We use essential cookies to make this site work. No tracking or advertising cookies are used. Cookie policy

Skip to main content
Back to Insights
Industry News

Mastercard's Generative AI Can Now Predict Full Compromised Card Numbers Before Fraudsters Use Them

Mastercard has deployed generative AI that reconstructs compromised card numbers from partial data, stopping fraud before it happens. Here is what it means for UK merchants.

29 September 2026
10 min read
Share:

Mastercard's Generative AI Can Now Predict Full Compromised Card Numbers Before Fraudsters Use Them

Fraud does not announce itself. A stolen card number sits quietly on a dark web marketplace for weeks, sometimes months, before a criminal decides to use it. By the time the transaction fires, the damage is already done: the chargeback lands on your account, the goods are gone, and your payment processor flags your business for elevated risk. For UK merchants already operating on thin margins, a single successful fraud event is not just a financial loss; it is a paperwork spiral that can take weeks to resolve.

Mastercard is now doing something that, until recently, belonged firmly in the realm of science fiction. Its generative AI system can reconstruct a full, compromised card number from the scattered, partial digits that typically circulate on criminal networks. It identifies the card before the fraudster does. That is not a marketing claim. It is a meaningful shift in how payment security works, and UK businesses need to understand what it actually means for them.

The Problem With How Fraud Has Always Been Caught

Traditional fraud detection is reactive by design. A transaction occurs, algorithms assess whether it looks suspicious based on historical patterns, and if it clears, the merchant gets paid. If the fraud is confirmed later, the chargeback arrives. The merchant loses the goods, the revenue, and often pays an additional dispute fee on top.

Even more sophisticated real-time fraud scoring tools, which assess velocity, geolocation, device fingerprinting, and behavioural signals, are fundamentally responding to an event that is already in motion. The card has already been stolen. The criminal already has enough data to attempt a transaction. The question has always been whether the system catches them in the act.

Mastercard's generative AI flips this logic. Instead of waiting for a fraudulent transaction to occur, it works upstream, at the point where compromised card data appears in the wild.

How the Technology Actually Works

When payment card data is stolen, whether through a merchant breach, a phishing campaign, or a skimming device, it rarely circulates in complete form. Criminals trade partial card data: sometimes the first six digits (the bank identification number), sometimes partial middle sequences, sometimes the last four combined with an expiry date. Complete card numbers are more valuable and command higher prices on dark web forums, but partial data is abundant and cheap.

Historically, banks and card networks monitored these marketplaces for compromised card data but could only act when they found a match to a card they already knew was stolen. Partial data was largely useless for preventive action.

Mastercard's generative AI changes this by treating the reconstruction of a card number as a pattern-completion problem. The model has been trained on the mathematical relationships between card number structures: the Luhn algorithm that governs valid card numbers, the issuer identification patterns embedded in BIN ranges, and the statistical relationships between partial sequences and the full numbers they belong to. When it encounters fragmented compromised data, it generates the most probable complete card numbers that match the partial information.

The company reports that this approach has doubled its ability to detect compromised cards in real time, and that it has increased the speed of detection by a factor of ten. According to Mastercard, the system scans approximately 125 billion transactions annually and can now identify a compromised card an average of 50 days earlier than previous methods allowed.

That 50-day window is the critical figure. In a typical fraud lifecycle, a stolen card sits dormant for weeks before use. Catching it in that dormant period, before a single fraudulent pound is spent, is the outcome that changes the economics entirely.

What Happens When the AI Identifies a Card

When the system reconstructs a likely compromised card number, it does not automatically block the card. That would create an unacceptable false-positive rate and would block legitimate cardholders from spending. Instead, the card is flagged within Mastercard's network and the relevant issuing bank is notified.

The bank can then assess the flagged card against its own data, apply additional monitoring, contact the cardholder proactively, or issue a replacement card before any fraud attempt occurs. The cardholder might receive a call or message asking whether they have used their card on a particular website recently, a familiar experience that now has a more sophisticated engine behind it.

For merchants, this is largely invisible in the daily operation of the terminal or payment gateway. But the downstream effect is significant: fewer stolen cards successfully complete transactions, which means fewer chargebacks reaching merchant accounts.

The UK Context: Why This Matters Here Specifically

The United Kingdom has one of the highest rates of card fraud among developed economies. UK Finance reported that card fraud losses totalled £376.5 million in 2023, with remote purchase fraud (card-not-present, the type most common in e-commerce) accounting for the overwhelming majority. That figure represents a persistent and structurally embedded problem that has resisted easy solutions for over a decade.

The UK's high card usage rate, combined with a sophisticated but fragmented e-commerce ecosystem and a large volume of cross-border transactions, creates ideal conditions for card fraud to thrive. British consumers make more card payments per capita than almost anywhere in Europe, and British businesses, particularly small and medium-sized enterprises, absorb a disproportionate share of the fraud losses that result.

The Payment Systems Regulator has been pushing hard on fraud liability frameworks, and the recent changes to authorised push payment fraud reimbursement rules have dominated headlines. But card fraud, particularly card-not-present fraud, remains a cost that sits primarily with merchants and issuers, not with consumers who are largely protected by their bank's chargeback rights.

Any technology that reduces the volume of compromised cards successfully used in transactions reduces that cost at its source.

Practical Implications for UK SME Merchants

If you run a business that accepts card payments, particularly online, here is how to think about what this development means in practical terms.

