Last reviewed: September 29, 2026. Card network rules and industry standards change over time. For anything that affects your business, check the current documents from the card networks, the PCI Security Standards Council and your payment provider.
Short answer: A BIN (Bank Identification Number) is the first six to eight digits of a payment card number. The formal name today is IIN, or Issuer Identification Number, defined by the international standard ISO/IEC 7812. The BIN tells the payment system which card network the card belongs to, which institution issued it, and usually what kind of card it is (credit, debit or prepaid) and which country it comes from. Since April 2022, Visa and Mastercard have been moving to 8-digit BINs. A BIN describes a range of cards and an issuer, not a person. It never reveals the cardholder's name, balance, address or full card number. If you want to know who issued your own card, the simplest and safest way is to look at the card itself, your statement or your banking app, or to call the number on the back of the card.
This guide explains what a BIN is, how the numbering standard works, why the industry moved from six to eight digits, what a BIN can and cannot tell anyone, how merchants use BINs for routing and fraud screening, what "BIN attacks" are and how businesses defend against them, and what the PCI rules say about showing card digits. It is written from an educational and defensive point of view. It does not explain how to create card numbers, and you should be wary of anyone who offers that.
What a BIN (IIN) is
A Bank Identification Number, or BIN, is the leading part of a payment card number that identifies the institution that issued the card. The term "BIN" is the one most people in payments still use in daily conversation. The official term in the international standard is Issuer Identification Number, or IIN. The change in name reflects a simple fact: not every card issuer is a bank. Card numbers are also issued by payment companies, fintech firms, retailers, fuel companies, airlines and others. In practice, the two terms mean the same thing, and you will see them used side by side in network documents, processor documentation and developer guides.
The anatomy of a card number
A card number is formally called a Primary Account Number, or PAN. Most cards you carry today have a 16-digit PAN, but the standard allows lengths from 8 to 19 digits. American Express cards commonly use 15 digits, and some debit and network cards use up to 19.
Every PAN has three parts:
- The Issuer Identification Number (BIN/IIN). The first six or eight digits, depending on the range. The very first digit is the Major Industry Identifier, which we cover below.
- The individual account identifier. The middle digits that the issuer assigns to a particular account. Only the issuer knows how these map to a customer.
- The check digit. The last digit, calculated from all the other digits using the Luhn formula (also called the "mod 10" algorithm). It exists to catch simple typing mistakes, such as a swapped pair of digits.
The check digit is often misunderstood. It is a typo filter, not a security feature. A number that passes the Luhn check is simply well formed. It does not mean an account exists, that it is open, or that it has any money behind it. If you want to understand exactly how that last digit works and why it catches errors, see our explainer on what the Luhn algorithm is and how it checks a card number.
| Part of the PAN | Typical position (16-digit card) | What it does | Who controls it |
|---|---|---|---|
| Major Industry Identifier (MII) | Digit 1 | Shows the broad industry category of the issuer | Defined by ISO/IEC 7812 |
| Issuer Identification Number (BIN/IIN) | Digits 1–6 or 1–8 | Identifies the issuer and usually the card product | Assigned through the registration authority and card networks |
| Individual account identifier | Digits 7 or 9 through 15 | Identifies the specific account within the issuer's range | The issuer |
| Check digit | Digit 16 | Catches typing errors using the Luhn formula | Calculated, not assigned |
Notice that when the BIN grows from six to eight digits, the account identifier shrinks by two digits on a 16-digit card. That trade-off is at the center of the 8-digit BIN change, which we explain in its own section.
ISO/IEC 7812: the standard behind BINs
BINs are not an invention of any single card company. They come from an international standard called ISO/IEC 7812, "Identification cards — Identification of issuers." It is published jointly by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC).
The standard has two main parts:
- ISO/IEC 7812-1 sets out the numbering system: how an issuer identification number is structured, how the PAN is built from it, and how the check digit is calculated.
- ISO/IEC 7812-2 covers the application and registration procedures that issuers follow to obtain an IIN.
The current edition of Part 1 was published in 2017. Its most important change was to lengthen the IIN from six digits to eight digits. The reason was straightforward: the world was running out of 6-digit ranges. There are only so many six-digit combinations, and many are reserved for specific industries or already in use. The growth of card programs, fintech issuers, prepaid products and virtual cards put pressure on the supply. Moving to eight digits multiplies the number of possible issuer ranges by one hundred.
