Last reviewed: September 29, 2026. Card network rules and prefix ranges change over time. For anything that affects a real system, check the current rules published by the card network or standards body.
Short answer: A credit card number is called a Primary Account Number, or PAN. Its structure is set by an international standard, ISO/IEC 7812. The first digit is the Major Industry Identifier. The first six or eight digits are the Issuer Identification Number (usually called the BIN), which shows which network and which bank issued the card. The digits after that identify one account. The last digit is a check digit, calculated with the Luhn formula, which catches most typing mistakes. Card numbers can be 12 to 19 digits long, although 15 and 16 are the most common. The number alone is not the whole story: the expiry date, the security code, chip cryptograms and tokens all do their own jobs.
A card number looks random. It is not. Every digit sits in a slot with a specific purpose, shaped by rules that the card networks and the International Organization for Standardization (ISO) have refined over decades. Knowing that structure helps consumers understand what is safe to share, helps merchants understand declines, and helps developers build checkout forms that catch typos before a payment request is ever sent.
This article is general educational information, not legal, security or financial advice.
In this guide
- What a card number really is: the PAN
- The ISO/IEC 7812 structure
- The first digit: the Major Industry Identifier
- The BIN or IIN: 6 digits versus 8 digits
- Network prefixes and card lengths
- The middle digits: the account identifier
- The check digit and how it catches typos
- Expiry date, cardholder name and security codes
- Magnetic stripe, EMV chip and contactless
- Why numbers change on reissue, and card vs account numbers
- Virtual card numbers and network tokens
- How card numbers are printed
- What is safe to share and what never is
- Masking and storage rules under PCI DSS
- How card numbers get stolen, and how to protect yourself
- What to do if your card number is compromised
- Common myths about card numbers
- FAQ
- Sources
What a card number really is: the PAN
In the payments industry, the long number on your card is called the Primary Account Number, or PAN. You will see the term in card network rules, in the Payment Card Industry Data Security Standard (PCI DSS), and in almost every technical payments document.
The PAN has one main job: to identify a payment account so a transaction can be routed to the right place. When you pay a shop, the shop's payment provider (the acquirer) needs to know which network should carry the request and which bank (the issuer) should approve or decline it. The PAN answers both questions, and it tells the issuer which account to charge.
It helps to think of a PAN as an address, not a password. An address tells a letter where to go. It does not prove the sender is allowed to send it. That is why modern payments add other checks on top of the number: the expiry date, the security code, the chip cryptogram, tokens, and authentication steps such as 3-D Secure. Each covers a weakness of the others.
The same structure is used for credit, debit, prepaid and charge cards, so almost everything in this article applies to all of them.
The ISO/IEC 7812 structure
Card numbers follow ISO/IEC 7812, "Identification cards: Identification of issuers". Part 1 describes the numbering system and Part 2 describes how issuers apply for and register numbers. The current edition of Part 1 was published in 2017, and it made one major change: it lengthened the issuer identifier from six digits to eight.
Under the standard, a card number has three logical parts:
- The Issuer Identification Number (IIN). The leading digits, identifying the organization that issued the card. Its first digit is the Major Industry Identifier (MII).
- The individual account identification. A variable-length block assigned by the issuer to one account.
- The check digit. One final digit calculated from all the digits before it, used to detect errors.
The standard allows a total length of up to 19 digits. Card networks then set their own rules within that limit, which is why a checkout form cannot simply demand "16 digits". Here is how a typical 16-digit number breaks down:
| Position | Part | What it does |
|---|---|---|
| Digit 1 | Major Industry Identifier (MII) | Broad industry category, for example banking and financial |
| Digits 1 to 8 (1 to 6 on older ranges) | Issuer Identification Number (IIN / BIN) | Identifies the network, the issuer and often the card product |
| Digits 9 to 15 (or 7 to 15) | Individual account identifier | Points to one specific account at the issuer |
| Digit 16 (last digit) | Check digit | Calculated with the Luhn formula to catch typing errors |
On a 15-digit or 19-digit card the logic is the same. The IIN stays at the front, the check digit stays at the end, and the account identifier grows or shrinks in the middle.
