March 22, 2018
Chargeback Management Guidelines for Visa Merchants
Managing chargebacks, cardholder disputes, copy requests, and chargeback reason codes.
PDF 2.06MB
March 22, 2018
Managing chargebacks, cardholder disputes, copy requests, and chargeback reason codes.
PDF 2.06MB
March 2018
The Merchant Frequently Asked Questions provides merchants with frequently asked questions regarding Visa Claims Resolution.
March 2018
The Visa Merchant Business News Digest provides a summary of recent Visa Business News publications that highlight key merchant-related publications.
February 07, 2018
As the payment system has evolved, instances in which a transaction is initiated with a stored credential based on a cardholder’s consent for future use have increased to significant levels. To help merchants and acquirers understand the Stored Credential and Merchant Initiated Transaction framework, Visa is summarizing the requirements and implications through this supplemental document. Please refer to October 2016 VisaNet Business Enhancement Global Technical Letter and Implementation Guide for full details.
218 KB
February 2018
The Visa Merchant Business News Digest provides a summary of recent Visa Business News publications that highlight key merchant-related publications.
January 10, 2018
eCommerce malware infections are a continued contributor to global fraud in the Card-Not-Present space. To help merchants combat fraud resulting from these global and persistent attacks, Visa is providing guidance and best practices for merchants to help secure their online stores.
127 KB
January 2018
The Visa Merchant Business News Digest provides a summary of recent Visa Business News publications that highlight key merchant-related publications.
December 2017
The Visa Merchant Business News Digest provides a summary of recent Visa Business News publications that highlight key merchant-related publications.
November 14, 2017
Visa has become aware of the rise in phishing campaigns throughout the payments ecosystem. The primary cybercriminal exploitation method begins with a phishing e-mail and relies on the Dynamic Data Exchange (DDE) protocol for infection instead of malicious macros or an exploit kit. Visa is providing this alert to ensure awareness of the cyber threats actively exploiting this Microsoft Windows feature.
625 KB
November 14, 2017
Visa hosted a webinar for clients to present an overview of Visa's new monthly client data security communication. To assist clients in managing their sponsored merchant and third party agent compliance with Visa’s data security validation requirements, effective November 2017, Visa will provide clients with a monthly report listing all merchants and third party agents due to revalidate compliance against the Payment Card Industry Data Security Standard and/or PCI PIN Security Requirements.
PDF 977 KB
November 2017
The Visa Merchant Business News Digest provides a summary of recent Visa Business News publications that highlight key merchant-related publications.
November 1, 2017
As counterfeit fraud becomes more challenging for fraudsters globally, they have shifted their focus to the card-not-present channel. Cybercriminals are targeting e-commerce transactions to exploit common vulnerabilities and compromise static payment data. In particular, the e-commerce space has seen developments in malware, modified source codes and database triggers.
PDF 1.1MB
October 2017
The Visa Merchant Business News Digest provides a summary of recent Visa Business News publications that highlight key merchant-related publications.
September 27, 2017
Visa understands the challenges faced by merchants when it comes to staying on top of account information changes. Outdated credential-on-file information can lead to declined transaction and cardholder inconvenience. Increase authorization approvals and reduce customer service issues and expense with Visa Account Updater (VAU). VAU offers two solutions that solve this problem; VAU and Real Time VAU.
PDF 123 KB
September 19, 2017
Visa hosted a webinar to discuss the topics and key take-aways from the 2017 Visa Security Symposium. This webinar highlighted the importance of securing a connected world. In today’s digital age, proper checks on data security and risk management are essential to defending the payments ecosystem.
PDF 1.7 MB
September 2017
The Visa Merchant Business News Digest provides a summary of recent Visa Business News publications that highlight key merchant-related publications.
September 1, 2017
Fuel dispenser chip card acceptance is the more secure way to accept Visa cards at your fuel dispensers, and the best way to avoid liability for counterfeit fraud. The sooner it is done the better for a number of reasons.
PDF 71 KB
August 18, 2017
This document reviews best practices for fuel merchants for preventing Automated Fuel Dispenser (AFD) fraud.
PDF 55 KB
August 01, 2017
Do you know who handles your data? Working with the right partners is crucial to protecting the cardholder environment. Ensuring that players prioritize security can help you score a security home run this summer.
PDF 789 KB
July 20, 2017
Visa has observed an increase in network intrusions involving service providers, re-breaches of merchant payment environments and skimming incidents involving Point of Sale (POS) device overlays. Visa is issuing this alert to make Members and entities aware of their obligations to investigate and immediately report all data compromise events.
August 2017
The Visa Merchant Business News Digest provides a summary of recent Visa Business News publications that highlight key merchant-related publications.
July 6, 2017
The best practices in this document allow merchants to maximize the financial benefits of this authorization processing capability, while creating the best experience for the customer.
