# Visa card restrictions

**URL:** <https://boards.straightdope.com/t/visa-card-restrictions/476990>\
**Category:** Miscellaneous and Personal Stuff I Must Share\
**Created:** [December 13, 2008, 5:26am UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990 "2008-12-13T05:26:12Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [December 13, 2008, 5:26am UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/1 "2008-12-13T05:26:12Z")

</div>

I’ve just received this email [redacted by me]:

> [@](#):
>
> Due to an unusually high volume of fraudulent VISA transactions that have occurred within the past week, we will be restricting Classic VISA Credit Card transactions of more than $200 with certain merchants, such as Big Lots, Food 4 Less, Kmart, Trader Joes, Safeway, Stater Brothers, Vons, and Wal-Mart, among others. This restriction is necessary to help protect your accounts against this type of fraud.
> 
> Should your transaction be declined as a result of this restriction, please contact our Credit Card Decline Assistance Line, toll-free, at 1-888-xxx-xxxx. They will validate your identity and allow your transaction to go through at the merchant site. If your merchant permits, you can also merely break your transaction into smaller transactions of $200 or less. These should go through fine.
> 
> Not all merchants and transactions will be affected by these restrictions. Your XXXXX Classic VISA Credit Card will still work perfectly fine at most restaurants, hotels, airlines and other VISA Credit Card merchants. XXXXX VISA Debit Cards are not affected by these restrictions at all.
> 
> We apologize for any inconvenience this may cause. We truly want to do the best we can to protect your accounts and hope to be able to lift these restrictions as soon as possible.
> 
> Please contact us at 800.xxx.xxxx, during normal business hours, should you have any questions.
> 
> Sincerely,
> 
> [etc.]

Weird. I’ve never heard of a blanket restriction like this. (Not that it affects me, as I don’t use that card at all.)

---

<div class="post-metadata">

**Author:** ![Leah\_M](https://avatars.discourse-cdn.com/v4/letter/l/57b2e6/32.png) [@Leah\_M](https://boards.straightdope.com/u/Leah_M)\
**Post date:** [December 13, 2008, 11:11am UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/2 "2008-12-13T11:11:44Z")

</div>

Doesn’t it seem kind of counterproductive to tell people they can just break up their transactions into multiple increments of 200$ or less?

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [December 13, 2008, 2:28pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/3 "2008-12-13T14:28:58Z")

</div>

I think they’re assuming that the fraudsters won’t know about the option, while legitimate users will.

---

<div class="post-metadata">

**Author:** ![LSLGuy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lslguy/32/5813_2.png) [@LSLGuy](https://boards.straightdope.com/u/LSLGuy)\
**Post date:** [December 13, 2008, 3:32pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/4 "2008-12-13T15:32:51Z")

</div>

I’d sooner assume the email is a phishing effort. … Card doesn’t work? Call our 800 number & tell our criminals all your account details so we can “fix” it.

Either that or it’s just a prank trying to launch a UL.

If I was the OP, I’d connect to Visa’s site (not using a URL found in the email) to see if they have any thing to either back up or debunk the email.

---

<div class="post-metadata">

**Author:** ![alphaboi867](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/alphaboi867/32/3898_2.png) [@alphaboi867](https://boards.straightdope.com/u/alphaboi867)\
**Post date:** [December 13, 2008, 3:39pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/5 "2008-12-13T15:39:31Z")

</div>

> [@Leah\_M](#):
>
> Doesn’t it seem kind of counterproductive to tell people they can just break up their transactions into multiple increments of 200$ or less?

Especially since many POS systems are set up to prevent exactly that.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [December 13, 2008, 3:44pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/6 "2008-12-13T15:44:53Z")

</div>

> [@LSLGuy](#):
>
> I’d sooner assume the email is a phishing effort. … Card doesn’t work? Call our 800 number & tell our criminals all your account details so we can “fix” it.
> 
> Either that or it’s just a prank trying to launch a UL.
> 
> If I was the OP, I’d connect to Visa’s site (not using a URL found in the email) to see if they have any thing to either back up or debunk the email.