The first digit: the Major Industry Identifier
The first digit of a card number is the Major Industry Identifier. It was designed to show, at a glance, which broad industry issued the card. The categories come from ISO/IEC 7812:
| First digit | ISO/IEC 7812 category | What you usually see |
|---|---|---|
| 0 | ISO/TC 68 and other industry assignments | Rare on consumer cards |
| 1 | Airlines | Some airline cards (for example, UATP) |
| 2 | Airlines, financial and other future assignments | Mastercard 2-series, Mir |
| 3 | Travel and entertainment | American Express, Diners Club, JCB |
| 4 | Banking and financial | Visa |
| 5 | Banking and financial | Mastercard, some Maestro ranges |
| 6 | Merchandising and banking/financial | Discover, UnionPay, RuPay, some Maestro ranges |
| 7 | Petroleum and other future assignments | Some fuel cards |
| 8 | Healthcare, telecommunications and other future assignments | Some domestic schemes |
| 9 | For assignment by national standards bodies | National or private-label schemes |
The MII is a clue, not a verdict. American Express starts with 3 because it began as a travel and entertainment card. Mastercard added a range starting with 2 when its 5-series ran short of space. Discover, UnionPay and RuPay all use parts of the 6-series. Never decide a card's brand from the first digit alone.
The BIN or IIN: 6 digits versus 8 digits
The leading digits are officially the Issuer Identification Number (IIN), but most people still call them the Bank Identification Number (BIN). The two terms mean the same thing. The BIN tells a payment system:
- Which network the card belongs to, such as Visa, Mastercard or American Express.
- Which institution issued it, so the authorization request goes to the right bank.
- Often, which product it is. One bank may have separate ranges for consumer credit, debit, business, prepaid and premium cards.
Why the BIN grew from 6 to 8 digits
For most of card history the IIN had six digits, allowing up to one million prefixes. With thousands of banks, fintechs and card programs each needing several ranges, supply ran low. The 2017 edition of ISO/IEC 7812-1 extended the IIN to eight digits, multiplying the space by 100. The major networks set April 2022 as the target date for the industry to handle 8-digit BINs.
Two points matter. First, card length did not change: the two extra BIN digits come out of the account identifier, not from a longer number. Second, older 6-digit BINs still exist, so systems now need to read the first eight digits to be sure of the issuer and product.
What it means for developers and merchants
BIN tables, routing logic and fraud rules keyed on six digits may need to read eight. Masking rules that used to show "first six and last four" also interact with longer BINs, which we cover in the PCI DSS section. For merchants, the BIN is an early fraud signal: a card issued in one country on an order where every other signal points elsewhere may deserve a closer look. Our guide to card-not-present fraud prevention for small merchants shows how BIN data fits into a sensible fraud process.
Network prefixes and card lengths
Each network owns specific prefix ranges, so a checkout form can read the first few digits and tell which network a card belongs to. That lets it show the right logo, format the number correctly, and expect the right length and security-code length.
The table lists commonly published ranges. It is a learning aid, not an official registry. Networks add and reassign ranges, and some are co-branded. For production systems, follow your payment processor's or the network's current documentation.