The standard gave the industry a long runway. It set the expectation that the payment ecosystem would be ready to handle 8-digit IINs by April 2022. Card networks then set their own rules and timelines to meet that target, which is why the "2022 BIN change" is often associated with Visa and Mastercard.
The first digit: the Major Industry Identifier
The first digit of a card number is known as the Major Industry Identifier, or MII. It groups issuers into broad categories. In the early days of card payments, these categories were quite meaningful. Today they are more of a historical outline, because banking cards dominate and several networks use ranges that begin with digits originally associated with other industries. Still, the MII explains why nearly every card in your wallet begins with 2, 3, 4, 5 or 6.
| First digit (MII) | Category under ISO/IEC 7812 | Common real-world examples |
|---|---|---|
| 0 | ISO/TC 68 and other future industry assignments | Rarely seen on consumer cards |
| 1 | Airlines | Some airline and travel-related cards |
| 2 | Airlines, financial and other future industry assignments | Mastercard's 2-series range (2221–2720) |
| 3 | Travel and entertainment | American Express, JCB, Diners Club |
| 4 | Banking and financial | Visa |
| 5 | Banking and financial | Mastercard (51–55), various Maestro ranges |
| 6 | Merchandising and banking/financial | Discover, UnionPay, many domestic debit networks |
| 7 | Petroleum and other future industry assignments | Some fuel and fleet cards |
| 8 | Healthcare, telecommunications and other future industry assignments | Some health and telecom cards; certain domestic networks |
| 9 | For assignment by national standards bodies | Country-specific schemes |
A useful way to think about it: the first digit tells you the "neighborhood," the first few digits tell you the "street" (usually the network), and the full BIN tells you the "building" (the issuer and product).
Card network ranges at a glance
Each major card network is associated with particular leading digits. This is how a checkout page can show a Visa or Mastercard logo after you type only the first digit or two. The ranges below are the commonly published ones. Networks can add, retire or reassign ranges, and domestic networks in some countries share or overlap with global ranges, so payment software should rely on current BIN data from its processor rather than hard-coded rules.
| Network | Common leading digits | Typical PAN length | Notes |
|---|---|---|---|
| Visa | 4 | 16 (some 13 or 19) | The entire 4-series is associated with Visa |
| Mastercard | 51–55 and 2221–2720 | 16 | The 2-series range was added in 2017 to expand capacity |
| American Express | 34, 37 | 15 | Uses a 4-digit security code on the front of the card |
| Discover | 6011, 644–649, 65 | 16 (up to 19) | Discover's network also accepts Diners Club and some partner ranges |
| JCB | 3528–3589 | 16 (up to 19) | Japanese network with global acceptance through partners |
| Diners Club International | 36, 300–305, 38–39 | 14 (some 16) | Processed on the Discover network in many markets |
| UnionPay | 62 | 16–19 | China's card network; some ranges are co-accepted by Discover |
| Maestro | Various, often 50 and 56–69 | 12–19 | Mastercard's debit brand; being phased out in parts of Europe |
Two practical lessons come out of this table. First, the leading digit alone is not enough to identify a network with certainty, especially for 5- and 6-series cards, where several brands and domestic schemes live side by side. Second, card lengths vary. A checkout form that forces every card into 16 digits will reject perfectly valid American Express, Diners Club or 19-digit debit cards.
The move from 6-digit to 8-digit BINs
For decades, the BIN was six digits long. That is why many older systems, reports and even regulations talk about "the first six digits." The 2017 revision of ISO/IEC 7812-1 changed that, and the card networks set April 2022 as the date by which their ecosystems had to be ready.
What Visa and Mastercard required
Visa and Mastercard both announced programs to move to 8-digit BINs, with April 2022 as the key milestone. Visa told its clients that it would begin assigning new 8-digit BINs, and that issuers, acquirers, processors and merchants needed to be able to recognize and process them. Mastercard likewise moved toward assigning 8-digit BINs and asked its customers to update their systems. Both networks also set out plans to transition existing 6-digit ranges over time, rather than switching every card overnight. In practice, this means 6-digit and 8-digit BINs will coexist for years.
For cardholders, nothing visible changed. Your card number stayed the same length. A 16-digit card is still 16 digits. The only difference is how many of those digits the system treats as the issuer's identifier, and how many are left for the account number.
Why the change mattered for businesses
The move to 8 digits sounds small, but it touched many systems:
- Routing tables that looked up issuers by the first six digits had to be able to read eight.