PDF 602 KB
May 31, 2017
Visa hosted a webinar providing an overview of the trends in the global payment system – from protection to authentication. This webinar highlights the effects more players and digitization have on the payments ecosystem and what that might mean for data security, fraud management and cyber intelligence in the future.
PDF 1.5 MB
May 4, 2017
In February 2017, analysts identified a new technique used with JavaScript-based eCommerce malware that enables the malware to re-infect the website automatically upon incomplete removal. Visa is providing this report in order to alert eCommerce merchants to this malware technique, and to provide detection and mitigation methods if this malware is discovered.
PDF 520 KB
April 10, 2017
This flyer provides clarification of the rules which detail how a merchant should identify the proper location for all transactions processed through the Visa system. Providing the proper information helps prevent unnecessary cardholder disputes and reduces additional risk to the Visa system.
PDF 673 KB
April 10, 2017
Today, cardholders have real-time, 24/7 access to their online banking through smartphone and other device apps. Purchase information is quickly updated to a cardholder’s account, however, a similar flow of information does not exist on purchase returns. Visa’s new return authorization messages will enable issuers to update cardholders’ online banking statements in real time and provide text alerts to those cardholders that opt in to the service with their issuer. This new service will improve customer experience, reduce inquiries related to lack of real-time information, provide real-time issuer account validation, and minimize related chargebacks.
PDF 520 KB
April 07, 2017
The information contained in the Visa Payment Acceptance Best Practices for U.S. Quick-Service Restaurants guide is geared toward the actions and decisions most pertinent to quick-service restaurants and operators in the U.S. It also includes best practices and on-the-job support tools for managers and employees.
PDF 4.6 MB
April 06, 2017
Visa provides a Partial Authorization service that provides an alternative to declining a transaction when the card’s available balance is not sufficient to approve a transaction in full. This flyer provides information about the benefits realized, how to use the service, and answers to frequently asked questions.
PDF 206 KB
April 06, 2017
Visa has been working with merchants, acquirers, and fuel-industry providers to support migration to the more secure EMV technology. The EMV liability shift is designed to better protect all parties. With the new rules, the party that is the cause of a chip transaction not occurring, either the issuer or acquirer, will be held financially responsible for any resulting card-present counterfeit fraud losses. However, due to challenges with EMV Automated Fuel Dispensers (AFD) solution readiness, Visa is delaying the U.S. domestic AFD EMV liability shift date to 1 October 2020.
PDF 461 KB
March 29, 2017
Webinar deck highlights tools and resources that are available to clients and merchants to mitigate risks when selecting a service provider partner. Additional highlights include Third Party Agent Risk Program initiatives, including unregistered agent campaigns and multiple tool enhancements.
PDF 1.1 MB
02 March 2017
The best ways to process card transactions and manage the risks posed by card payments in the fuel segment.
PDF 2.6 MB
01 March 2017
Multiple information security firms have reported on the emerging threat of a new malware variant identified as “Flokibot”. While Flokibot attacks have focused on the LAC region to date, this malware may represent a broader threat to the payments ecosystem. Visa is publishing this alert in order to provide clients and stakeholders with technical information, including background on the malware, indicators of compromise and suggested mitigation activities to protect the payments ecosystem.
PDF 488 KB
21 February 2017
It is always a great opportunity to set goals and make plans to achieve them. While motivation is at an all-time high, consider taking the following actions to help secure the payments ecosystem at the merchant level.
PDF 426 KB
01 February 2017
Download this comprehensive manual for all businesses that accept Visa transactions in the card-present and/or card-absent environment. This guide provides the latest information and best practices to help merchants process Visa transactions, understand Visa products and rules and protect cardholder data while minimising the risk of loss from fraud.
PDF 5.9 MB
18 January 2017
With the migration of EMV chip acceptance devices, Visa is implementing two significant changes at the POS.
PDF 216 KB
30 December 2016
As the US market migrates to EMV chip, the fraud threat from criminals placing skimming devices on, or in, attended and unattended point-of–sale (POS) devices for the purpose of collecting payment card information, including PIN numbers, increases. Perpetrators use skimmed payment information to quickly create counterfeit cards re-encoded with the stolen card information, typically resulting in ATM withdrawals. To help clients combat skimming, Visa is providing guidance on recommended inspection and response actions. This data security alert may be disseminated to all payment system stakeholders.
PDF 111 KB
13 December 2016
This document describes 3 tools that can be used to help reduce counterfeit fraud on AFD transaction.
PDF 1009 KB
13 December 2016
Visa provides a Partial Authorisation service that provides an alternative to declining a transaction when the card’s available balance is not sufficient to approve a transaction in full. This flyer provides information about the benefits realised, how to use the service, and answers to frequently asked questions.