I disagree. The email is from my credit union. The 800-number is the actual toll-free number to it. Googling the 888-number only returns three websites, but two of them are .org credit unions and one is a .com credit union. The format of the email and my name are correct. The link in the email (the ‘here’ in ‘To view this email as a web page, go here’) is correct.

But as I said, I don’t use this card. It’s my ‘last ditch, emergency’ card and I haven’t used it since I got my REI and airline miles cards.

---

<div class="post-metadata">

**Author:** ![Leah\_M](https://avatars.discourse-cdn.com/v4/letter/l/57b2e6/32.png) [@Leah\_M](https://boards.straightdope.com/u/Leah_M)\
**Post date:** [December 13, 2008, 3:52pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/7 "2008-12-13T15:52:42Z")

</div>

> [@Johnny\_L.A](#):
>
> I think they’re assuming that the fraudsters won’t know about the option, while legitimate users will.

Well, it is true that they wouldn’t have received the notice about it, but if they might think of it on their own, anyway.

---

<div class="post-metadata">

**Author:** ![bouv](https://avatars.discourse-cdn.com/v4/letter/b/bc8723/32.png) [@bouv](https://boards.straightdope.com/u/bouv)\
**Post date:** [December 13, 2008, 4:15pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/8 "2008-12-13T16:15:11Z")

</div>

> [@LSLGuy](#):
>
> I’d sooner assume the email is a phishing effort. … Card doesn’t work? Call our 800 number & tell our criminals all your account details so we can “fix” it.

How good is a phising scam if it only gives the criminals declined credit card numbers? 😕 You’d be better off just dialing phone numbers in the white pages and claiming to be from the cred card company and hope you get a confused old person.

---

<div class="post-metadata">

**Author:** ![Jane\_D\_oh](https://avatars.discourse-cdn.com/v4/letter/j/839c29/32.png) [@Jane\_D\_oh](https://boards.straightdope.com/u/Jane_D_oh)\
**Post date:** [December 13, 2008, 5:59pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/9 "2008-12-13T17:59:39Z")

</div>

> [@](#):
>
> Should your transaction be declined as a result of this restriction, please contact our Credit Card Decline Assistance Line, toll-free, at 1-888-xxx-xxxx. They will validate your identity and allow your transaction to go through at the merchant site. If your merchant permits, you can also merely break your transaction into smaller transactions of $200 or less. These should go through fine.

Most merchant agreements expressly forbid breaking transactions into smaller amount to get approvals. That this would be suggested in writing is VERY unusual. I would be interested to know if any of the mentioned merchants received anything from Visa. I don’t see anything out on the [Visa](http://usa.visa.com/merchants/risk_management/cisp_alerts.html) Merchant site about increased fraud or transaction limits but I only looked quickly. If I do find anything, I’ll post again.

---

<div class="post-metadata">

**Author:** ![Student\_Driver](https://avatars.discourse-cdn.com/v4/letter/s/3da27b/32.png) [@Student\_Driver](https://boards.straightdope.com/u/Student_Driver)\
**Post date:** [December 13, 2008, 6:11pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/10 "2008-12-13T18:11:12Z")

</div>

They should let their cardholders preemptively authorize their cards for \>$200 sales, perhaps on day-by-day basis. I’d be pissed if I wanted to purchase a cheap laptop or flatscreen at Wal-Mart for Christmas, as that’s hardly the type of purchase that can be broken into sub-$200 transactions, and delaying a line of fellow customers when my card is declined and I have to call the card company up, authorize the purchase, then re-ring everything is a bit much.

