchain / Crypto or Digital Currency participants, and any other entities operating or accessing a payments environment on behalf of the Visa Member.

1 Submit Notification to Visa

1.1 Within three (3) calendar days, report to the Visa Global Risk Investigations group any suspected or confirmed unauthorized access to any Visa cardholder data or systems.

1.2 Visa Acquirers and Third-Party Processors with access to Visa’s Global Investigation Management Tool (GIMT) must provide notice and relevant or requested documentation via GIMT.

1.3 All other notifications must be provided to the appropriate regional Visa Global Risk Investigations group listed in Section A, Table 1.1.

2. Perform Initial Investigation and Provide Incident Report

2.1 Within three (3) calendar days of notification of a suspected or confirmed Compromise Event, provide the Incident Report to Visa. Visa Members are required to perform an initial investigation and submit an Incident Report via Visa's Global Investigation Management Tool (GIMT).

2.2 A Member of Record (e.g., Issuer, Acquirer) is responsible for engaging and managing its Merchants, Processors, Gateways, Agents, Service Providers, Third-Party vendors, Integrator Resellers, and any other entities, operating or accessing a payments environment on its behalf to investigate and fully address any potential Compromise Event.

2.3 Within three (3) calendar days of notification of a Compromise Event, provide Visa with status of compliance with Payment Card Industry Data Security Standard (PCI DSS) requirements and (PCI) – PIN Security Requirements at the time of the incident, if applicable.

3. Provide At-Risk Payment Account Data

3.1 Visa Members (e.g., Issuers, Acquirers) are required to ensure that all compromised Visa account numbers (known or suspected) are provided to Visa’s Global Risk Investigations group via Visa’s Global Investigation Management Tool (GIMT) or Compromised Account Management System (CAMS), within three (3) calendar days of any of the following scenarios:

3.2 The known or suspected compromised account data must be based on authorization transaction records or other at-risk payment data (e.g., stored PAN’s) delineated by Point-of-Sale (POS) entry mode, where applicable.

4. Manage PCI Forensic Investigation (PFI)

4.1 Visa may, at its discretion, require a potentially compromised entity to conduct a PCI Forensic Investigation. Should Visa require a PFI, Members or responsible parties will receive formal notification from Visa via the Global Investigations Management Tool (GIMT) or via the appropriate email channel.

4.2 Within five (5) business days, ensure that a contract retaining a PFI to perform the PCI forensic investigation has been executed, and inform Visa of the PFI company and lead investigator as described in Section B4.3.1.

4.3 Visa will review, but not recognize forensic reports from a non-approved PFI company when a PFI is required.

4.4 Visa reserves the right to require additional PFI investigations and/or directly retain a PFI to perform additional PFI investigations if, in its sole discretion, it determines that the WTDIC requirements have not been satisfied.


Section B1: Requirements for Members: Fraud Scheme Cases

7. Managing Payment Ecosystem Attacks and Fraud Scheme Cases

Visa has observed an increase in attacks that impact participants in the Visa payments ecosystem. These attacks can include, but are not limited to Ransomware Events, Supply Chain Attacks, Brute Force Attacks, Credential Take Over, Credential Stuffing, Merchant and Cardholder Collusion, Force Posting, Fraudulent Purchase Return (aka Credit Vouchers), Fraudulent Purchase Return Authorization, Account Testing, Account Enumeration, or any other nefarious activity against or leveraging participants in the Visa Payment ecosystem.

Entities are not required to report compromise events that do not involve payment systems or data. However, for any suspected or confirmed event that could include a payment system or data of a Visa payment ecosystem participant, or potential access to payment card data, Visa does require an Incident Report.


Section B2: Investigation Fees and Non-Compliance Assessments for Members

8. Investigation Fees

Visa is dedicated to promoting the safe and sound long-term prosperity of the Visa payment ecosystem and continues to make significant investments in payments technology to protect the payment ecosystem.

PFI-led investigations may be subject to applicable fees. If a PCI forensic investigation is not completed within four (4) full calendar months from the date Visa provided notice of the requirement for a PFI, Visa may impose fees.

9. Non-Compliance Assessments

Effective 9 February 2025, Non-Compliance Assessments (NCA’s) associated with the WTDIC guide are tiered for Level 3 merchants. A Member is subject to a non-compliance assessment of up to USD 100,000 per incident for failing to adhere to any of the below requirements.