PDF 326 KB
08 December 2016
Chip card technology in the US has created new challenges for committing fraud at the physical point of sale. Data compromises continue to occur, with fraud migrating online and into other card-not-present channels. As a result, some merchants may experience an increase in chargebacks and transaction declines, cutting into their profitability. In this webinar, learn about current fraud trends and strategies to mitigate fraud in e-commerce. Visa shares common flags for card-not-present fraud and methods for managing and resolving transaction disputes.
PDF 1.3 MB
17 November 2016
Global e-commerce sales are expected to double from 2015 to 2019. While growth in this sales channel creates great opportunities for merchants, it also has the ability to attract high levels of fraud activity. With the holiday season fast approaching, merchants should understand how to best protect against Card-Not-Present Fraud.
PDF 678 KB
16 November 2016
Recognising the signs of a cyber-attack can make the difference between falling victim to a Point-of-Sale compromise and stopping a breach in progress, or preventing one altogether. Through research and intelligence gathered from payment data breach investigations, Visa identified many common tactics, attack characteristics and malware types across breaches in every merchant vertical. Learn some of the new developments in Point-of-Sale network attacks and gain insights into data exfiltration methods as well as how to spot the common warning signs of a breach within the payment environment. Knowing the attacker’s tactics and tools goes a long way in building better defences.
PDF 607 KB
26 October 2016
With steady progress and growth of EMV since 1 October 2015, there are now more than 1.46 million chip-enabled businesses and 363 million chip-enabled Visa cards, making the US the largest Visa chip card market in the world. The number of Visa chip transactions surpassed half a billion in the month of August, representing a 1,000+ percent annual increase. As we reach the one-year anniversary of the EMV liability shift, many questions remain regarding the process behind the migration and the advancements made in the past year. This session discussed why the USA moved to EMV, the progress the industry and Visa has made in the past year, analyse early results and updates on further enhancements, such as Visa Quick Chip.
September 30, 2016
As part of a broader effort to mitigate small merchant breaches, Visa Payment System Risk established new data security program requirements for U.S. and Canadian acquirers with an effective date of January 31, 2017. This infographic addresses the most common questions on the topic of the small merchant validation and Qualified Integrator/Reseller (QIR) requirements.
PDF 800 KB
28 September 2016
Protecting the payment system is a shared responsibility. During this webinar, Visa experts shared latest compromise trends, mitigation strategies, and the latest 'What To Do If Compromised' document.
PDF 3.6 MB
26 September 2016
Visa has seen an increase in global ATM cash-out fraud, which can extract millions of dollars from financial institutions in a short time. The key to limiting losses is quick detection and decisive action, carefully coordinated with Visa. ATM cash-out fraud can happen at any time, anywhere in the world. It often affects issuers in one country and acquirers in another. To help clients combat this global and sophisticated type of fraud, Visa is providing guidance and best practices.
PDF 116 KB
30 August 2016
In late August 2016, Visa became aware of a recent ATM malware compromise in Southeast Asia and is providing indicators of compromise (IOCs) in order to enable security and incident response teams of financial institutions and ATM manufacturers to check and secure network environments. While these IOCs are specifically associated with an investigation involving ATMs in the Southeast Asia incident, Visa notes that the methods employed by the criminals in this incident represent a broader criminal threat to ATM manufacturers/models worldwide and their deployers.
Visa previously published a technical analysis on malware, including filenames, malware hashes, and criminal methodology involved in a separate ATM Jackpotting incident in the Asia-Pacific region. While there are similarities between the two events, this notification serves to highlight key differentiators – including malware and methodologies - pertaining to the incident in Southeast Asia.
PDF 641 KB
24 August 2016
Mobile purchases increased to nearly one in five online orders and generated about $69.1 billion during the most recent holiday season. As mobile payments grow, fraud risks increase. Knowing the differences between e-commerce and m-commerce fraud is a critical first step in protecting merchants. Visa and CyberSource experts explain how a process-based approach can help clients detect and control mobile fraud.
PDF 1.75 MB
12 August 2016
On Monday, 8 August 2016, Oracle Security informed Oracle MICROS customers that it had detected malicious code in certain legacy MICROS systems. Oracle is currently investigating the compromise, and as of 12 August 2016, the company has not published details about the cause/s. Visa is issuing this alert to provide indicators of compromise (IOCs) associated with cybercrime threats known to have previously targeted Oracle systems.
PDF 682 KB
09 August 2016
Visa shares the profile of criminal account testing and associated fraudulent authorisations, and the best practices that payment operations groups must deploy to restrict fraud.
PDF 2.5 MB
4 August 2016
The PCI Security Standards Council convened a small merchant business taskforce to provide guidance and feedback to prepare resources that simplify data security for some of the most vulnerable businesses preyed upon by cybercriminals. Relying on cross-industry expertise to help small merchants understand why and how to protect payment card data and resolve risks to their businesses, the taskforce has developed a toolkit to aid this effort.