- Fraud rules built on 6-digit BINs could produce false matches, because one 6-digit prefix might now contain several different 8-digit ranges from different products, or even different issuers.
- Reports and databases that stored the first six digits for analytics needed new fields and new logic.
- Receipt printing and masking logic had to be checked against updated PCI guidance about how many leading digits may be shown.
- Customer service scripts that asked callers for the "first six digits" needed review.
If you run an online store or build payment software, the practical takeaway is simple: never assume a BIN is exactly six digits long. Store and compare BINs in a way that supports both lengths, and get BIN attributes from your processor or network data rather than from a list you maintain by hand.
What a BIN reveals, and what it never reveals
This is the part that matters most for privacy, and it is also where many myths start. A BIN is a label for a range of cards. Thousands or even millions of cards can share the same BIN. That means the BIN can only describe attributes that are common to the whole range.
What a BIN usually reveals
- Card network (brand). Visa, Mastercard, American Express and so on.
- Issuing institution. The bank or company that issued the card, sometimes shown as the sponsor bank rather than the brand name on the card.
- Country of issue. The country where the issuer registered the range.
- Funding type. Credit, debit, prepaid or charge card.
- Product or tier. For example, classic, gold, platinum, business, commercial or corporate.
- Consumer or commercial use. Whether the range is meant for individuals or businesses.
- Sometimes, regulatory status. In the US, processors may flag whether a debit BIN belongs to an issuer covered by the Durbin fee cap.
What a BIN never reveals
- The cardholder's name, address, phone number or email.
- The full card number, expiry date or security code (CVV/CVC).
- The account balance, available credit or transaction history.
- Whether a specific card is active, blocked, lost or stolen.
- The cardholder's credit score or income.
- The PIN, online banking login or any other secret.
Because of this, knowing a BIN is not sensitive in the same way that knowing a full card number is. That is also why PCI rules allow the leading digits to be shown in some situations while the middle digits must stay hidden. The BIN on its own cannot be used to make a purchase, and nobody can "work backward" from a BIN to a person.
How BINs route a payment
When you pay with a card, the merchant does not talk to your bank directly. The request travels through a chain of companies, and the BIN helps each one decide where to send it next.
- You present the card. You tap, insert, swipe or type your card number at checkout.
- The merchant's system sends the request to its acquirer or processor. This is the company that handles card payments for the merchant.
- The processor reads the BIN. It checks the leading digits against its BIN tables to find out which network the card belongs to and what kind of card it is.
- The request goes to the card network. Visa, Mastercard or another network receives the authorization request.
- The network uses the BIN to find the issuer. It forwards the request to the issuer (or the issuer's processor) that owns that BIN range.
- The issuer approves or declines. The issuer checks the account, the available funds or credit, and its own fraud models, then sends back a response.
- The response travels back the same way. Within a second or two, the terminal or checkout page shows "approved" or "declined."
In this flow, the BIN is like the address on an envelope. Without it, the network would not know which issuer should receive the request. That is why BIN tables are so important to processors, and why the move to 8-digit BINs required so much testing.
BINs, interchange and the Durbin Amendment
Every time a merchant accepts a card, it pays fees. The largest single part of those fees is usually interchange, which the merchant's acquirer pays to the card issuer. Interchange rates are set by the card networks, and they depend on many factors: whether the card is credit or debit, whether it is a consumer, business or premium card, how the card was used (in person or online), the type of merchant, and the country.
The BIN is how the payment system knows most of those card-side factors. A premium rewards credit card generally carries a higher interchange rate than a basic debit card. A commercial card often carries different rates from a consumer card. When the processor reads the BIN, it can place the transaction in the right interchange category. That is why two customers buying the same item for the same price can cost the merchant different amounts in fees.
If you are curious how fees show up on the cardholder side, especially when you shop abroad, our guide to foreign transaction fees and dynamic currency conversion explains the charges you may see on your own statement.
Regulated vs exempt debit in the US
In the United States, debit card interchange is shaped by a law often called the Durbin Amendment, part of the 2010 Dodd-Frank Act. The Federal Reserve put it into effect through Regulation II (Debit Card Interchange Fees and Routing). The rules divide debit issuers into two groups:
- Regulated issuers. Banks and credit unions that, together with their affiliates, have $10 billion or more in assets. Their debit interchange fees are capped by Regulation II. The cap that took effect in 2011 is 21 cents plus 0.05 percent of the transaction, with an extra one cent possible for issuers that meet fraud-prevention standards. The Federal Reserve proposed lowering that cap in 2023, and the fee standard has also been the subject of litigation, so check the Federal Reserve's Regulation II pages for the figures that apply today.
