July 2025 Summaries
4 posts from Evervault
Filter
Month:
Year:
Post Summaries
Back to Blog
Visa's 2025 Acquirer Monitoring Program (VAMP) introduces significant changes to payment fraud monitoring by consolidating various regional programs into a unified global system, thereby increasing compliance pressures on Payment Service Providers (PSPs). The key elements of VAMP include the introduction of a consolidated VAMP ratio that tracks both fraud and disputes for card-not-present transactions, as well as a new enumeration tracking system to monitor card testing attacks. These changes necessitate a shift in fraud management strategies, rendering traditional dispute resolution methods less effective and emphasizing proactive measures like 3D-Secure (3DS) for fraud prevention and liability shift. Implementing 3DS 2.x is crucial, as it provides enhanced data exchange for risk assessment and shifts liability for fraud chargebacks from merchants to issuing banks. The program's enforcement timeline spans from an advisory period in 2025 to stricter thresholds in 2026, compelling PSPs to adopt robust fraud prevention infrastructure to remain compliant and competitive, particularly in high-risk merchant segments. The evolving regulatory landscape underscores the necessity for PSPs to move from reactive to preventive approaches in managing disputes, with 3D-Secure becoming a pivotal component of compliance and competitive strategy.
Jul 30, 2025
1,466 words in the original blog post.
Visa's new changes to the Acquirer Monitoring Program (VAMP), effective April 2025, significantly impact high-risk merchants by including previously excluded resolved disputes from Rapid Dispute Resolution (RDR) and Cardholder Dispute Resolution Network (CDRN) into overall fraud rate calculations. This shift necessitates that high-risk merchants, often dealing with high dispute rates due to the nature of their industries such as gambling and digital goods, adapt their strategies beyond traditional chargeback management. 3D-Secure (3DS), a protocol designed to add an extra security layer for online transactions, becomes critical in managing fraud rates as it shifts liability from merchants to card-issuing banks upon successful authentication, thus reducing TC40 fraud reports that contribute to VAMP calculations. The implementation of 3DS is crucial for payment service providers (PSPs) to help merchants stay under the new fraud thresholds while maintaining conversion rates. The advisory period until October 2025 offers a grace period without penalties, but high-risk merchants must adopt comprehensive fraud prevention tools like 3DS to navigate the evolving compliance landscape successfully.
Jul 16, 2025
2,777 words in the original blog post.
The webinar on 3D-Secure for high-risk payments discussed various aspects of 3DS implementations, including its impact on approval rates and the differences in how European and US issuers handle transactions. While data-only transactions don't significantly enhance approval rates, they provide valuable fraud intelligence. The 3RI (3DS Requestor Initiated) process is beneficial for recurring transactions, though its success rates in the US are generally lower than in the EU. Standalone 3DS solutions offer advantages over acquirer-provided solutions, such as consistent user experience and greater flexibility, while issuers require accurate merchant data for effective fraud prevention. Although the effectiveness of 3DS varies by market, with higher success in Europe, the US is expected to improve as the system becomes more widely adopted. For high-risk merchants, the correct Merchant Category Code (MCC) must be used to maintain liability shift protections under 3DS.
Jul 14, 2025
817 words in the original blog post.
The process of online payments begins with the client entering sensitive cardholder data, which must be protected through encryption to prevent unauthorized access and ensure compliance with standards like PCI DSS v4.0. Traditional encryption methods, using algorithms such as AES-256 and TLS 1.2+, face challenges in key management and maintaining compliance, often burdening engineering teams with complex processes and documentation. Evervault offers an alternative by providing encryption-as-a-service, simplifying the integration of payment security through a single SDK call or by routing traffic via Relay, a proxy that ensures data is encrypted immediately. Their solution involves performing cryptographic operations within AWS Nitro enclaves, ensuring that raw cardholder data never reaches application servers, thus enhancing security and easing compliance burdens. This approach allows teams to maintain control over payment pipelines while reducing the operational load associated with traditional encryption methods, enabling flexibility in payment processing and adherence to PCI DSS requirements.
Jul 11, 2025
1,575 words in the original blog post.