PDF 1.5 MB
4 August 2016
Visa highlights the ATM “Jackpotting” incidents in the attached data security alert. This publication provides information regarding indicators of compromise (IOCs) as well as recommendations for response.
PDF 586 KB
02 August 2016
This flyer provides clarification of the rules which detail how a merchant should identify the proper location for all transactions processed through the Visa system. Providing the proper information helps prevent unnecessary cardholder disputes and reduces additional risk to the Visa system.
PDF 673 KB
15 July 2016
Magento is a popular open-source, e-commerce platform written in PHP. Several critical and high vulnerabilities were discovered and patched on the Magento platform on January 2016. Merchants who have not deployed security patch SUPEE-7405, as required by PCI standards, are vulnerable to remote exploits that can compromise account data. Document shares a description and impact of Magento and provides detection and mitigation steps.
PDF 302 KB
12 July 2016
In March 2016, the PoSeidon (point-of-sale) POS malware was modified with the incorporation of a persistence monitoring capability. PoSeidon malware now actively monitors the POS system processes in order to maintain the infection and malware functionality. If the malware is removed from the system, the monitor process waits two (2) minutes and re-infects the system. Document provides an overview of the threat and risk description and best practices to mitigate against PoSeidon.
PDF 339 KB
28 June 2016
In response to a rise in incidents in which skimming devices were placed on POS terminals to collect payment card information, Visa shares typical skimming events that affect self-checkout terminals and the ways in which perpetrators carry out these attacks and how merchants can identify and properly manage these incidents.
PDF 3.5 MB
14 June 2016
Outlines upcoming changes to the acceptance process at the point of sale for merchants using chip acceptance devices.
PDF 198 KB
07 June 2016
Visa provides an Account Number Verification (ANV) Service that assists merchants in verifying if an account is in good standing. This flyer provides information about the service and gives various scenarios for real-life application.
PDF 391 KB
01 June 2016
A manual for acquirers who have boarded, or are considering boarding, an Internet pharmacy or Internet pharmacy referral merchant.
PDF 1.2 MB
20 May 2016
Managing chargebacks, cardholder disputes, copy requests and chargeback reason codes
PDF 5.1M
12 May 2016
The Payment Card Industry Security Standards Council (PCI SSC) has published version 3.2 of the PCI DSS, which provides a baseline of technical and operational requirements designed to protect cardholder data. The bulletin includes key updates, effective dates for implementation and additional resources.
PDF 285 KB
12 May 2016
A Visa security alert describing recent incidents involving suspects placing skimming devices on point-of–sale (POS) terminals for the purpose of collecting payment card information, including PIN numbers.
PDF 106 KB
11 May 2016
The Payment Card Industry Standards Security Council (PCI SSC) which is responsible for defining the technical and operation standards for the protection of payment card data will release an update to the PCI Data Security Standard (PCI DSS) in late April 2016. Visa’s representatives on the PCI SSC will provide information on what to expect with Version 3.2, review the key changes associated with this release and outline dates and impacts to Visa compliance programmes.
PDF 819 KB
06 May 2016
This flyer provides best practices to help reduce counterfeit fraud for service station transactions where merchants are not yet accepting chip cards.
PDF 447 KB
21 April 2016
Following Visa’s requirements for processing a refund will help keep your customers informed and reduce the number of questions you may receive as the result of a return. This flyer describes best practices in processing a refund to a cardholder’s account.
PDF 789 KB
18 April 2016
Many merchants are creating an omni-channel experience for their customers that provides convenient, seamless and secure delivery across all of their channels, including in-store, e-commerce, telephone, mobile web and mobile app. This flyer describes the omni-channel experience depending on the payment and delivery option selected by the customer.
PDF 654 KB
14 April 2016
Visa Claims Resolution, a new global initiative that will replace Visa’s existing dispute resolution process. VCR will simplify dispute processing by migrating from a litigation-based approach to a liability-assignment-based approach. This flyer describes the new process, consolidation of reason codes, and merchant benefits.
PDF 10.3 MB
13 April 2016
Visa and a guest speaker from NCR Corporation discuss the latest skimming techniques and technology, as well as how to spot skimming devices and safeguard against sophisticated attacks.
PDF 10.3 MB
A flyer for lodging, car rental, and cruise line merchants to help them ensure that authorisations are not improperly tying up customer funds.
PDF 897 KB
23 March 2016
Visa and a guest speaker from FireEye explain how financially motivated attackers are targeting customer data and the payment ecosystem. The session dived into security vulnerabilities and techniques hackers use to steal customer information, including payment card data. Visa subject matter experts also provide valuable cyberthreat indicators, risk mitigation strategies and practical guidance on how to detect these threats and secure systems from attack.
