Using AI, Mastercard Expects to Find Compromised Cards Quicker, Before They Get Used by Criminals

FILE - A sign indicating MasterCard credit cards are accepted is posted at a New York business, Jan. 21, 2015. Mastercard said Wednesday, May 21, 2024, that it expects to be able to discover that your credit or debit card number has been compromised well before it ends up in the hands of a cybercriminal. (AP Photo/Mark Lennihan, File)
FILE - A sign indicating MasterCard credit cards are accepted is posted at a New York business, Jan. 21, 2015. Mastercard said Wednesday, May 21, 2024, that it expects to be able to discover that your credit or debit card number has been compromised well before it ends up in the hands of a cybercriminal. (AP Photo/Mark Lennihan, File)
TT
20

Using AI, Mastercard Expects to Find Compromised Cards Quicker, Before They Get Used by Criminals

FILE - A sign indicating MasterCard credit cards are accepted is posted at a New York business, Jan. 21, 2015. Mastercard said Wednesday, May 21, 2024, that it expects to be able to discover that your credit or debit card number has been compromised well before it ends up in the hands of a cybercriminal. (AP Photo/Mark Lennihan, File)
FILE - A sign indicating MasterCard credit cards are accepted is posted at a New York business, Jan. 21, 2015. Mastercard said Wednesday, May 21, 2024, that it expects to be able to discover that your credit or debit card number has been compromised well before it ends up in the hands of a cybercriminal. (AP Photo/Mark Lennihan, File)

Mastercard said Wednesday that it expects to be able to discover that your credit or debit card number has been compromised well before it ends up in the hands of a cybercriminal.

In its latest software update rolling out this week, Mastercard is integrating artificial intelligence into its fraud-prediction technology that it expects will be able to see patterns in stolen cards faster and allow banks to replace them before they are used by criminals.

“Generative AI is going to allow to figure out where did you perhaps get your credentials compromised, how do we identify how it possibly happened, and how do we very quickly remedy that situation not only for you, but the other customers who don't know they are compromised yet,” said Johan Gerber, executive vice president of security and cyber innovation at Mastercard, in an interview.

Mastercard, which is based in Purchase, New York, says with this new update it can use other patterns or contextual information, such as geography, time and addresses, and combine it with incomplete but compromised credit card numbers that appear in databases to get to the cardholders sooner to replace the bad card, The AP reported.

The patterns can now also be used in reverse, potentially using batches of bad cards to see potentially compromised merchants or payment processors. The pattern recognition goes beyond what humans could do through database inquiries or other standard methods, Gerber said.

Billions of stolen credit card and debit card numbers are floating in the dark web, available for purchase by any criminal. Most were stolen from merchants in data breaches over the years, but also a significant number have been stolen from unsuspecting consumers who used their credit or debit cards at the wrong gas station, ATM or online merchant.

These compromised cards can remain undetected for weeks, months or even years. It is only when the payment networks themselves dive into the dark web to fish for stolen numbers themselves, a merchant learns about a breach, or the card gets used by a criminal do the payments networks and banks figure out a batch of cards might be compromised.

“We can now actually proactively reach out to the banks to make sure that we service that consumer and get them a new card in her or his hands so they can go about their lives with as little disruption as possible,” Gerber said.

The payment networks are largely trying to move away from the “static” credit card or debit card numbers — that is a card number and expiration date that is used universally across all merchants — and move to unique numbers for specific transactions. But it may take years for that transition to happen, particularly in the US where payment technology adoption tends to lag.

While more than 90% of all in-person transactions worldwide are now using chip cards, the figure in the US is closer to 70%, according to EMVCo, the technological organization behind the chip in credit and debit cards.

Mastercard's update comes as its major competitor, Visa Inc., also looks for ways to make consumers discard the 16-digit credit and debit card number. Visa last week announced major changes to how credit and debit cards will operate in the US, meaning Americans will be carrying fewer physical cards in their wallets, and the 16-digit credit or debit card number printed on every card will become increasingly irrelevant.

 

 

 

 



Impostor Uses AI to Impersonate Rubio and Contact Foreign and US Officials

Secretary of State Marco Rubio attends a signing ceremony for a peace agreement between Rwanda and the Democratic Republic of the Congo at the State Department, June 27, 2025, in Washington. (AP Photo/Mark Schiefelbein, File)
Secretary of State Marco Rubio attends a signing ceremony for a peace agreement between Rwanda and the Democratic Republic of the Congo at the State Department, June 27, 2025, in Washington. (AP Photo/Mark Schiefelbein, File)
TT
20

Impostor Uses AI to Impersonate Rubio and Contact Foreign and US Officials

Secretary of State Marco Rubio attends a signing ceremony for a peace agreement between Rwanda and the Democratic Republic of the Congo at the State Department, June 27, 2025, in Washington. (AP Photo/Mark Schiefelbein, File)
Secretary of State Marco Rubio attends a signing ceremony for a peace agreement between Rwanda and the Democratic Republic of the Congo at the State Department, June 27, 2025, in Washington. (AP Photo/Mark Schiefelbein, File)

The State Department is warning US diplomats of attempts to impersonate Secretary of State Marco Rubio and possibly other officials using technology driven by artificial intelligence, according to two senior officials and a cable sent last week to all embassies and consulates.

The warning came after the department discovered that an impostor posing as Rubio had attempted to reach out to at least three foreign ministers, a US senator and a governor, according to the July 3 cable, which was first reported by The Washington Post.

The recipients of the scam messages, which were sent by text, Signal and voice mail, were not identified in the cable, a copy of which was shared with The Associated Press.

“The State Department is aware of this incident and is currently investigating the matter,” it said. “The department takes seriously its responsibility to safeguard its information and continuously takes steps to improve the department’s cybersecurity posture to prevent future incidents.”

It declined to comment further due to “security reasons” and the ongoing investigation.

One of the officials said the hoaxes had been unsuccessful and “not very sophisticated.” Nonetheless, the second official said the department deemed it “prudent” to advise all employees and foreign governments, particularly as efforts by foreign actors to compromise information security increase.

The officials were not authorized to discuss the matter publicly and spoke on condition of anonymity.

“There is no direct cyber threat to the department from this campaign, but information shared with a third party could be exposed if targeted individuals are compromised,” the cable said.

The FBI warned in a public service announcement this past spring of a “malicious text and voice messaging campaign” in which unidentified “malicious actors” have been impersonating senior US government officials.

The scheme, according to the FBI, has relied on text messages and AI-generated voice messages that purport to come from a senior US official and that aim to dupe other government officials as well as the victim’s associates and contacts.

It is the second high-level Trump administration official to face such AI-driven impersonation.

The government was investigating after elected officials, business executives and other prominent figures received messages from someone impersonating President Donald Trump’s chief of staff, Susie Wiles. Text messages and phone calls went out from someone who seemed to have gained access to the contacts in Wiles’ personal cellphone, The Wall Street Journal reported in May.

Some of those who received calls heard a voice that sounded like Wiles, which may have been generated by artificial intelligence, according to the newspaper. The messages and calls were not coming from Wiles’ number, the report said.