Around here, gas stations with pay-at-pump card readers all have prominent corporate-provided signage that tell users to break their large fuel purchases into smaller transactions when paying by card (between $50 to $100 depending on card brand) for the same reason-- card companies are denying large purchases at gas pumps due to fraud. If telling folks to break apart transactions is against merchant agreements, then a number of petrochemical conglomerates are in violation…

---

<div class="post-metadata">

**Author:** ![Jane\_D\_oh](https://avatars.discourse-cdn.com/v4/letter/j/839c29/32.png) [@Jane\_D\_oh](https://boards.straightdope.com/u/Jane_D_oh)\
**Post date:** [December 13, 2008, 6:45pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/11 "2008-12-13T18:45:50Z")

</div>

> [@Student\_Driver](#):
>
> …Around here, gas stations with pay-at-pump card readers all have prominent corporate-provided signage that tell users to break their large fuel purchases into smaller transactions when paying by card (between $50 to $100 depending on card brand) for the same reason-- card companies are denying large purchases at gas pumps due to fraud. If telling folks to break apart transactions is against merchant agreements, then a number of petrochemical conglomerates are in violation…

Sorry, I should have been more clear. Once a card is [declined](http://usa.visa.com/merchants/operations/chargebacks_dispute_resolution/preventing_chargebacks.html), going back and getting smaller auths is against merchant agreements. If you go out for $100.00 and then another, as long as there is no decline message, you are in compliance and have no risk of losing the transaction in a dispute.

If I were a cashier or manager at Trader Joe’s and didn’t see the letter mentioned above and someone came to me and said they wanted to pay with credit card X and wanted one auth for $200.00 and a second auth to cover the balance, I would think fraud and probably ask for a different form of payment. It’s just far enough outside the norm to raise a doubt.

---

<div class="post-metadata">

**Author:** ![Boyo\_Jim](https://avatars.discourse-cdn.com/v4/letter/b/87869e/32.png) [@Boyo\_Jim](https://boards.straightdope.com/u/Boyo_Jim)\
**Post date:** [December 13, 2008, 7:39pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/12 "2008-12-13T19:39:56Z")

</div>

A couple things here. First, I’s say this isn’t a “blanket” restriction… it applies only to certain specified vendors.

Second, it seems like Visa has identified vendors with very high rates of fraud, and put them on some kind of watch list. I’d be real suspicious that these vendors have security issues and perhaps can’t be trusted to leep my CC number secure. I would be especially concerned that employees at these vendors are retaining the numbers and using or selling them.

Lastly, I’m concerned that Visa doesn’t cancel its contract with these vendors, who seemingly can’t be trusted not to abuse your CC number.

---

<div class="post-metadata">

**Author:** ![Student\_Driver](https://avatars.discourse-cdn.com/v4/letter/s/3da27b/32.png) [@Student\_Driver](https://boards.straightdope.com/u/Student_Driver)\
**Post date:** [December 13, 2008, 8:27pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/13 "2008-12-13T20:27:16Z")

</div>

> [@Jane\_D\_oh](#):
>
> Sorry, I should have been more clear. Once a card is [declined](http://usa.visa.com/merchants/operations/chargebacks_dispute_resolution/preventing_chargebacks.html), going back and getting smaller auths is against merchant agreements. If you go out for $100.00 and then another, as long as there is no decline message, you are in compliance and have no risk of losing the transaction in a dispute.
> 
> If I were a cashier or manager at Trader Joe’s and didn’t see the letter mentioned above and someone came to me and said they wanted to pay with credit card X and wanted one auth for $200.00 and a second auth to cover the balance, I would think fraud and probably ask for a different form of payment. It’s just far enough outside the norm to raise a doubt.

Ahh, gotcha.

Having worked as a cashier in a few retail situations, I’d probably not blink an eye at a customer wanting to split their transactions up even without knowing of the suggestion by the bank. It’s pretty common for people to buy things in one trip for two purposes (personal and work use, personal and charitable use, or getting stuff for one’s self and a neighbor), and they need separate transactions for reimbursment.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [December 13, 2008, 9:23pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/14 "2008-12-13T21:23:32Z")

</div>

> [@Boyo\_Jim](#):
>
> it seems like Visa has identified vendors with very high rates of fraud, and put them on some kind of watch list.

I don’t think it’s a Visa thing. I think this is a move on the part of some credit unions who issue Visa cards.

> [@Boyo\_Jim](#):
>
> I’d be real suspicious that these vendors have security issues and perhaps can’t be trusted to leep my CC number secure. I would be especially concerned that employees at these vendors are retaining the numbers and using or selling them.