- Exempt issuers. Smaller banks and credit unions below the $10 billion threshold. Their debit interchange is not capped by Regulation II, so it is generally set by network rate tables and is often higher.
Because the fee depends on which group the issuer falls into, processors and networks mark debit BINs as regulated or exempt. A merchant's statement may show separate lines for "regulated" and "exempt" debit transactions. The same BIN data helps explain why a debit payment from a very large national bank might cost the merchant less than one from a small community bank.
Regulation II also has a routing requirement. Issuers must enable at least two unaffiliated networks on each debit card, so that merchants have a choice. In 2022, the Federal Reserve clarified that this applies to card-not-present transactions, such as online purchases, as well as in-store ones, with the clarification taking effect in July 2023. BIN data helps processors know which networks are enabled on a given debit card.
How merchants use BINs for fraud screening
For online merchants, BIN data is one of the most useful early signals in a fraud check. It is available as soon as a customer starts typing, it costs little to use, and it can highlight orders that deserve a second look. It is never enough on its own, but it adds context to everything else the merchant knows.
Country mismatches
The classic BIN check compares the card's country of issue with other location signals from the order:
- BIN country vs IP address country. If a card was issued in one country but the customer's internet connection appears to come from another, that may be worth a closer look.
- BIN country vs billing address. A billing address in a different country from the card's issuer can be a warning sign, though there are many innocent reasons for it.
- BIN country vs shipping address. Sending goods to a third country, far from both the card's country and the billing address, is a common pattern in fraud involving stolen card data.
The key word is "may." Mismatches happen all the time for honest reasons. People travel. Expats keep cards from their home country. Students abroad pay with a parent's card. Companies issue corporate cards from a head office in one country to staff in many others. Virtual private networks (VPNs) make the IP address unreliable. A good fraud system treats a mismatch as one factor that raises or lowers a risk score, not as an automatic decline. Declining every mismatch would turn away many legitimate customers, including the travelers and international students our guide on how to pay for studying abroad is written for.
BIN data inside a wider fraud strategy
Modern fraud prevention combines many signals: device data, customer history, order value, address verification results, security code checks, velocity patterns, and increasingly machine-learning scores from the payment provider. BIN attributes are one layer in that stack. For a practical, plain-language overview of the other layers, see our guide to card-not-present fraud prevention for small merchants.
BIN attacks and card-testing fraud
The same features that make BINs useful also make them a target. A BIN attack is a type of card-testing fraud in which criminals start from a known BIN and use automated tools to try large numbers of possible card numbers, expiry dates or security codes against a merchant's checkout, hoping that some combinations will be approved. It is also called an enumeration attack, because the attacker enumerates (runs through) many possibilities in sequence.
A related pattern is plain card testing. Here, criminals already hold a batch of stolen card details, often bought on underground markets, and want to find out which cards still work. They make small test payments or authorization attempts, usually at merchants with weak defenses, and then use the cards that pass for larger fraud elsewhere.
Why the Luhn check does not stop it
Because the last digit of a card number is a check digit, many randomly typed numbers fail the Luhn formula immediately. Attackers know this and only submit numbers that are well formed. That is exactly why passing the Luhn check says nothing about whether a card is real. Our article on the Luhn algorithm explains why the check digit was designed to catch typos, not to protect against fraud. The real protection sits with the issuer, which knows which accounts exist, and with the merchant's and network's fraud controls.
Signs a merchant is under a card-testing attack
- A sudden spike in failed payments or authorization declines, often at unusual hours.
- Many small payments, frequently for the lowest-priced item or a small donation amount.
- Many different card numbers from the same BIN or a handful of BINs in a short time.
- Many attempts from the same IP address, device or customer account, or from rotating IP addresses.
- Many new customer accounts with random-looking names or email addresses.
- Decline reasons such as "incorrect number," "incorrect CVC" or "expired card" appearing at high volume.
How merchants defend against card testing
No single tool stops every card-testing attack. The strongest approach layers several defenses, so that an attacker who gets past one still meets others. Payment providers such as Stripe publish guidance on this, and the card networks expect merchants and acquirers to take reasonable steps. Here are the main controls, in plain terms.