You will not see this in your dashboard. Mastercard's AI operates at the network and issuer level. Your payment terminal, gateway, or processor does not surface this directly to you. The benefit arrives as a reduction in fraudulent transactions reaching your account, not as a new feature you can toggle on.

It complements, but does not replace, your own fraud controls. If you accept online payments, you should still be running 3D Secure authentication, address verification, and CVV checks. Mastercard's system catches compromised cards before they are deployed; your own controls are the last line of defence when a criminal has a complete, valid card number that has not yet been identified by the network. Both layers need to be active.

Chargebacks should reduce over time, but monitor your data. If your business processes a significant volume of card-not-present transactions, track your chargeback rate quarterly. As generative AI fraud detection matures and scales, the industry expects a measurable reduction in card-not-present fraud rates. If your rates are not moving in that direction over the next 12 to 18 months, it is worth auditing your own fraud stack.

This does not protect against account takeover fraud. Mastercard's AI reconstructs compromised card numbers from partial data. It does not address the separate problem of account takeover, where a criminal gains access to a legitimate customer's online account and uses their saved payment method to make purchases. That threat vector requires different controls, including step-up authentication and behavioural biometrics at the application layer.

High-value merchants should pay particular attention. If your average transaction value is high, whether you run a camera shop, a bespoke furniture business, a jeweller, or any other premium retail operation, you are a more attractive target for card fraud. The economics favour criminals attempting high-value transactions. Faster identification of compromised cards is disproportionately valuable for businesses where a single fraudulent order represents a meaningful sum.

The Bigger Picture: Generative AI as a Defensive Tool

Most public conversation about generative AI in financial services focuses on the offensive uses: AI-generated phishing emails, synthetic identity fraud, deepfake voice calls impersonating bank customers. These are real and growing threats. But Mastercard's deployment is a reminder that the same generative capabilities that make AI powerful for attackers are equally powerful for defenders.

Pattern completion, probabilistic reconstruction, and the ability to infer structure from incomplete data are not inherently offensive capabilities. Applied to compromised payment data, they become a predictive shield. The race between AI-powered fraud and AI-powered fraud prevention is now genuinely competitive in a way it was not three years ago.

The BIS Committee on Payments and Market Infrastructures noted in its 2023 report on payment system innovations that machine learning applications in fraud detection were producing measurable improvements in detection rates across multiple major economies. Mastercard's generative AI represents a significant step beyond what that report was describing: from pattern recognition to generative inference.

One Number That Sums It Up

50 days. That is the average head start Mastercard's system now has on fraudsters who acquire partial card data. In payment fraud terms, 50 days is the difference between a compromised card being cancelled before a single transaction clears and a criminal running up thousands of pounds in fraudulent purchases across multiple merchants before anyone acts.

For UK merchants, that head start belongs to the network and the issuing banks. Your job remains ensuring your own controls are sharp. But knowing that the upstream infrastructure is getting smarter, faster, and more predictive should give you some confidence that the systemic fraud burden on UK commerce is, slowly, being pushed back.


Klipy helps UK businesses manage their payment costs with clarity and control. If you want to understand how your current card acceptance setup affects your fraud exposure and processing fees, we are here to help.

Sources

  1. Mastercard official press release on Decision Intelligence Pro and generative AI fraud detection: https://www.mastercard.com/news/press/2024/february/mastercard-uses-generative-ai-to-help-banks-combat-fraud/
  2. UK Finance Annual Fraud Report 2024 (reporting on 2023 data), card fraud losses of £376.5 million: https://www.ukfinance.org.uk/system/files/2024-05/Annual-Fraud-Report-2024.pdf
  3. BIS CPMI report on innovations in payments and financial market infrastructures, machine learning fraud detection section (2023): https://www.bis.org/cpmi/publ/d218.htm
  4. Payment Systems Regulator (PSR) work on fraud liability and APP fraud reimbursement framework: https://www.psr.org.uk/our-work/app-scams/
  5. Luhn algorithm technical background for card number validation (standard reference): ISO/IEC 7812
  6. PYMNTS.com coverage of Mastercard Decision Intelligence Pro deployment scale and detection improvement claims: https://www.pymnts.com/mastercard/2024/mastercard-generative-ai-tool-twice-as-effective-at-detecting-compromised-cards/
  7. The Paypers coverage of AI-powered fraud detection trends in European payments (cross-reference for context): https://thepaypers.com

Disclaimer

The views and information shared in this post are for educational and informational purposes only and do not constitute financial, legal, or professional advice. While every effort is made to ensure accuracy, Klipy UK Limited accepts no liability for decisions made based on this content. Payment processing rates, regulations, and product features referenced are subject to change. Klipy UK is an authorised seller of Teya payment solutions. Where third-party sources are cited, links are provided for reference; Klipy UK does not endorse or guarantee the accuracy of external content. For personalised guidance on your business payment needs, please contact us directly at editor@klipy.uk.

Found this helpful? Share with your network:

This content is published by Klipy UK, a Teya-authorised reseller of payment solutions. The views expressed are for informational purposes only and do not constitute financial advice. All content is the intellectual property of Klipy UK. Reproduction without permission is prohibited.

Ready to Compare Your Rates?

See exactly how much you could save. Upload your statement or enter your monthly turnover-instant results, no obligation.

Try Calculator