My presumption upon reading the email is that people who steal credit cards (the actual cards, not just the numbers) tend to shop at the stores enumerated. (Though Trader Joe’s surprises me.)

---

<div class="post-metadata">

**Author:** ![Jane\_D\_oh](https://avatars.discourse-cdn.com/v4/letter/j/839c29/32.png) [@Jane\_D\_oh](https://boards.straightdope.com/u/Jane_D_oh)\
**Post date:** [December 14, 2008, 12:45am UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/15 "2008-12-14T00:45:39Z")

</div>

> [@Boyo\_Jim](#):
>
> A couple things here. First, I’s say this isn’t a “blanket” restriction… it applies only to certain specified vendors.
> 
> Second, it seems like Visa has identified vendors with very high rates of fraud, and put them on some kind of watch list. I’d be real suspicious that these vendors have security issues and perhaps can’t be trusted to leep my CC number secure. I would be especially concerned that employees at these vendors are retaining the numbers and using or selling them.
> 
> Lastly, I’m concerned that Visa doesn’t cancel its contract with these vendors, who seemingly can’t be trusted not to abuse your CC number.

I assure you, declines are not industry specific.

When it comes to protecting your credit card information, merchants are required by [CISP](http://usa.visa.com/merchants/risk_management/cisp_overview.html) to maintain certain levels of security. If your information is compromised, the merchant is required to inform you. If Visa finds, during investigation after a security compromise, that you are not CISP compliant, you can be fined up to $500,000 and lose the right to accept Visa. Merchants don’t want this to happen. That’s why you don’t see full credit card numbers on credit card receipts anymore. Merchants have done other things as well to ensure your information is secure.

That’s why the info in the letter above is so odd. Generally you would get a letter from a merchant saying your card had been compromised and you should get a new card to ensure your safety. I can only imagine the card issuing bank has seen some fraud patterns locally and is trying to mitigate it. That’s why there’s nothing on the Visa website about the above mentioned vendors.

---

<div class="post-metadata">

**Author:** ![Boyo\_Jim](https://avatars.discourse-cdn.com/v4/letter/b/87869e/32.png) [@Boyo\_Jim](https://boards.straightdope.com/u/Boyo_Jim)\
**Post date:** [December 14, 2008, 4:52am UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/16 "2008-12-14T04:52:52Z")

</div>

> [@Jane\_D\_oh](#):
>
> I assure you, declines are not industry specific.
> 
> When it comes to protecting your credit card information, merchants are required by [CISP](http://usa.visa.com/merchants/risk_management/cisp_overview.html) to maintain certain levels of security. If your information is compromised, the merchant is required to inform you. If Visa finds, during investigation after a security compromise, that you are not CISP compliant, you can be fined up to $500,000 and lose the right to accept Visa. Merchants don’t want this to happen. That’s why you don’t see full credit card numbers on credit card receipts anymore. Merchants have done other things as well to ensure your information is secure.
> 
> That’s why the info in the letter above is so odd. Generally you would get a letter from a merchant saying your card had been compromised and you should get a new card to ensure your safety. I can only imagine the card issuing bank has seen some fraud patterns locally and is trying to mitigate it. That’s why there’s nothing on the Visa website about the above mentioned vendors.

Hi Jane, long time no chat!

I’m not sure if your first comment was directed at me, but no where did I suggest anything about “industry specific”.

My WAG is that Visa isn’t holding these vendors to the letter of their contracts – that they do so much business that Visa doesn’t want to lose that revenue, so they don’t cancel the contracts outright. Instead they’ve created some new rules meant to lower the risk to consumers, while not killing some of their golden egg vendors.

As a consumer I’m not at all happy to hear that Visa _knows_ specific vendors are associated in one way. shape or form with a much higher level of fraudulent transactions than the norm, yet continues to do business with them.

The is reminiscent of stories a few months back about Wachovia bank – they handled the internet transactions of several vendors they know to be fraudulent, but continued to service their accounts because they were so profitable. Not quite the same thing, but similar in principle.