| Network | Commonly published starting digits | Typical length | Security code |
|---|---|---|---|
| Visa | 4 | 16 (most cards); 13 on some old cards; up to 19 on some products | 3 digits (CVV2), back |
| Mastercard | 51 to 55, and 2221 to 2720 (the "2-series") | 16 | 3 digits (CVC2), back |
| American Express | 34, 37 | 15 | 4 digits (CID), front |
| Discover | 6011, 644 to 649, 65 (plus some co-branded 622 ranges) | 16 to 19 | 3 digits (CID), back |
| Diners Club International | 36, 300 to 305, 3095, 38, 39 | 14 to 19 (14 is classic) | 3 digits, back |
| JCB | 3528 to 3589 | 16 to 19 | 3 digits (CAV2), back |
| UnionPay | 62 | 16 to 19 | 3 digits (CVN2), back |
| Maestro | Various, including 50, 56 to 58 and some 6 ranges | 12 to 19 | Often 3 digits; some cards have none |
| RuPay (India) | 60, 65, 81, 82, 508 (plus co-branded ranges) | 16 | 3 digits, back |
| Mir (Russia) | 2200 to 2204 | 16 to 19 | 3 digits, back |
Notes on the table
- Mastercard's 2-series. Mastercard began issuing 2221 to 2720 cards in 2017. Old forms that only accept Mastercard numbers starting with 5 wrongly reject them, which is still a common bug.
- Discover, Diners Club and UnionPay. Discover acquired Diners Club International in 2008, and many Diners cards run on the Discover network. Discover and UnionPay also have acceptance agreements, so some 62 ranges route over Discover in the US.
- Maestro. Mastercard has been moving European issuers from Maestro to Debit Mastercard, so new Maestro cards are becoming rare. It remains the classic example of a card as short as 12 digits.
- Overlaps. Some ranges are shared or co-branded (65 appears for both Discover and RuPay in different contexts). Precise detection needs a current BIN table.
The practical rule for forms: accept 12 to 19 digits, strip spaces and dashes, and let brand detection decide which lengths are valid for that card.
The middle digits: the account identifier
After the BIN come the digits that identify the individual account. With an 8-digit BIN on a 16-digit card, seven account digits remain (positions 9 to 15). With a 6-digit BIN, nine remain.
The issuer decides how to use these digits, and the standard does not say what they mean to the outside world. Some issuers assign numbers in sequence; others use internal schemes. Three things are worth knowing:
- They contain no personal information. The number does not encode your name, date of birth, Social Security number, credit limit or credit score.
- They are not your bank account number. The issuer links the card to the underlying account in its own systems.
- They are the part that must stay secret. The BIN is shared by many cards and the last four digits appear on receipts. The middle digits make your card unique, which is why PCI DSS focuses on hiding them.
The check digit and how it catches typos
The last digit of a card number is a check digit, calculated from all the other digits using the Luhn formula (also called "mod 10"), as specified by ISO/IEC 7812. When someone types a card number, the form can run the same formula. If the result is wrong, the number cannot be valid, and the form can ask the person to check it, instantly and without any network request.
The formula catches the mistakes humans make most often: every single-digit error (typing 7 instead of 1) and most swaps of two neighboring digits (typing 34 instead of 43; the known exception is swapping 09 and 90). We explain the method, its history and its limits in our dedicated article: What Is the Luhn Algorithm and How Does It Validate Card Numbers?
What the check digit does not do
The check digit is an error-detection tool, not a security feature. Passing it only means a number is well-formed. It does not mean the card exists, the account is open, there is credit available, or the person typing it is the cardholder. Only the issuer can answer those questions, through an authorization request over the card network. A public formula cannot protect anything, and it was never meant to. Its job is to stop obviously mistyped numbers from being sent at all.
Expiry date, cardholder name and security codes
The expiry date
The expiry date is printed as MM/YY, and the card is valid through the last day of that month. It is stored by the issuer alongside the account and is not calculated from the card number. Online checkouts ask for it because a correct expiry is one more sign that the person paying really has the card details.
Cards expire because chips and surfaces wear out, because newer cards can carry updated security features, and because it gives the issuer a natural point to review the account. On renewal, many issuers keep the same number and change only the expiry date and security code; others issue a new number.
The cardholder name
The name printed on the card is also stored in the magnetic stripe's Track 1 and in the chip. Online, many merchants ask for it, but it is generally a weaker check than the expiry date or security code, because issuers do not always verify the exact spelling. Business cards may show both a person's name and the company name.