1. Velocity limits
Velocity rules limit how many payment attempts can happen within a time window. Common versions include limits on the number of attempts per IP address, per device, per customer account, per email address and per card BIN. For example, a store might block further attempts after several failures from the same device within a short period. The exact thresholds depend on the business; a ticketing site on sale day has very different normal traffic from a small craft shop.
2. CAPTCHA and bot detection
Most card-testing attacks are automated. Adding a CAPTCHA or an invisible bot-detection challenge on the checkout or on the "add payment method" step makes automated attempts slower and more expensive. Modern bot-detection services run in the background and only challenge sessions that look suspicious, so genuine customers are rarely bothered.
3. 3-D Secure authentication
3-D Secure (3DS) is a protocol, managed by EMVCo, that lets the card issuer authenticate the cardholder during an online purchase. Brand names include Visa Secure, Mastercard Identity Check and American Express SafeKey. In the current version, EMV 3-D Secure 2.x, the issuer receives rich data about the transaction and device and can often approve low-risk payments without any extra step. For higher-risk payments, the issuer may ask the cardholder to confirm in a banking app or with a one-time code. A criminal who only has a list of card numbers usually cannot pass that step. In the European Economic Area and the UK, strong customer authentication rules make this kind of check a standard part of many online payments.
4. Address Verification Service (AVS) and security code checks
The Address Verification Service (AVS) compares the numeric parts of the billing address and postcode entered at checkout with what the issuer has on file. It is widely used in the US, Canada and the UK. The card security code (CVV2, CVC2 or CID) check confirms that the person entering the number also has the three- or four-digit code from the card. Merchants can decline or review payments where these checks fail. Note that repeated attempts with different security codes are themselves a warning sign, which is why velocity rules and code checks work well together.
5. Work with your payment provider
Your acquirer or payment provider sees patterns across many merchants and can often block an attack faster than you can alone. If you suspect an attack, contact them quickly. Ask what tools they offer, such as risk rules based on BIN, country or card type, and how to tune them without blocking genuine customers.
PCI DSS: what may be displayed and stored
The Payment Card Industry Data Security Standard (PCI DSS) is the security standard that businesses handling card data must follow. It is maintained by the PCI Security Standards Council (PCI SSC), which was founded by the major card networks. The current major version is PCI DSS v4.0, with v4.0.1 as a limited revision, and its future-dated requirements became mandatory on March 31, 2025.
Several PCI rules relate directly to BINs, because the BIN is the part of the card number that businesses most often want to keep or show.
Masking: what may be displayed
PCI DSS requires that the full card number be masked when displayed, so that only people with a legitimate business need can see more than a limited number of digits. The standard describes the maximum as the BIN and the last four digits. Historically, that meant the first six and last four digits. You have probably seen this on receipts, invoices or account screens, where a card appears as something like "4XXXXX…1234" or only "…1234".
Masking rules apply to screens, printed receipts, reports and similar displays. Many businesses choose to show even less, such as only the last four digits, because less exposure means less risk. Showing fewer digits than the maximum is always allowed.
Truncation and the 8-digit BIN
Truncation means permanently removing part of the card number when it is stored, so that the full number can never be recovered from the stored value. The move to 8-digit BINs raised an obvious question: if the BIN is now eight digits, may a business keep the first eight and the last four?
The PCI SSC addressed this in its published guidance (FAQs). In summary, for card numbers of 16 digits or more that are issued under 8-digit BINs, retaining or displaying the first eight and last four digits is acceptable. For shorter card numbers, the first-six-and-last-four limit continues to apply. The logic is that a 16-digit number with 8 + 4 digits known still leaves enough hidden digits to protect the account, while a shorter number would not. The exact wording and conditions are set by PCI SSC and the card brands, and can be updated, so always check the current FAQ and your acquirer's requirements before changing what your systems show or store.
What must never be stored
PCI DSS draws a hard line around sensitive authentication data. After a payment is authorized, businesses must not store:
- The full contents of the magnetic stripe or chip data.
- The card security code (CVV2, CVC2, CID).
- The PIN or encrypted PIN block.
The BIN itself is not sensitive authentication data, and it is commonly kept for analytics, routing and fraud purposes. But if the full card number is stored at all, it must be protected with strong methods such as encryption, truncation, tokenization or hashing, as the standard sets out.