PDF 1.4 MB
Four best practices that merchants can implement to help reduce counterfeit fraud for point-of-sale transactions.
PDF 932 KB
04 March 2016
A flyer for quick service restaurants demonstrating how to use a chip cards for payment at the point of sale.
PDF 735 KB
01 March 2016
Operational procedures for special services for lodging and cruise line merchants
PDF1.2 MB
24 February 2016
01 February 2016
Visa highlights “Kuhook” Point-of-Sale (POS) malware, a variant from the “ModPOS” malware family. This point-of-sale malware, “Kuhook”, is one of the most sophisticated and difficult to detect payment card stealing malware identified. Visa experts and Mandiant highlight the malware capabilities, indicators of compromise and mitigation steps.
PDF 4,770K
29 January 2016
Learn how to best communicate that you accept Visa cards and/or mobile payments with Visa. Download the Visa POS Graphic for display at physical locations, on payment terminals and on websites.
ZIP 2.6M
15 January 2016
Visa shares best practices to help mitigate against malware attacks.
PDF 330K
07 January 2016
Updates to the small merchant data security requirements for US and Canadian acquirers. These requirements involve the use of Qualified Integrators and Resellers (QIRs) and required PCI DSS validation. This document includes Frequently Asked Questions about data security requirements.
PDF 193K
22 December 2015
Visa has identified multiple malware families targeted at the lodging industry, including casinos and resorts. To name a few, “FindPOS” (or “Poseidon”), “FrameworkPOS”, and “rawpos” are confirmed in several Visa investigations, suggesting the industry continues to be attractive to attackers interested in payment card data. This publication provides information on each malware family along with security best practices to mitigate this threat.
PDF 311K
18 December 2015
Visa recommends best practices to help merchants mitigate fraud attacks during the holiday season.
PDF 340Kz
17 December 2015
Visa highlights “BlackPOS” malware, a malicious payment card-stealing software targeting point-of-sale systems. “BlackPOS” collect payment card data in ways that are difficult to identify and detect. Visa experts explains how it works, its methods of communication and maintaining stealth, and provides indicators of compromise for detection and eradication.
PDF 629K
16 December 2015
Visa has identified multiple malware families (“FindPOS”, “FrameworkPOS” and “rawpos”) being used to target the lodging industry, including casinos and resorts.
PDF 314K
08 December 2015
Lists qualification criteria for custom payment service rates available to retail merchants in the electronic commerce space. Also provides information about key Visa products for validating the identity of cardholders.
PDF 405K
08 December 2015
Information for US merchants, acquirers, processors and terminal providers planning deployment of EMV chip terminals in the US.
PDF 1.2M
03 December 2015
Visa has identified a variation of malware (from the ModPOS malware family) targeting Point-of-Sale (POS) systems designed to run on Microsoft Windows. Codenamed “Kuhook”, the malware utilises keylogger and memory scraping/parsing functionality. The malware is a sophisticated set of kernel mode device drivers written for the Windows XP platform and is compressed to make the source code and data unreadable.
PDF 160K
24 November 2015
This flyer explains the importance of reversing authorisations properly and provides the required fields used in the reversal process.
PDF 324K
17 November 2015
Visa and CyberSource experts explore CNP risk methodologies to optimise the consumer experience and reduce false declines while minimising fraud losses. Additionally, Visa tools such as CVV2, AVS, Verified by Visa – among others – were covered in great detail as well as CyberSource’s Decision Manager.
PDF 2.06M
13 November 2015
Updated data security alert highlighting attacks on point-of-sale integrators or resellers. This alert outlines attack vectors and mitigation strategies.
PDF 429K
13 November 2015
Managing chargebacks, cardholder disputes, copy requests and chargeback reason codes
PDF 5.1M
29 October 2015
Requirements for US and Canadian acquirers to ensure that their small merchants take steps to secure their point-of-sale (POS) environment. Merchants must use Qualified Integrators and Resellers (QIRs) and Level 4 merchants must validate PCI DSS compliance.
PDF 414K
23 October 2015
This document describes 3 tools that can be used to help reduce counterfeit fraud on AFD transaction.
PDF 1M
21 October 2015
Valuable information for small merchants, including franchisees, highlighting the importance of protecting their customer's cardholder data, explaining the Payment Card Industry (PCI) Data Security Standards (DSS), and providing tools, solutions and strategies to use to help mitigate the risk of fraud and data breaches.
PDF 416K
21 October 2015
Visa explores common security vulnerabilities identified in data breaches and provides mitigation strategies that help to strengthen those payment processing environments.
PDF 926K
05 October 2015
This flyer provides best practices to help reduce counterfeit fraud for service station transactions where merchants are not yet accepting chip cards.
PDF 446K
21 September 2015
This flyer describes options to help airline merchants provide additional information when posting ancillary transactions, such as baggage fees and on-board meals.