The different names for the printed code
The short code printed on the card has different names by network: CVV2 (Visa), CVC2 (Mastercard), CID (American Express and Discover), CAV2 (JCB) and CVN2 (UnionPay). They all do the same job: prove that the person paying online or by phone has seen the physical card. American Express prints a 4-digit code on the front; most others print 3 digits on the back.
CVV1, CVV2, iCVV and dynamic codes compared
| Code | Where it lives | Used for | Why it exists |
|---|---|---|---|
| CVV1 / CVC1 | Encoded in the magnetic stripe | In-person swipe transactions | Helps detect a stripe built from a card number alone |
| CVV2 / CVC2 / CID | Printed on the card | Online, phone and mail-order payments | Not in the stripe, so a skimmed stripe does not reveal it |
| iCVV (chip CVV) | Inside the chip's stripe-equivalent data | Chip transactions | Differs from CVV1, so chip data copied onto a fake stripe fails |
| Dynamic CVV | A small display on the card, or shown in an app | Online payments | Changes regularly, so a stolen code soon stops working |
| Chip cryptogram (ARQC) | Generated fresh by the chip each time | Chip and contactless payments | A one-time value that cannot be reused |
The design idea is separation. Each value sits in a different place, so stealing one type of data does not give a criminal everything. A stripe skimmer gets CVV1 but not CVV2. A fake website that captures CVV2 does not get the chip's secret keys.
Security codes are calculated by the issuer from card data and secret keys only the issuer (or its processor) holds. They cannot be worked out from the card number. That is also why PCI DSS forbids merchants from storing the printed code after authorization, even encrypted.
A few issuers have launched or trialed cards with a tiny display showing a code that changes periodically, or they show a changing code in their app. Even if a website leaks your details, the code will have changed by the time a criminal tries it. These cards remain uncommon, and availability varies by country.
Magnetic stripe, EMV chip and contactless
Your card number is also stored electronically, and how it is stored decides how easy it is to copy.
What is on the magnetic stripe
A payment card's stripe holds two tracks that matter for payments:
- Track 1 holds letters and numbers: the card number, cardholder name, expiry date, a service code, and issuer discretionary data including CVV1.
- Track 2 holds only numbers: the card number, expiry date, service code and discretionary data including CVV1. Most terminals rely on Track 2.
The three-digit service code tells the terminal how the card may be used, for example whether it has a chip that should be used instead of the stripe, and whether a PIN is required.
The stripe's weakness is that its data is static. The same information is read every swipe, so a skimmer can copy it onto a blank card. That is exactly the fraud chip cards were built to stop. Mastercard has announced a gradual phase-out of the magnetic stripe on its cards, and in many countries swiping is already rare.
How the EMV chip is different
The chip follows specifications managed by EMVCo, the technical body owned by the major networks. It is a tiny secure computer holding cryptographic keys that cannot be read out in normal use.
When you pay by chip, the terminal sends transaction details, including the amount and an unpredictable number. The chip uses its secret key to produce an Application Cryptogram (called the ARQC in authorization requests), which also reflects a counter that rises with each transaction. The issuer checks it with its own copy of the keys. The result is valid for one transaction only: an intercepted cryptogram cannot be reused, and a new one cannot be created without the chip's keys.
The chip still holds the card number, because the network needs it for routing. But the number alone is not enough to create a valid chip transaction. That is the "address, not password" idea in action.
Contactless
Contactless cards contain the same kind of chip plus an antenna. Tapping uses short-range radio under the ISO/IEC 14443 standard and EMVCo's contactless specifications, designed to work over only a few centimeters. Each tap produces a fresh one-time cryptogram, so data captured from one tap cannot be turned into a working clone.
Countries and issuers set limits on how much you can spend by tapping without a PIN, and the card may occasionally ask for a PIN even below the limit as an extra check. These limits vary by country and change over time.
Paying with a phone or watch is also contactless, but with an extra layer: the device normally uses a token instead of your real card number, as explained below.
Why numbers change on reissue, and card vs account numbers
A replacement card often arrives with a completely different number. Common reasons include:
- Lost or stolen card. The old number is blocked forever and a new one is issued.