Tokenization and network tokens
Tokenization replaces a real card number with a substitute value, called a token, that is useless to a thief outside its intended context. There are two broad kinds, and both interact with BINs in different ways.
Network tokens
Network tokens are issued by the card networks themselves, following the EMV Payment Tokenisation framework published by EMVCo. A network token looks like a card number. It has the same length and format, and it passes the Luhn check, but it is not your real card number. It is linked to your account by the network's token service and can be limited to a specific merchant, device or channel. Mobile wallets such as Apple Pay and Google Pay use network tokens; many merchants and payment providers also use them for stored cards.
This is where BINs come in. Network tokens come from their own token BIN ranges, separate from the BIN on your physical card. That has some practical effects:
- A merchant looking only at the leading digits of a token may see a different BIN from the card's real BIN. Payment systems therefore carry extra data, such as the token's underlying product and the Payment Account Reference (PAR), which lets merchants and processors link transactions from the same underlying account without exposing the real card number.
- Fraud rules and reporting that rely on the BIN need to understand token BINs, or they may misread country, product or issuer information.
- When your physical card is replaced (for example, after it expires or is reported lost), a network token can often be updated automatically, so stored payments keep working.
For consumers, the takeaway is reassuring. When you pay with a phone wallet, the merchant usually never receives your actual card number. If that merchant suffers a data breach, the stolen tokens are far less useful to criminals than real card numbers would be.
Virtual cards, prepaid cards and their BINs
Virtual cards
A virtual card is a card number that exists only digitally, without a plastic card. Many banks and fintech apps let you create virtual cards for online shopping, subscriptions or one-off purchases. Businesses use them to pay suppliers and control employee spending.
From a BIN point of view, virtual cards are ordinary card numbers. They are issued from BIN ranges assigned to the issuer, just like physical cards. Some issuers use dedicated BIN ranges for virtual products; others issue virtual and physical cards from the same ranges. A merchant's BIN data may show a virtual card as prepaid, debit, credit or commercial, depending on how the program is set up. The same card network rules and PCI requirements apply to virtual card numbers as to any other card number.
Virtual cards can improve safety, because you can lock, limit or delete them without affecting your main card. If you want to compare options, see our roundup of the best virtual cards for online payments.
Prepaid cards
Prepaid cards are loaded with money in advance and spent down. They include gift cards, payroll cards, benefits cards, travel money cards and general-purpose reloadable cards. Most prepaid programs are run by a program manager and issued through a sponsor bank, so the BIN may show the sponsor bank's name rather than the brand printed on the card.
Prepaid BINs matter to merchants because of the risk of a failed later charge. A hotel that authorizes a card at check-in and charges the final bill at check-out, or a subscription service that bills monthly, may treat prepaid cards differently. That is why some cardholders find that a prepaid card is declined for certain kinds of purchases even though it has enough balance. The BIN's "prepaid" flag is often the reason.
Prepaid cards are also different from credit products that help build a credit history. If you are weighing a prepaid card against other options, our guide to secured credit cards explains how the two differ.
How to find your own card's issuer legitimately
Sometimes you genuinely need to know who issued a card: to report it lost, to dispute a charge, to confirm whether it is credit or debit, or to check whether it has foreign transaction fees. The good news is that you almost never need a lookup service for your own card. The reliable answers are already in your hands.
Check the card itself
Look at the front and back of the card. The issuer's name is usually printed on the front, and the back normally shows the issuer's name, a customer service phone number and sometimes a note such as "issued by [bank name] pursuant to a license from Visa/Mastercard." That small print is especially helpful for fintech and co-branded cards, where the brand on the front is not the legal issuer.
Check your statement or banking app
Your monthly statement, card agreement or the app you use to manage the card will name the issuer and the card product. The card agreement also states whether it is a credit, debit or prepaid product and lists fees such as foreign transaction fees.
Call the number on the back of the card
If you are still unsure, call the phone number printed on the back of the card, or the number on your issuer's official website. Do not use a number from an unexpected text, email or pop-up. The issuer can tell you exactly what kind of card you have, and it is the right place to report fraud or a lost card.
Common BIN myths
Myth 1: "If someone knows my BIN, they can use my card."
No. The BIN is shared by a large number of cards. It says nothing about your specific account and cannot be used to pay for anything. It is the rest of the card data, together with the security code and authentication, that protects your account. That said, you should still keep your full card number private.
Myth 2: "A BIN lookup can find the cardholder's name or address."
