The recent wave of mass overseas fraudulent charges on Mastercard credit cards continues to escalate, with multiple cardholders reporting unauthorized overseas deductions despite keeping their physical cards secure in China and never conducting any overseas transactions—some victims lost over 10,000 yuan.
Further interviews reveal that many cardholders share strikingly similar experiences: their physical cards sat idle for extended periods, were only linked to Apple Pay, and had never even been used for in-store swipes.
Several cardholders confirmed that all stolen funds have been fully recovered with no actual financial loss, but industry observers note this incident has exposed overlooked risk control blind spots in cross-border payment channels.
Unlike traditional data-leak-driven fraud, this incident points directly to systemic risk control weaknesses: inadequate Token scenario verification at issuing banks, flawed transaction routing configurations, and insufficient early warning systems at card organizations.
Industry experts believe that banks, card organizations, and wallet providers must establish joint risk control mechanisms, while cardholders should also take preventive measures in advance.
Multiple Cardholders Experience "Bizarre" Charges: Funds Fully Refunded
Between 1:30 PM and 2:00 PM on September 28, after enduring an overseas credit card fraud ordeal, two fraudulent charges in Chen Yang's (pseudonym) account were fully refunded, though the bizarre experience still left him shaken.
"The moment I discovered the fraud, my mind went blank," Chen Yang recalled. At 9:30 AM on September 26, while resting at home, his phone buzzed with two consecutive transaction alert text messages from Bank of China, and his Apple Pay wallet simultaneously pushed notifications of overseas spending records.
The sudden alerts instantly put him on edge. The card that was charged was a Mastercard credit card locked in a drawer at home, never actually used for any purchases.
Both transaction merchant names were obscured with asterisks, the transaction location pointed to Brazil, and the total fraudulent amount was 11,404.68 Brazilian reais, equivalent to approximately 14,800 yuan.
Chen Yang applied for this card in September last year with a credit limit of about 70,000 yuan. His original reasons for applying were twofold: he liked the card's design, and he planned to use it for future trips to Europe.
After receiving the card, the physical card remained at home and was never taken out. Chen Yang recalled, "At the time, I only linked the card to my phone's Apple Pay wallet, but I never completed a single payment through Apple Pay."
When the incident occurred, he was in China with his phone in hand and did not receive any payment verification.
After discovering the anomaly, Chen Yang tried to lock the card through the mobile banking app to stop the losses and called the credit card VIP customer service hotline. "What was most unsettling was that I never received any risk warning, transaction verification, or temporary freeze notification from the bank throughout the entire process," Chen Yang recalled.
Since credit card transactions have a settlement window period, funds are not transferred in real-time like debit cards. The bank leveraged this mechanism to initiate stop-payment operations through card organization channels, ultimately recovering the fraudulent funds.
Chen Yang told reporters that in his cardholder communication group, from September 28 to September 29, many cardholders reported that their stolen funds had been refunded.
Another cardholder, Li Kai (pseudonym), also recounted a similar experience. Six months ago, he specifically applied for this Bank of China credit card for future overseas spending. To avoid wasting the card, Li Kai occasionally used it, but the card remained idle most of the time with almost no large purchases or overseas transaction records.
The anomaly also occurred on September 26, when Li Kai suddenly received transaction alert text messages from Bank of China, discovering three unfamiliar overseas fraudulent transactions on his card totaling nearly 8,000 yuan.
During the same period, Li Kai was in China, and his physical credit card was always properly kept and carried with him. The card never left his possession, and there was no loss or lending to others.
"The bank told me they had confirmed it was fraud, that I didn't need to repay the debt, but they didn't explain the reason for the fraud," Li Kai said.
Additionally, Bank of China credit card customer service staff confirmed that the bank has taken corresponding risk control measures. Bank of China credit card customer service representatives stated that this fraud incident will not cause customers additional financial losses and asked customers to wait for the bank's follow-up contact.
Virtual Tokens Become the Fraud Breakthrough Point: Some Banks Launch Internal Investigations
Although the funds were recovered, the risk control vulnerabilities exposed by the entire incident have not disappeared with the refunds.
From the fraud patterns, multiple cardholders' experiences show high similarity: cards linked to Apple Pay, physical cards rarely used or never swiped offline.
Most fraudulently charged cards were Mastercard cards linked to Apple Pay. Several cardholders speculated that the core breakthrough point of this fraud incident was the Token card number generated after linking bank cards to Apple Pay—the payment token.
Li Kai told reporters, "Apple also responded to me that the device card number itself is not confidential information. The three fraudulent orders did not appear in my Apple Pay account, which means the fraud gang obtained credit card-related information and then linked the card to their own Apple Pay to initiate payments."
He believes that in previous months, Apple had promoted campaigns for linking Apple Pay with Mastercard, and many users linked their credit cards to Apple Pay during the same period, with card expiration dates also concentrated in the same range. Fraudsters may have used this to obtain the expiration dates of these cards, then continuously guessed device card numbers to bypass CVV verification and complete fraudulent payments.
A bank credit card center representative explained that when users link credit cards to Apple Pay, the phone does not directly store or use the user's real bank card number. The system automatically generates a unique virtual replacement card number for each linked card—this unique virtual card number is the payment token (Token).
However, in this fraud incident, the core problem lies in vulnerabilities in virtual tokens and the risk control system. The credit card center representative speculated that in this fraud incident, hackers may have simulated the generation sequence of unique virtual replacement card numbers and then conducted batch number testing for remote fraud.
Regarding the risks of mass fraud, some banks have already launched internal investigations. A representative from a bank's credit card center stated that their bank has not experienced fraud cases yet. Although several fraud attempts were detected, none passed transaction verification.