- Suspected compromise. Banks sometimes reissue proactively after a merchant breach or suspicious activity, even if you have seen no fraud.
- Product change. Upgrading or downgrading may move you to a different BIN range.
- Issuer or network change. When portfolios move between banks or networks, customers typically get new numbers.
- Expiry. Some issuers keep the number on renewal; others do not.
A new number does not usually mean a new account. Your balance, payment history, limit and rewards normally stay with the underlying account, and for credit reporting the account typically continues as the same tradeline. That matters for the age of your credit history, as our explainer on how credit scores are calculated explains.
Card numbers versus account numbers
The card number and the account number are related but different. The card number identifies a card credential; the account number identifies the actual credit, debit or prepaid account behind it. One account can have many card numbers: authorized user cards, virtual cards and device tokens all point to the same account. The card number often changes on replacement; the account number usually does not.
This also means a debit card number is not your bank account number. Your bank account has its own number, plus a routing number, sort code or IBAN depending on the country. You cannot use a debit card number to set up a bank transfer, or the other way round.
The downside of a new card number is updating subscriptions and saved cards. Network "account updater" services and tokenized wallets reduce that work, because a token can stay the same when the card behind it changes. Not every merchant uses them, so check important bills yourself.
Virtual card numbers and network tokens
Because a card number is only a pointer, other numbers can point to the same account. The industry uses this in two ways.
Virtual card numbers
A virtual card number is a full card number, with its own expiry date and security code, issued for online use. It follows the same ISO/IEC 7812 structure, so merchants accept it like any card. Depending on the provider, it may be single-use, locked to the first merchant that charges it, limited by amount or time, or easy to pause and delete in an app. If a merchant holding it is breached, you delete that number and your main card keeps working. Our guide to the best virtual cards for online payments compares options.
Network tokenization
A payment token is a surrogate number that replaces your real card number in a specific context. The framework is EMVCo's EMV Payment Tokenisation Specification. Visa runs the Visa Token Service, Mastercard runs the Mastercard Digital Enablement Service (MDES), and other networks have their own services.
Tokens look like card numbers, with the same length and structure, so they flow through existing systems. But they carry restrictions called domain controls: a token may work only on one device, only at one merchant, or only for one type of transaction. If it is stolen and used outside that domain, the network can reject it.
How Apple Pay and other wallets use tokens
When you add a card to Apple Pay, your card number is not simply copied to the phone. The network and issuer create a Device Account Number (often called a DPAN), a token specific to that device. According to Apple's platform security documentation, it is stored in the device's Secure Element, and Apple does not store your actual card number on the device or its servers.
At checkout, the phone sends the Device Account Number plus a one-time dynamic security code for that transaction. The merchant sees the token, not your real number. The network maps the token back to your real card number (sometimes called the funding PAN, or FPAN) before sending the request to your issuer. Google Wallet and Samsung Wallet use a similar token approach. You can often see that the last four digits in your wallet differ from those on your plastic card, a visible sign that the phone is not using your real number.
For merchants, storing tokens instead of PANs limits breach damage and helps subscriptions survive card reissues. Payment providers also offer their own "vault" tokens, which differ from network tokens but serve a similar purpose: your server keeps a reference, not the card number.
How card numbers are printed
Embossed cards
For decades, card numbers were embossed, raised in the plastic, so manual imprint machines could press them through carbon paper. Those machines have almost disappeared, and embossing is becoming less common.
Flat-printed cards
Many modern cards print or laser-engrave the number flat. This is cheaper, durable and allows cleaner designs. It also makes it practical to put the number on the back, where it is less visible when the card is on a table or in someone's hand.
Numberless cards
Some issuers now offer cards with no number printed at all. You view the number, expiry and security code in the issuer's app after unlocking it with a fingerprint, face or passcode. This reduces shoulder surfing and makes a lost card less useful to a finder. The trade-off is depending on your phone to see your details.