No. BIN data describes the issuer and the product. It contains no personal information. Any site claiming to reveal a cardholder's identity from a BIN is either wrong or dishonest.
Myth 3: "A number that passes the Luhn check is a real card."
No. The Luhn check only confirms that a number is well formed. Many well-formed numbers are not linked to any account. Only the issuer can say whether an account exists and is valid, and it does that through an authorization request, not a formula.
Myth 4: "Premium cards have special BINs that guarantee approval."
No BIN guarantees approval. Every transaction is decided by the issuer based on the account, the available credit or funds, and its fraud models. The product tier affects benefits and merchant fees, not whether a particular payment will go through.
FAQ
What does BIN stand for?
BIN stands for Bank Identification Number. The official term under ISO/IEC 7812 is Issuer Identification Number (IIN), because not every card issuer is a bank. The two terms are used interchangeably in the payments industry.
How many digits is a BIN?
A BIN is either six or eight digits. The 2017 revision of ISO/IEC 7812-1 extended the IIN to eight digits, and Visa and Mastercard set April 2022 as the date by which the ecosystem had to support 8-digit BINs. Both lengths are in use today.
Can someone steal my identity or money with just my BIN?
No. A BIN identifies a range of cards and the issuer, not you. It does not include your name, address, balance or full card number, and it cannot be used to make a purchase on its own.
How do merchants use my card's BIN?
Mainly to route the payment to the right network and issuer, to determine fees, to show the right card logo and options, and to add context to fraud checks, such as comparing the card's country of issue with the shipping address or IP location.
Why was my prepaid card declined when it had enough money?
Some merchants, such as hotels, car rental firms and subscription services, restrict prepaid cards because later charges might fail. They recognize prepaid cards from the BIN. Ask the merchant about its card policy or use a different payment method.
What is a BIN attack?
A BIN attack is a form of card-testing fraud in which criminals use automated tools to try many possible card numbers from a known BIN at a merchant's checkout, hoping some are accepted. Merchants defend against it with velocity limits, bot detection, 3-D Secure, AVS and security code checks, and monitoring.
How many card digits may a business show on a receipt?
Under PCI DSS, displayed card numbers must be masked so that no more than the BIN and last four digits are visible, unless someone has a legitimate business need to see more. PCI SSC guidance allows the first eight and last four for card numbers of 16 or more digits issued under 8-digit BINs; otherwise the limit is the first six and last four. Many receipts show only the last four.
How can I find out which bank issued my card?
Look at the front and back of the card, your statement, your card agreement or your banking app. If you are still unsure, call the number on the back of the card. You should never need to enter your full card number into a website to find out who issued it.
Bottom line
The BIN is the first six or eight digits of a card number, and it acts as the card's address in the payment system. It tells networks and processors where to send a payment, helps set the fees a merchant pays, and gives fraud systems useful context about the card's issuer, country and type. The standard behind it, ISO/IEC 7812, moved to 8-digit issuer numbers in 2017, and the major networks made the ecosystem ready for them from April 2022.
For cardholders, the BIN is not a secret and cannot be used to identify you or spend your money. The things that actually protect your account are the rest of your card details, your security code, your PIN and one-time codes, and your issuer's fraud monitoring, so keep those private. For merchants and developers, BIN data is valuable but imperfect. Use it as one signal among many, get it from official sources, stay within PCI limits on displaying digits, and build layered defenses against card testing before an attack arrives.
If you want to go one level deeper into how card numbers are structured, read our explainer on the Luhn algorithm and card number check digits. And if you are choosing a new card, our guide on how to choose the right credit card for you covers what really matters.
This article is general information, not legal, compliance or financial advice. Merchants should confirm requirements with their acquirer, payment provider and the current card network and PCI SSC documents.
Sources
- ISO, ISO/IEC 7812-1:2017 Identification cards — Identification of issuers — Part 1: Numbering system
- PCI Security Standards Council, PCI DSS v4.0.1 and FAQs on masking and truncation
- EMVCo, EMV 3-D Secure and EMV Payment Tokenisation specifications
- Federal Reserve Board, Regulation II (Debit Card Interchange Fees and Routing)
- Visa, Visa client communications on 8-digit BIN readiness
- Mastercard, Mastercard guidance on 8-digit BINs and the 2-series range
- Stripe Docs, Card testing: how to prevent and respond
- Federal Trade Commission, Lost or Stolen Credit, ATM, and Debit Cards