---

<div class="post-metadata">

**Author:** ![Boyo\_Jim](https://avatars.discourse-cdn.com/v4/letter/b/87869e/32.png) [@Boyo\_Jim](https://boards.straightdope.com/u/Boyo_Jim)\
**Post date:** [December 14, 2008, 5:02am UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/17 "2008-12-14T05:02:16Z")

</div>

> [@Johnny\_L.A](#):
>
> I don’t think it’s a Visa thing. I think this is a move on the part of some credit unions who issue Visa cards.
> 
> My presumption upon reading the email is that people who steal credit cards (the actual cards, not just the numbers) tend to shop at the stores enumerated. (Though Trader Joe’s surprises me.)

Oops, I read Jane’s comments before I read yours. Are all of those stores local to you?

It seems very strange to me that credit card hieves would patronize such a select group of places. I suppose the professionals sell off the cards (?). Though I would also think the lowest risk fraudulent transactions would be online, not in person at retail stores.

---

<div class="post-metadata">

**Author:** ![Johnny\_L.A](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/johnny_l.a/32/1084_2.png) [@Johnny\_L.A](https://boards.straightdope.com/u/Johnny_L.A)\
**Post date:** [December 14, 2008, 5:27am UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/18 "2008-12-14T05:27:13Z")

</div>

AFAIK, they are all national chains.

It doesn’t seem strange to me that card thieves would use the cards at those stores. (Except for Trader Joe’s, since it strikes me as being more ‘upscale’ than Safeway.) Stores such as Wal-Mart and Kmart (and Big!Lots, formerly Pick-N-Save) tend to cater to the less affluent segments of society. I posited that stolen cards are being used by the thieves. My impression of the kind of person who would steal a card and then use it in a store (as opposed to a more sophisticated fraud) is that they are probably of a lower socioeconomic class and are probably more familiar with those stores than higher-end ones. (Note: I am emphatically not implying that poor people are thieves.)

If this is the case, then it would be reasonable that Wal-Mart has a higher incidence of fraudulent card use than, say, Nieman-Marcus. I’ve been inside of a Wal-Mart a half-dozen or so times in my life. As it happens, since a friend specifically asked for a Wal-Mart gift card for Christmas (she’s a ‘starving student’), I went there today. While I was there I finished my Christmas shopping and the total came to $199 and change. I used my Visa card (not the one from my credit union, from whence the email came) and the clerk did not check the signature or ask for ID. If this is how things are done, then it doesn’t surprise me that some credit unions would place the restrictions on the cards they issue.

---

<div class="post-metadata">

**Author:** ![Markxxx](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@Markxxx](https://boards.straightdope.com/u/Markxxx)\
**Post date:** [December 14, 2008, 6:40am UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/19 "2008-12-14T06:40:11Z")

</div>

I used to be an assitant controller and everything that email says goes against our merchant agreement. Once a card is declined it’s done with. I am looking at a copy of a merchant agreement and it says “Once a card is declined do not run it through again. If you do and it, for some reason, is given approval your transaction in this case will NOT be approved when you submit and if there is any chargeback you forfeit your rights.”

But there are many forms of decline, one says “forget it,” and the other says “Call.” If you call the merchant may OK it. Usually when Visa wants you to call, it’s due to something like you are using your card but didn’t first activate it from your home phone. The call is specific in that the MERCHANT places the call and hands the phone to you, not YOU making the call.

Merchants will NOT be happy with this arrangement, who wants to hold up a line while people call and get an OK. This seems very fishy to me.

The other thing is every merchant has it’s own agreement. In my hotel there were five levels we could choose from. And each have different standards.

---

<div class="post-metadata">

**Author:** ![susan](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/susan/32/17537_2.png) [@susan](https://boards.straightdope.com/u/susan)\
**Post date:** [December 14, 2008, 6:32pm UTC](https://boards.straightdope.com/t/visa-card-restrictions/476990/20 "2008-12-14T18:32:24Z")

</div>

Any reason not to contact the purported sender to determine whether it’s legit? Any evidence from the purported sender’s website to support the legitimacy of the e-mail?

[Next page](https://boards.straightdope.com/t/visa-card-restrictions/476990.md?page=2)