Portrait (vertical) cards
Networks have updated their brand rules to permit vertical designs, and a growing number of cards are printed in portrait orientation, matching how people actually insert and tap cards. Orientation does not change the number, the chip or how the card works.
What is safe to share and what never is
| Piece of data | Risk level | Guidance |
|---|---|---|
| Last 4 digits | Low | Normally fine to share to identify which card you mean. They appear on receipts. |
| Card brand | Low | Fine to share. |
| First 6 or 8 digits (BIN) | Low to moderate | Not secret, but no reason to share casually. With the last 4, it narrows down the full number. |
| Full card number | High | Only when you are paying, through a checkout you trust or a merchant you contacted. |
| Expiry date | High with the number | Only in trusted checkouts. |
| Security code | Very high | Only in a checkout you started yourself. Never by email, chat or text. |
| PIN | Critical | Never share with anyone, including your bank. |
| One-time passcodes from your bank | Critical | Never read out or forward to someone who contacted you. It is often the last step in a scam. |
Never post a photo of your card online. Even a partly covered image can reveal enough.
Your bank's fraud team may mention the last four digits and ask you to confirm transactions, but a genuine bank will not ask for your PIN or a one-time passcode on a call it started. A merchant may take full card details by phone for an order, but only when you called a number you found yourself. Nobody legitimately needs photos of both sides of your card over email or messaging apps.
Masking and storage rules under PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) applies to organizations that store, process or transmit card data. It is maintained by the PCI Security Standards Council, founded by the major card networks. Version 4.0.1 is current, and the requirements that version 4.0 marked as "future-dated" became mandatory on March 31, 2025.
PCI DSS separates two kinds of data. Cardholder data is the PAN, plus the cardholder name, expiry date and service code when stored with it. Sensitive authentication data is full track data from the stripe or chip, the card security code, and PINs or PIN blocks.
Key rules in simple terms
- No sensitive authentication data after authorization. Merchants may never keep the security code, full track data or PIN once a payment is authorized, even encrypted. That is why a genuine merchant asks for your code again or uses a token.
- Mask the PAN when displayed. Requirement 3.4.1 says the BIN and last four digits are the most that may be displayed, unless someone has a documented business need to see more. Many systems show only the last four.
- Make stored PANs unreadable, using strong cryptography, truncation, index tokens or properly controlled one-way hashes.
- Keep only what you need for legal, regulatory or business purposes.
Masking versus truncation
Masking hides digits on display while the full number may still exist in secure storage. Truncation permanently removes digits from the stored value. A receipt showing only the last four digits is truncation on paper.
With 8-digit BINs, showing the first eight and last four of a 16-digit number leaves only four digits hidden. The PCI Security Standards Council has published FAQs on how 8-digit BINs relate to masking and truncation and points organizations to each card brand's rules on acceptable truncation formats. If you design systems that display or store partial PANs, follow current PCI SSC guidance rather than old "first six, last four" habits.
For small businesses, the simplest way to reduce PCI DSS scope is to never touch raw card numbers. Hosted payment pages, embedded payment fields and tokenization send the number straight from the customer to the provider, and your systems only see tokens and the last four digits. Never ask customers to email card numbers, and never keep them on paper forms or in spreadsheets.
How card numbers get stolen, and how to protect yourself
Criminals rarely "guess" card numbers in any useful way. They take them from people, devices or databases.
Skimming
A skimmer is a device attached to an ATM, fuel pump or terminal that copies magnetic stripe data, often paired with a hidden camera or fake keypad to capture the PIN. "Shimmers" sit inside chip slots, but thanks to the cryptogram and iCVV, chip data is far less useful to criminals than stripe data. Use chip or contactless instead of swiping, check readers for loose parts or bulky slots, cover the keypad when typing your PIN, and prefer ATMs inside bank branches.
