Arrow-right Camera
The Spokesman-Review Newspaper
Spokane, Washington  Est. May 19, 1883

Mastercard wants to get rid of card numbers for online shopping

Mastercard cards are arranged for this undated photo. It’s stock went up 23% in 2023.  (Andrew Harrer/Bloomberg)
By Aisha S Gani Bloomberg

Mastercard Inc. is expanding its efforts to eliminate the use of credit card numbers when customers make purchases online in a bid to fight fraud.

A decade after it first unveiled a technology that replaces consumers’ card numbers with so-called tokens, the company is now processing 1 billion such transactions every week, Chief Executive Officer Michael Miebach said in an interview. That’s after it took the payments behemoth three years to process the first billion of such transactions.

Now, Mastercard is planning to expand the use of the technology to replace security measures like passwords with biometric data such as fingerprints or face scans, Miebach said. It’s the latest step that the financial industry is taking to combat the rising issue of online payment fraud, which is expected to exceed $91 billion by 2028.

A decade ago, the common thinking was “if you want to keep it safe, protect data and protect transactions through passwords,” Miebach said at Mastercard’s London offices. “That worked for a while. And then it started to become the vulnerability instead of effective safety and security.”

Mastercard and rival Visa Inc. first introduced token technology about a decade ago after fraudsters had targeted the payment systems of retailers including Target Corp. and Best Buy Co., absconding with tens of millions of consumers’ credit card information. At first, the technology was focused on replacing card numbers with a token that only the networks can unlock, meaning it’s useless if a hacker does get their hands on it.

Fueled by payment services such as Apple Pay, that helped reduce fraud for in-store purchases. Now, though, criminals are targeting e-commerce sites that require consumers to manually put in their card information to make a purchase.

Increasingly, hackers are also targeting websites in places including India that rely on one-time passwords to help with security. These passwords - which retailers and banks send to consumers in order to authenticate their identity - have grown increasingly vulnerable to fraudsters, Miebach said.

Mastercard will partner with banks and payment providers around the world to replace these one-time passwords with a token based on consumers’ biometric information. It introduced the service in India this week after inking partnerships with PayU and banks including Axis Bank Ltd.

“The source of the problem was that if the data was exposed and somebody penetrated and got into that data, they could use it,” Miebach said. “The digital economy - what is the one thing that’s holding it back? It’s the risk of data breaches of fraud and so forth. And tokenization is a big lever to curb those.”

Mastercard has said it expects all e-commerce transactions to be tokenized in Europe by the end of the decade.