Didyou know

BIN - Bank Identification Number, also known as the Issuer Identifier Number (IIN), refers to the first six digits of a payment card's Primary Account Number (PAN).

The Bank Identification Number (BIN) provides information about the payment card being used and the bank that issued it. It provides a way to check if the issuing bank is in the same country as the geolocation and address information provided by the consumer. While this alone is not enough to indicate fraud, it provides an additional signal as to the identity of the individual.

The BIN can also be used to reduce consumer data entry errors on check-out pages. For example, the BIN also identifies the card brand being used. The consumer can be asked to select the card brand they are using (Visa, MasterCard, Discover, American Express) and the card number the consumer enters can be checked to ensure it makes sense, and this is known as inline validation.

BIN Checks can also aid in several other checks and measures:

Export Compliance - Ensure the card issuing country is one you are allowed to sell/export goods to.

Identify Prepaid Cards - If offering the option to pay in installments or using recurring billing, prevent the customer from providing a prepaid card which may only carry a balance to cover the first transaction.

 

subscribe to newsletter

 

 

Credit Card BIN Checkstechnique overview

The credit card number can tell you several very interesting things. By using the first 6 digits you can determine the card type (Visa, MasterCard, American Express, Discover) and you can determine the bank and country where the card was issued. The first 6 digits of the credit card number are known as the Bank Identification Number (BIN), which identifies the consumer's issuing bank and other information about thay payment card. Key considerations when implementing or buying this functionality include:

  • It is not easy to get a BIN list in-house, and is accessed most often through a thrid party service provider or through your acquirer.
  • There are two types of BIN lists - there are BIN lists for BIN to country, and BIN lists for bank to BIN.
  • BIN to Country List - List provides the country of issuance when provided a BIN number.
  • Bank to BIN List - List provides the bank name, phone number and country when provided a BIN number
  • Does the provider offer a BIN List or database for the merchant to keep and use in-house, do they offer a hosted BIN lookup service, or both?
  • For vendors that provide BIN list or database, how often are these databases updated? Do they offer a subscription service that includes updates, or must you purchase periodic updates to the database?

How does it work?

Credit card numbers are ISO 7812 numbers. As an ISO 7812 number it contains:

  • A single-digit major industry identifier (MII) (the MII is considered to be part of the issuer identifier number), a six-digit issuer identifier number (IIN), an account number, and a single digit checksum using the Luhn algorithm.

Cards participating in the BIN system include:

  • Credit cards, debit cards, charge cards, stored-value cards, and Electronic Benefit Transfer (EBT) cards.

 

The term "Issuer Identification Number" (IIN) is replacing "Bank Identification Number". See ISO 7812 for more information.

The prefixes and lengths for the most common card types are:

Card Type Prefix(es) Length Validation
American Express 34, 37[1]
15[2]
Luhn algorithm
China Union Pay 622 (622126-622925) 16,17,18,19
unknown
Diners Club Carte Blanche 300-305
14
Luhn algorithm
Diners Club International[4]
36
14
Luhn algorithm
Diners Club US & Canada
55
16
Luhn algorithm
Discover Card
6011, 65
16
Luhn algorithm
JCB
35
16
Luhn algorithm
JCB
1800,2131
15
Luhn algorithm
Laser (debit card)
6304, 6706, 6771, 6709
16-19
Luhn algorithm / unknown?
Maestro (debit card)
5020,5038,6304,6759
16,18
Luhn algorithm
MasterCard
51-55
16
Luhn algorithm
Solo (debit card)
6334
16,18,19
Luhn algorithm
Switch (debit card)
4903,4905,4911,4936,564182,633110,6333,6759
16,18,19
Luhn algorithm
Visa
4[1]
13,16[7]
Luhn algorithm
Visa Electron (debit)
417500,4917,4913,4508,4844
16
Luhn algorithm

 

How do you use the results?

Online merchants may use BIN lookups to help validate transactions. For example, if the credit card's BIN indicates a bank in one country, while the customer's billing address is in another, the transaction may require additional review. With BIN services that provide more information than just the issuing country, this data can also be beneficial. For example recognizing and preventing the use of prepaid cards for recurring transactions. In cases of a data breach against a particular issuer compromising many of their cardholders, the BIN can be used to flag potentially bad orders coming from these cards. The BIN check has uses outside of fraud prevention as well, such as recognizing the card type before attempting authorization to ensure you accept that card brand.

AdditionalResources

  • Introduction to eCommerce Credit Card Payments.

    Covers the credit card process flow defining each of the "payment players"; reviews payment concepts such as authorizations, settlements, reversals, chargebacks and the credit card association's high risk programs.

  • OVERVIEW OF ECOMMERCE FRAUD PREVENTION TECHNIQUES.

    A core curriculum course providing an introduction to 30 plus fraud prevention techniques; what they are, high level discussion on how to employ them and big picture considerations for using them.

  • Ecommerce Fraud Moving from Tools to Solutions.

    This session covers what constitutes a fraud solution and categorizes the many types of third party fraud tools. The course outlines the common terminology of fraud solutions and describes the capabilities needed to implement a fraud solution.

keynotes

  • Alternative Solutions - Charge Verification.
  • Building this In-House - This technique can easily done in-house, provided you have access to a BIN list. A list or database can be purchased, but will need regular updates.
  • Estimated Costs - Can be found as a per transaction hosted solution, or you can potentially get it from your acquirer. Many providers offer a list or database which can be purchased for a one-time fee, but updates or repurchasing the subscription will be required to keep the list current.
  • Sample Vendors - MaxMind