Identity & access

Banking data leaks

We detect your cards for sale on illicit markets, recognised by your BINs, and the cards and accounts of the people in your perimeter found in stealer logs and leaks.

Territory: Identities and access Organisation or person

The problem

A stolen payment card is resold in batches sorted by issuer: the first digits, the BIN, say which bank, fintech or retailer issued it. The batch circulates for days before the first dispute, and the issuer learns of it from its customers. On the other side, a stealer log or a database leak holds the cards and accounts your employees and customers saved in their browser. Our collection partners see those batches and logs as soon as they circulate; what is missing is the match against your BINs and your people.

Client area preview

What you see

Fictional data, for illustration only: no client, no real data.

What you get: the batches carrying your BINs and the cards of your perimeter, masked, with the source, the date and the status, revealable on demand.

  1. 01

    The batches of cards for sale that carry your BINs, with the marketplace, the date, the announced volume and the cardholders’ country when stated

  2. 02

    The cards and bank account numbers of the people in your perimeter found in stealer logs and leaks, masked, with the source, the date and the device they came from

  3. 03

    The status of every card: to block, blocked, issuer notified, dispute opened, and the export for your fraud team

A limit stated plainly · A card seen in a batch or a log has not necessarily been used: we say that it circulates, where and since when, never that a fraud took place.

How it works

Our answer in three steps

VesperID matches every batch put up for sale against your declared BINs and every stealer log or leak against the people in your perimeter, shows every card masked, revealable on demand under journal, and hands you the playbook: block the card, notify the issuer, open the fraud process.

  1. 01

    You declare your BINs if you issue cards, as a bank, a fintech or a retailer with its own card, and your domains and people for the cards and accounts of your perimeter.

  2. 02

    Our collection partners follow the card marketplaces and acquire stealer logs and leaks as soon as they circulate; the platform matches every batch against your BINs and every record against your people, without keeping any full number.

  3. 03

    An analyst qualifies the credible batches, discards old relistings and sends the alert with the playbook: block, notify the issuer, open the fraud process.

Where this data comes from

Batches come from the card marketplaces followed by our partners’ analysts, closed spaces included; the cards and accounts of people come from the stealer logs and leaks acquired as soon as they circulate. VesperID matches, masks and keeps no full number.

Our sources in detail

Cross analyses

What the platform computes on top

This service’s data is crossed with the others’: here are the analyses that come out of it, all visible in the client area.

Discover the platform
  1. 01

    Prioritisation

    A fresh batch carrying your BIN ranks above an old card from a compilation: severity, freshness, announced volume and criticality rank the queue.

  2. 02

    Chain from the infected device

    A card captured by an information stealer is tied to the infected device and to the credentials of the same log: the chain links the device, the accesses and the card, with the isolation playbook.

  3. 03

    “Card exposure” playbook

    Block the card, notify the issuer, open the fraud process, document the dispute: the steps in the order in which they cut the exposure.

What you receive

Banking data leaks

  1. 01

    One alert per batch for sale and per card or account found, with the expected action

  2. 02

    Table of exposed cards, masked, revealed on demand under journal, CSV export for the fraud team

  3. 03

    “Card exposure” playbook: blocking, notifying the issuer, fraud process and dispute

  4. 04

    Monthly follow-up of batches, blocked cards and the time between listing and blocking

Frequently asked questions

  • Do you keep the card numbers?

    No. We keep the BIN, the last four digits, the source, the date and the status; the full number is never written to our database. It is revealed on demand, after re-authentication, with a reason, within twenty reveals per person per day, and every reveal is written to the journal.

  • Has a card seen in a leak been used?

    We do not know, and we do not say so: we record that it circulates, where and since when. The safe answer remains blocking and reissuing the card, notifying the issuer and opening the fraud process; the record gives you the dated elements for the dispute.

  • How is this service priced?

    Like every service of the catalogue, on an annual licence: a price per declared identifier (a BIN, a person) and a flat annual detection fee, each on its own line of the proposal, never a bundle. The price is given on quote.

Request an exposure assessment.

One hour with an analyst, not a demo: what already circulates about your organisation, what to monitor, what is better left alone. Reply within 24 h.

No public price list: bespoke offering, written proposal after scoping.