• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

2

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'

3

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 

1

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

2

Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'

3

Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
Tech

How to Guess Visa Card Details in Just 6 Seconds

Jeff John Roberts
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
Jeff John Roberts
By
Jeff John Roberts
Jeff John Roberts
Editor, Finance and Crypto
Down Arrow Button Icon
December 5, 2016, 9:44 AM ET
Photo by: Jörg Carstensen/picture-alliance/dpa/AP Images
Photo by: Jörg Carstensen/picture-alliance/dpa/AP ImagesPhotograph by Jörg Carstensen — Picture-Alliance/AP

If you shop online, you know how retailers ask for extra credit card information such as a security code to reduce the risk of fraud. In the case of Visa, however, it turns out there’s a way for hackers to guess that card information in mere seconds.

The trick, described in a new academic paper, may have been responsible for the hack of thousands of Tesco customers in the U.K. It also shows how online payments remain a weak spot at a time when credit card companies are using chips and other features to tighten up security for in-store transactions.

The Visa (V) vulnerability described in the paper works like this: The hackers use bots to submit credit card information to hundreds of retailers at once in order to guess the missing security code information. Since the code is only three numbers, it takes a maximum of 1,000 guesses to crack it. The paper suggests the attack can be carried out in just six seconds:

These experiments have also shown that it is possible to run multiple bots at the same time on hundreds of payment sites without triggering any alarms in the payment system. Combining that knowledge with the fact that an online payment request typically gets authorized within two seconds makes the attack viable and scalable in real time. As an illustration, with the website bot configured cleverly to run on 30 sites, an attacker can obtain the correct information within four seconds.

The trick works, according to the researchers, because Visa does not detect multiple attempts to use a card across its network. This is different than MasterCard, they say, which will detect the guessing attack after fewer than 10 attempts, even when the guesses are spread across multiple websites.

Online retailers are also part of the problem since many of them allow someone to submit the same credit card details over and over again, the report suggests.

One solution to the “guessing attack” problem might be for retailers to require additional verification details such as a zip code and, indeed, many do so already. But as the paper notes, this information could also be guessed in the way described above—and meanwhile, many retailers are reluctant to create additional friction for the customer in the payment process.

Get Data Sheet, Fortune’s technology newsletter

The best answer appears to be for Visa to adopt a similar approach to MasterCard (MC) and shut down a card when someone tries to guess card details multiple times in rapid succession.

Visa provided a detailed statement to the Independent, which was one of several U.K. outlets to report on the research, saying the paper “did not account for the multiple layers of fraud prevention that exist within the payments system.” However, it did not address whether it would adopt a system like the one used by MasterCard. Visa did not immediately respond to an email from Fortune for more details.

To conduct the experiment, the researchers used their own credit cards. They also pointed out, however, that hackers who wished to conduct a “guessing attack” could easily purchase credit card numbers in online criminal forums.

There have been no confirmed cases of hackers carrying out the attack described in the paper, but some security experts believe it has indeed been used, including in a major security breach last month at Tesco.

About the Author
Jeff John Roberts
By Jeff John RobertsEditor, Finance and Crypto
LinkedIn iconTwitter icon

Jeff John Roberts is the Finance and Crypto editor at Fortune, overseeing coverage of the blockchain and how technology is changing finance.

See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

How Grab’s CTO sees the superapp’s push into physical AI and automated driving—and why he uses his competitors’ robots in the office
AITransportation
How Grab’s CTO sees the superapp’s push into physical AI and automated driving—and why he uses his competitors’ robots in the office
By Angelica AngMay 22, 2026
6 hours ago
Trump AI and crpto czar David Sacks sits next to Meta CEO Mark Zuckerberg at a dinner table in the White House as Zuckerberg turns to Sacks and says something.
AIAmerican Politics
Tech billionaires convinced Trump to back off an AI executive order. But much of MAGA favors AI regulation
By Jeremy KahnMay 22, 2026
6 hours ago
James Daunt sits in a booksop, gesturing with both hands and smiling.
AIbooks
Barnes & Noble CEO clarifies the bookseller’s stance on AI-written books after refusing to ban them: ‘This is a straightforward rejection of AI books’
By Sasha RogelbergMay 22, 2026
8 hours ago
A photo taken during the Maroon Bells bicycle ride during Fortune Brainstorm Tech 2019 in Aspen, Colorado. (Photo: Fortune)
InnovationBrainstorm Tech
Fortune Brainstorm Tech 2026 will be brilliant
By Andrew NuscaMay 22, 2026
9 hours ago
satya nadella
AITech
Microsoft reports are exposing AI’s real cost problem: Using the tech is more expensive than paying human employees
By Jake AngeloMay 22, 2026
10 hours ago
Sam Altman standing in a lift.
AIOpenAI
The big questions looming over OpenAI’s trillion-dollar IPO
By Beatrice NolanMay 22, 2026
10 hours ago

Most Popular

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
Success
Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
By Preston ForeMay 21, 2026
1 day ago
Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
Success
Despite a $500 million net worth, Shaq just finished his fourth degree. He warns graduates: 'Your character will take you further than your resume'
By Preston ForeMay 20, 2026
3 days ago
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
Workplace Culture
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’ 
By Preston ForeMay 19, 2026
3 days ago
Pay transparency is exposing a bigger problem: Most companies can't explain why they pay what they pay
Workplace Culture
Pay transparency is exposing a bigger problem: Most companies can't explain why they pay what they pay
By Sydney LakeMay 20, 2026
2 days ago
Indeed chief economist says we’re entering an era of ‘great mismatch’ thanks to a generational imbalance of workers
Success
Indeed chief economist says we’re entering an era of ‘great mismatch’ thanks to a generational imbalance of workers
By Emma BurleighMay 22, 2026
11 hours ago
McKinsey partner says up to 50% of work hours could be transformed within the next 5 years
AI
McKinsey partner says up to 50% of work hours could be transformed within the next 5 years
By Emma BurleighMay 21, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.