PDF 855K
11 September 2015
Information relating to the prepayment of merchandise when it is not immediately available. Includes requirements relating to cardholder consent, merchant policy and transaction receipts.
PDF 537K
02 September 2015
Visa analyses the underlying causes of recurring breaches and the downsides to "tick the box" cyber incident response. Breach preparedness and incident response best practices are provided to help respond to a breach the right way.
PDF 615K
01 September 2015
This flyer provides information about chip acceptance at restaurants and the options available for adding tips to the final transaction amount.
PDF 585K
26 August 2015
A summary of the 2015 Payment Security Symposium held 12-13 August 2015.
PDF 2.78M
25 August 2015
The presentation deck of a panel of industry experts discussing the importance of effective penetration testing, including how to identify a tester and define the scope of a test.
PDF 547K
20 August 2015
Microsoft will no longer support or issue security fixes for Windows Server 2003 after 14 July 2015. This poses a greater risk to the data security of a company utilising Windows Server 2003. Furthermore, as of 15 July 2015, companies using this software may no longer be in compliance with Payment Card Industry Data Security Standard (PCI DSS).
PDF 387K
18 August 2015
This flyer identifies the merchant types that are now eligible to process guaranteed reservations and provides the rules that must be followed by reservation merchants.
PDF 891K
17 August 2015
A checklist of best practices to protect your business from malicious remote access activity associated with unauthorised access to merchant Point-of-Sale (POS) environments via POS integrators.
PDF 90K
5 August 2015
Visa explores threats and security practices for protecting payment card data and personally identifiable information in the health care industry.
PDF 1.64M
22 July 2015
Visa reviews how flat networks or networks without adequate network segmentation make it easy for an attacker to pivot and traverse the network after it has gained entry. Properly segmenting the network can greatly reduce PCI scope, controls, and costs. Also provided are recommendations, benefits and principles of network segmentation, and how to best defend against network threats and vulnerabilities.
PDF 1.15M
5 June 2015
Visa has observed a considerable increase in malicious remote access activity associated with unauthorised access to merchant Point-of-Sale (POS) environments via POS integrators.
PDF 519K
1 June 2015
A manual for acquirers who have boarded, or are considering boarding, an Internet pharmacy or Internet pharmacy referral merchant.
PDF 1.45M
27 May 2015
Learn about Visa’s investigation lifecycle and containment procedures to help minimise payment card fraud.
PDF 1M
26 May 2015
This flyer informs merchants about key card acceptance procedures that will help them avoid being out of compliance with Visa rules.
PDF 601K
29 April 2015
Visa explores threats observed in e-commerce payment processing systems, including merchants, web applications and other internet-facing systems
PDF 1M
21 Apr 2015
Operational procedures and special services for car rental company managers, counter staff and marketing professionals.
PDF 3.6M
21 Apr 2015
Operational procedures and special services for hospitality and lodging professionals.
PDF 4.4M
15 April 2015
An incident response plan is crucial to responding to a data breach and further protecting payment environments.
PDF 1.1M
25 March 2015
Data breach findings and mitigation action items for small merchants.
PDF 331K
05 March 2015
This document outlines changes to the dispute resolution rules concerning compelling evidence. The changes will be effective 17 October 2015
PDF 429K
01 March 2015
Impact and mitigation of "Carbanak" malware
PDF 307K
01 March 2015
The “rawpos” malware is a memory scraper infecting global lodging merchants.
PDF 1M
26 February 2015
Risk-focused guidelines on managing third party agents.
PDF 1.3M
28 January 2015
Data breach findings and mitigation action items for large merchants.
PDF 592K
31 December 2014
Pre-PCI POS PEDS must be removed by 5 May 2010.
PDF 144K
1 Dec 2014
Strategies for long-term risk management
PDF 707K
29 October 2014
Impact and mitigation of “POODLE” vulnerability
PDF 112K
20 August 2014
A review of the 2014 North America Payment Card Security Symposium.
PDF 447K
14 August 2014
Scheme using compromised merchant information to issue fraudulent credits with ATMs.
PDF 130K
14 August 2014
Common myths of accepting chip cards, and information on implementing chip acceptance for your business.
PDF 296K
14 August 2014
Scheme using compromised merchant information to issue fraudulent credits with ATMs.
PDF 130K
8 August 2014
Key points to discuss with your acquirer when determining the best options for upgrading terminals to accept chip cards.
PDF 667K
8 August 2014
Reasons for the movement to chip technology in the US and information on the migration strategy.
PDF 774K
8 August 2014
T&E merchants: movement to chip technology in the US and how chip cards are used with chip terminals during transactions
PDF 1.2M
5 August 2014
Guidelines for online merchants looking to sell pharmaceuticals.