Phishing, smishing and fake calls
Phishing uses fake emails, texts, websites and calls to trick you into giving card details. Common stories include a "failed delivery" fee, an "unpaid toll", a "suspended account" or a "refund". Some callers pretend to be your bank's fraud team and ask you to "verify" your card, code or a one-time passcode. Do not click payment links in unexpected messages; go to the company's site or app directly. If someone calls claiming to be your bank, hang up and call the number on the back of your card. Many of the same red flags appear in our guides to avoiding loan scams and fake offers and spotting crypto scams.
Data breaches and web skimming
Card data can be stolen in data breaches at merchants and service providers, or by malicious code injected into a checkout page to copy details as customers type ("web skimming" or "formjacking"). PCI DSS 4.0 added requirements for managing and monitoring scripts on payment pages because of this threat. As a shopper, use a mobile wallet at checkout when offered so the merchant gets a token, use virtual numbers for unfamiliar shops, and avoid saving your card on every site.
Card-testing attacks
Once criminals have a batch of stolen numbers, they want to know which still work. In card testing, bots make many small purchases or authorization attempts on a merchant's site, often donation pages or cheap digital goods. Approved numbers are then sold or used for bigger fraud. A tiny, strange charge from an unknown merchant can be a sign your card is being tested, so report it. Merchants can fight back with rate limits, bot detection, address and security-code checks, and 3-D Secure; our card-not-present fraud guide covers the details.
Habits that help
- Turn on alerts for every transaction, or at least online and international ones.
- Review your statement monthly, even with autopay.
- Use strong, unique passwords and two-factor authentication on banking and shopping accounts.
- Keep your phone updated, since mobile wallets depend on device security.
- Where you can, use credit rather than debit online. In the US, credit cards generally carry stronger protections against unauthorized charges, and fraud does not drain your bank account while it is being resolved.
What to do if your card number is compromised
If you see unknown charges or think your details are exposed, act fast. Speed limits the damage and, in some cases, your legal liability.
- Lock or freeze the card in your banking app to stop new transactions.
- Contact your issuer using the number on the back of your card or the official app. Report the charges and ask for the card to be canceled and replaced.
- Review recent transactions, including tiny ones, and list everything you do not recognize.
- Update saved cards and subscriptions when the new card arrives.
- Change passwords on any account where the card was saved, especially if you entered details on a suspicious site.
- Watch for follow-up scams from people pretending to be your bank's fraud team.
- If you suspect wider identity theft, check your credit reports. In the US, the FTC's IdentityTheft.gov gives a personalized recovery plan, and you can consider a credit freeze.
Your liability in the US
According to the FTC, under the Fair Credit Billing Act your maximum liability for unauthorized credit card use is $50, and if only your card number was stolen (not the card itself), you have no liability for unauthorized use. The major networks also have "zero liability" policies for many cards, subject to conditions.
Debit cards fall under the Electronic Fund Transfer Act, where timing matters. The FTC explains that if you report before any unauthorized charges, you owe nothing; within two business days of learning of the loss or theft, your maximum loss is $50; after that but within 60 days of your statement being sent, up to $500; and after 60 days you could lose much more.
If your problem is a dispute with a merchant rather than fraud, the process is different. Our guide on how to dispute a credit card charge in the US and UK explains chargebacks and deadlines. Outside the US, rules differ; in the UK, for example, payment services rules generally limit a customer's liability for unauthorized payments to a small amount unless they acted fraudulently or with gross negligence. Check your issuer's terms and your national consumer agency.
Common myths about card numbers
Myth: "If a number passes the Luhn check, it is a real card."
False. The check digit only proves a number is well-formed. Many well-formed numbers belong to no account, and only the issuer can confirm one. Our Luhn algorithm explainer covers why the formula is about typos, not security.
Myth: "The card number contains my personal details."
False. It identifies an issuer and an account, nothing more. No name, birthday, address or credit score is encoded.
Myth: "The security code can be calculated from the number."
False. Issuers generate it using secret keys. No public formula links the number and the code.
Myth: "Contactless cards can be skimmed from across the room."
Largely false. Contactless works over a few centimeters, and each tap produces a one-time cryptogram that cannot build a working chip clone. Blocking sleeves are harmless, but the design already limits this risk.
