About this tool
What to do when a card number leaks without CVV or expiry: kill the number, check pending charges for card-testing, and score how much worse it gets if more leaked with it.
The Card Number Exposure Checklist is for the specific case of a leaked card number without the CVV or expiry date — a lower-risk exposure than a full card dump, but not a harmless one. It scores two things: how far through the 16-step response you are, weighted towards killing the old number before card-testing scripts find it, and how much worse the leak gets if the dump also included the CVV, expiry, PIN or other identity fields. Unlike a home address or a date of birth, a card number can be rotated, and getting the issuer to reissue a genuinely new number — not just a new expiry on the same digits — is the single step that fully closes the leak.
Open Card Number Exposure Checklist on AltFTool — it loads instantly in your browser.
Under What else was in the same leak?, tick the categories that applied — Expiry date, CVV / CVC security code, Card PIN, Billing address, Online banking username or password — never the card number itself.
Work the four groups starting with Kill the number today, ticking steps such as Report the card as compromised, not lost or damaged and Confirm the replacement card has a different number.
Read the Response score, which is held at 69% while any critical step is open, plus the Do these next list, then press Copy result.
Distinguishes a leaked number alone from a full card number plus CVV and expiry, which needs a faster, harder response.
Reporting the card compromised and confirming the replacement has a different number outweigh clean-up tasks, and missing either caps the score.
You never type your actual card number — you tick which categories leaked, and nothing leaves the browser.
Less dangerous than a full card dump, but not safe. A bare number still passes the Luhn checksum, reveals your issuing bank through its first six to eight digits, and can be run through card-testing scripts against merchants that accept CVV-optional or recurring stored-card charges. Reissue it rather than assuming it is unusable.
Watch pending authorisations, not just settled transactions. Card-testing typically shows up as one or more small, oddly specific charges — sometimes under a dollar or a few units of local currency — used to confirm a number and any guessed CVV or expiry work before a larger charge follows.
It depends how you report it. A routine "lost or damaged card" replacement or an expiry-date renewal sometimes keeps the same underlying number. Telling the issuer the number was exposed in a breach gets it treated as compromised, which normally triggers a full number change, not just a new physical card.
Generally no, if you report it promptly. Visa's and Mastercard's zero-liability policies, and most card-issuer terms, cover unauthorised transactions you report in good time. This is general information, not legal advice — check your specific card's terms, and involve your bank immediately if a charge you did not make has already posted.