PDF 1.5M
1 August 2014
Visa International e-commerce rules, foreign currency transactions, and cross-border payment disclosures and processing.
PDF 773K
31 July 2014
US CERT advisory of “Backoff” malware family targeting Point-of-Sale systems
PDF 967K
8 July 2014
Upcoming changes to the dispute resolution process that will be effective for chargebacks processed on or after 18 April 2015
PDF 321K
1 July 2014
How to mitigate insecure remote access and user credential management.
PDF 143K
1 June 2014
This guide illustrates the new Visa Brand Mark on Visa cards and new card design features.
PDF 257K
2 May 2014
Responsibilities and requirements for using the Payment Facilitator Model, and benefits for all parties involved in a transaction.
PDF 458K
8 April 2014
Expiration of Windows XP support can negatively impact merchants.
PDF 444K
7 April 2014
How mail and phone order merchants can qualify transactions for CPS, safeguard themselves, and lower operating costs.
PDF 525K
1 April 2014
Impact and mitigation of OpenSSL "Heartbleed" vulnerability.
PDF 116K
17 March 2014
Expanded use of multiple clearings for split-shipment card-absent transactions, and best practices for employing this process.
PDF 642K
6 March 2014
Impact and mitigation of "Chewbacca" Point-of-Sale malware
PDF 129K
19 February 2014
Spanish language guidelines to prevent ATM skimming.
PDF 1.9M
1 February 2014
Updated alert involving memory-parsing malware
PDF 59K
10 January 2014
Counterfeit fraud prevention best practices and procedures for all US acquirers and merchants.
PDF 3.1M
1 January 2014
What merchants need to know about the PCI Security Standards.
1 January 2014
Looking for a validated Service Provider? Please review this list.
1 January 2014
The latest Payment Card Industry Data Security Standard.
1 January 2014
Modifications made to processing card-absent transactions containing multiple items for a single order.
PDF 1.1M
1 January 2014
Actionable items to help prevent merchant breaches.
PDF 4.38M
1 January 2014
The PCI SSC certified Approved Scanning Vendor listing.
1 January 2014
The PCI SSC certified Payment Application Qualified Security Assessor listing.
1 January 2014
Payment application validated by the PCI SSC.
1 January 2014
What merchants need to know about the PCI Security Standards.
1 January 2014
The latest Payment Card Industry Data Security Standard.
1 January 2014
The PCI SSC certified Qualified Security Assessor listing.
1 January 2014
Proper card acceptance procedures can minimise counterfeit fraud transactions.
PDF 3M
1 January 2014
A 1-page guide that explains what card skimming is, how to spot it, and what to do in response.
PDF 225K
1 January 2014
The PCI SSC certified PCI Forensic Investigator listing.
14 November 2013
Data security and fraud protection best practices for petroleum merchants.
PDF 2.02M
16 October 2013
Best practices for securing cardholder data in a processing environment.
PDF 984K
18 Sep 2013
A primer on the secure technologies, encryption and tokenisation.
PDF 1.71M
11 Sep 2013
Best practices for merchants using mobile payment applications.
PDF 1.64M
1 Sep 2013
Global Compromised Account Recovery (GCAR) programme – how it works and what qualification criteria must be met
PDF 2.2M
28 August 2013
Preventing merchant breaches and secure technology options.
PDF 638K
1 August 2013
Updated alert involving memory-parsing malware
PDF 48K
6 May 2013
Retire all pre-PCI attended POS PEDs by 31 December 2014
PDF 428K
24 Apr 2013
An in-depth look on data security threats targeting grocery retailers.
PDF 580K
11 Apr 2013
Memory-parsing malware targeting Point-of-Sales and back-of-house systems
PDF 331K
1 Apr 2013
This document outlines changes to the dispute resolution rules concerning compelling evidence. The changes will be effective 17 October 2015
PDF 29K
14 Mar 2013
Integration guidance for merchants utilising digital wallets.
PDF 44K
13 February 2013
English language presentation on PIN-focused hacker attacks.
PDF 1.25M
12 February 2013
Spanish language presentation on PIN-focused hacker attacks.
PDF 1.67M
6 February 2013
Outline of Visa's data security compliance programmes.
PDF 56K
5 February 2013
Keep your Point-of-Sale terminals safe from fraudsters.
PDF 768K
1 January 2013
Information to review before setting minimum transaction amounts on Visa card payments, with best practices for sales staff.
PDF 291K
1 January 2013
Best practices for hoteliers considering accepting mobile payments.
PDF 1.15M
1 January 2013
Chip card acceptance for hotel, car rental, and restaurant merchants, with quick reference chart
PDF 685K
1 January 2013
Invest in secure technologies to future-proof hospitality payment systems.
PDF 1.08M
1 January 2013
Guidelines for accepting Visa travellers cheques.