Myth: "Every card has 16 digits."
False. Amex has 15, classic Diners Club has 14, and some cards have up to 19. Forms that insist on 16 reject real customers.
Myth: "Someone who knows my last four digits must be my bank."
False. The last four digits appear on receipts and are easy to obtain. Scammers use them to sound convincing. Always call back on the number printed on your card.
FAQ
What does PAN stand for on a credit card?
PAN stands for Primary Account Number, the official name for the long card number. It is defined by ISO/IEC 7812 and used throughout card network rules and PCI DSS.
What is the difference between a BIN and an IIN?
There is no practical difference. IIN (Issuer Identification Number) is the official ISO term; BIN (Bank Identification Number) is the older industry name. Both mean the leading digits that identify the issuer, now 8 digits under ISO/IEC 7812-1:2017.
How many digits are in a credit card number?
Between 12 and 19, with 19 the maximum in the standard. Most Visa, Mastercard and Discover cards have 16 digits, American Express has 15, and classic Diners Club has 14.
Can someone use my card with just the number?
It is harder than it used to be, because most online merchants also require the expiry date and security code, and many use 3-D Secure. But some merchants accept payments with fewer checks, so treat the full number as sensitive and report unknown charges quickly.
Is it safe to give someone the last four digits of my card?
Generally yes. They are printed on receipts and shown in apps, and cannot be used alone to pay. Just do not treat a caller as genuine because they know them.
Why is my Apple Pay card number different from my physical card?
Apple Pay uses a Device Account Number, a network token created for your device. The merchant receives the token, not your real PAN, which is why the last four digits in Wallet differ from those on your card.
Does the card number change when my card expires?
Sometimes. Many issuers keep the number and change only the expiry date and security code. Others issue a new number. After a loss, theft or suspected compromise, you will almost always get a new one.
What is the difference between CVV and CVV2?
CVV1 is encoded in the magnetic stripe and checked on swipe transactions. CVV2 is printed on the card and used online and by phone. They are different values, so copied stripe data does not reveal the printed code. Chip cards use a separate iCVV as well.
Can you tell the bank from a card number?
Often, yes. The BIN identifies the issuer, and payment systems use BIN tables to map ranges to issuers, card types and countries. The tables change and some ranges are shared, so the result is not always exact.
Why does a website reject my card number before I submit it?
The form probably detected a typo with the check digit, or it did not recognize your card's prefix or length. If the digits are correct, the site's brand detection may be outdated, for example not recognizing Mastercard numbers that start with 2.
Are virtual card numbers real card numbers?
Yes. They follow the same structure and are accepted like any card. The difference is that they can be limited, locked to one merchant, or deleted without affecting your physical card.
Bottom line: a card number is a structured address. The first digit gives an industry category, the BIN identifies the network and issuer, the middle digits identify one account, and the last digit catches typos. The expiry date, security codes, chip cryptograms and tokens add the protection the number itself cannot. Share the last four digits freely, share the full number only when paying through a checkout you trust, and never share your security code, PIN or one-time passcodes with anyone who contacted you. If you are choosing a new card, our guide on how to choose the right credit card is a good next step.
Sources
Official documentation referenced in this guide.
- ISO: ISO/IEC 7812-1:2017, Identification cards, Identification of issuers, Part 1: Numbering system
- PCI Security Standards Council: Document library (PCI DSS v4.0.1)
- PCI Security Standards Council: FAQs (including 8-digit BINs and truncation)
- EMVCo: EMV Payment Tokenisation
- EMVCo: EMV chip and contactless specifications
- Visa: Visa Token Service
- Visa: Visa Core Rules and Visa Product and Service Rules
- Mastercard: Mastercard Digital Enablement Service (MDES)
- Apple: Apple Platform Security guide (Apple Pay)
- FTC: Lost or stolen credit, ATM, and debit cards
- FTC: How to recognize and avoid phishing scams
- FTC: IdentityTheft.gov
- CFPB: Credit cards consumer tools