Where Did Verification Go: A Gap Between Technical Ideals and Actual Configuration
It is worth noting that this is not the first time Mastercard has been embroiled in fraud controversy. As early as September last year, Mastercard cards issued by Shanghai Pudong Development Bank experienced highly similar batch abnormal transactions.
Just one year later, mass fraud has occurred again, both pointing to Mastercard as the service provider. Industry observers believe this may expose Mastercard's shortcomings in cross-border risk联防.
Professor Tian Lihui of Nankai University's School of Finance pointed out that cardholders' technical judgments highly align with known information. Compared with previous fraud cases, Tian Lihui believes this incident presents three new characteristics: attack targets shifted from physical card information to device Tokens, attack paths bypassed Apple Pay's facial verification, and attack methods changed from single-point leaks to batch number range testing.
"This is no longer traditional card theft, but rather the scaled exploitation of configuration flaws in payment technology implementation," Tian Lihui further stated. As a clearing institution, Mastercard Net Union bears management responsibility for monitoring and warning abnormal transactions in number ranges.
Two consecutive years of mass fraud indicate this is not an occasional vulnerability, but rather systematic configuration deficiencies in Token scenario verification at some issuing banks. Issuing banks are the first gate, and Mastercard Net Union is the monitoring layer—their responsibilities cannot replace each other.
A deeper contradiction lies in the enormous execution gap between security promises and actual implementation.
"The core reason is the gap between Token security promises and issuing banks' actual configuration capabilities," Tian Lihui explained. Tokenization should use device account numbers to replace real card numbers and strictly limit transaction scenarios, but device card numbers are issued sequentially and can be batch-tested; scenario verification lacks unified mandatory standards; more dangerously, once cardholders and institutions relax vigilance because of "Token equals security," other defense lines will also loosen.
Two consecutive years of similar incidents indicate that attackers have formed stable exploitation patterns, while the number range patterns in product design and uneven implementation configurations provide replicable conditions for such attacks.
"Many victims simply linked their cards to Apple Pay. Their physical cards weren't lost, they didn't travel abroad, yet they were still fraudulently charged at Latin American online merchants. So from this perspective, Apple Pay itself isn't to blame—its token technology is inherently secure. The problem may mainly lie in Mastercard's cross-border clearing chain," said Wang Pengbo, Chief Analyst at Botong Consulting.
Wang Pengbo further stated that as a card organization, Mastercard has insufficient risk control constraints on global downstream overseas merchants. Some overseas online merchants can bypass secondary verification, and criminal operations may have exploited this loophole for batch transactions.
Meanwhile, at the card organization level, early warning and interception for concentrated test transactions in the same number range are also insufficient. They only belatedly exposed risks after large numbers of users had already been fraudulently charged, revealing obvious shortcomings in cross-border risk联防, with a significant portion of risk pressure transferred to issuing banks and ordinary cardholders.
Dong Ximiao, Chief Researcher at Zhaolian Finance, reminded that compared with traditional fraud, this type of risk attack surface has expanded from card number information to device and digital credential links. Transactions often show cross-border, dispersed characteristics with more participants and more complex liability determination.
Apple Pay replaces physical card numbers with device account information and incorporates dynamic security mechanisms, which can reduce the risk of direct card number exposure. However, Tokens are not absolutely secure, especially if registration risk monitoring is insufficient, making it difficult for a single institution to identify cross-industry gang fraud.
Industry Suggests Clarifying Responsibilities: Three Parties Need Joint Risk Control
Industry observers believe that to plug this new type of fraud, relying on any single party is insufficient. Instead, the security boundaries among wallets, card organizations, and issuing banks need to be re-clarified with actionable remediation paths.
Tian Lihui pointed out that "Mastercard should comprehensively audit issued device card number ranges, fix configuration flaws, and change number range generation from sequential issuance to randomization. Banks, card organizations, and wallets need to establish joint risk control: wallets should write in tamper-proof scenario identifiers, card organizations should enforce verification and real-time alerts at the clearing layer, and issuing banks should硬性 intercept abnormal requests at the access layer."
Wang Pengbo emphasized that card organizations cannot just be a "transaction pipeline." "Card organizations must subsequently consolidate their own risk control responsibilities and identify and intercept centralized, batch-testing abnormal transaction behaviors earlier."
Dong Ximiao further pointed to the institutional level, suggesting strengthening risk scoring at the registration stage, promoting real-time risk information sharing among card organizations, payment platforms, and banks, and improving cross-border transaction dispute and liability determination rules.
The特殊性 of cross-border chains lies precisely here: a transaction originates from a mobile wallet, passes through clearing networks and overseas merchant gateways, then reaches domestic issuing bank backends, crossing different countries' regulatory environments and data rules. Any looseness in verification at any link could create a gap in the entire defense line. By the time fund anomalies occur, losses often fall directly on cardholders first, then banks initiate chargeback processes for recovery.
This also means that before systematic patches are fully implemented, users need to establish their own security boundaries.
For cardholders who have already experienced fraud or wish to take preventive measures in advance, Dong Ximiao suggests: "If cardholders discover abnormal overseas transactions, they should follow the sequence of 'stop loss—collect evidence—appeal': immediately freeze or report the card lost through customer service or the app; as soon as possible, make inquiries, withdrawals, or POS purchases at domestic ATMs and keep receipts to prove the card never left their possession; then file a fraud investigation with the bank and report to public security authorities. Transaction receipts, statements and alert screenshots, customer service communication records, police report receipts, and entry/exit or travel documents should all be preserved."