PDF 611K
1 January 2013
Three common payment card misconceptions in the hospitality industry.
PDF 4.13M
1 January 2013
Maintaining safe online transactions, including risk management, chargebacks and fraud prevention advice.
PDF 4.1M
1 January 2013
Find out about Visa's PED programme requirements
PDF 249K
27 May 2015
Learn about Visa’s investigation lifecycle and containment procedures to help minimise payment card fraud.
PDF 1M
1 January 2013
A new representment right to provide compelling evidence for specific chargeback reason codes
PDF 296K
September 16, 2013
This document provides guidance for issuers that plan to develop or use a third-party dynamic Cardholder Verification Method (CVM) service to authenticate their cardholders. Dynamic CVMs, such as One-Time Passcodes (OTP), are becoming more prevalent for on-line banking and e-commerce transactions as financial institutions aim to strengthen their customer authentication capabilities. Visa developed the following dynamic CVM best practices for issuers to consider and assess the security features of these solutions.
PDF 36 KB
August 24, 2012
Visa Data Security: Tips and Tools for Small e-Commerce Businesses
PDF 1.7 MB
August 24, 2012
Quick tips and security steps to ensure your customer’s information is safe.
PDF 102 KB
April 28, 2011
Recent data compromises have demonstrated the need for third party payment application integrators and resellers to maintain security processes that go beyond providing software that is compliant with the Payment Application Data Security Standard (PA-DSS).
Visa shares best practices to help defend against poor implementation, maintenance and support processes that have led to merchant and agent data compromises. Visa advises acquirers, merchants, agents and payment application vendors to contact their licensed integrators and resellers, and insist that these best practices be immediately adopted. Merchants and agents should also consider including these best practices as a condition of their service level agreements with third party integrators and resellers.
PDF 60 KB
March 31, 2011
This frequently asked questions (FAQ) document provides guidance for issuers and the ATM environment on Visa-specific programs that mandate compliance with Payment Card Industry (PCI) standards.
PDF 43KB
August 24, 2010
Recent payment card data compromises have demonstrated the critical need for payment application companies to maintain mature software processes for their customers that go beyond Payment Application Data Security Standard (PA-DSS) compliant software. Acquirers, merchants and agents should review Visa’s best practices and insist that their payment application vendors, integrators and resellers fully adopt these practices
PDF 60 KB
July 14, 2010
In October 2009, Visa published the Visa Best Practices for Data Field Encryption to promote the proper encryption of sensitive card data that is transmitted, processed or stored by stakeholders throughout the payment system. As part of these best practices, Visa recommended that entities use tokens (such as a transaction ID or a surrogate value) to replace the Primary Account Number (PAN) for use in payment-related and ancillary business functions. Tokenization can be implemented in isolation or in concert with data field encryption to help merchants eliminate the need to store sensitive cardholder data after authorization. Entities that properly implement and execute a tokenization process to support their payment functions may be able to reduce the scope, risks and costs associated with ongoing compliance with the Payment Card Industry Data Security Standards (PCI DSS).
PDF 50 KB
July 14, 2010
To reinforce its commitment to protecting consumers, merchants, and the overall payment system, Visa is pursuing a global security objective that will enable merchants to eliminate the storage of full PAN and expiration date information from their payment systems when not needed for specific business reasons. To ensure consistency in PAN truncation methods, Visa has developed a list of best practices to be used until any new global rules go into effect.
PDF 39 KB
June 16, 2010
Corporate Franchise Servicer entities operate in a number of merchant segments, including lodging and food service. In an effort to address the increasing threat of data compromises that affect franchise businesses, effective immediately, Visa will extend the Third Party Agent Program to include a new category of agents, called “Corporate Franchise Servicers.” Corporate Franchise Servicers (CFS) operates in a number of merchant segments, including food service and lodging. The inclusion of Corporate Franchise Servicer agents in the Visa Third Party Agent Program will help ensure that Corporate Franchise Servicer agents protect card data by at a minimum complying with the Payment Card Industry Data Security Standards (PCI DSS).
PDF 41 KB
June 11, 2010
Visa Data Security: Tips and Tools for Small Merchant Businesses
PDF 538 KB
October 5 , 2009
Visas shares best practices for data field encryption to protect cardholder data and sensitive authentication data.
PDF 52 KB
April 22, 2009
It is common practice for some card issuers to print the full PAN on each page of a cardholder’s billing statement; however, Visa strongly recommends that, as a “best practice,” issuers truncate or eliminate the printing of the cardholder PAN on billing statements and other cardholder communications.
PDF 29 KB
February 10, 2009
Visa Operating Regulations specify that all Visa clients, including issuers and acquirer financial institutions, must comply with the Payment Card Industry Data Security Standard (PCI DSS). This bulletin specifies the requirements and recommendations necessary for facilitating this compliance.
PDF 39 KB