Industry News

BOC Mastercard Fraud 2026: Brazil Charges, Apple Pay and the SPDB Replay

Bank of China Mastercards appear hit by mass fraud: Brazil-located charges, cards never leaving wallets, Apple Pay holders at the front of the queue. We brea…

BOC Mastercard Fraud 2026: Brazil Charges, Apple Pay and the SPDB Replay

What Happened: Brazilian Bills During the Mid-Autumn Holiday

Between September 25 and 26, 2026 (the Mid-Autumn holiday weekend), Chinese social media filled up with fraud reports from Bank of China Mastercard credit card holders. The first leak came from a blogger claiming knowledge of BOC's card center, describing a large-scale Mastercard fraud wave that had risk and IT teams working overnight. Weibo and Xiaohongshu users then posted matching screenshots: a middle-of-the-night Apple Pay notification saying the primary card was no longer valid, followed by the discovery that the card was locked and a new charge - or several - from a Brazilian merchant had landed on the account. Mainstream financial media including Sina Finance and Securities Times picked up the story on September 26.

From the public reports, the incident shows highly consistent patterns:

  • Card family: all Bank of China-issued Mastercard credit cards, with GBP cards the most affected and USD cards next - the classic multi-currency structure held by students and cross-border shoppers (product lines such as the Zhuojian series aimed at overseas use);
  • Geography: fraudulent transactions point almost exclusively to Brazil and other Latin American countries;
  • Card never left the wallet: multiple victims stated their physical cards had never been taken out or even used offline - textbook card-not-present fraud;
  • Inconsistent bank response: some users got a "suspected risky transaction" alert with automatic freeze; others only found out when the charge posted.

As of publication, Bank of China has not issued a formal statement on the cause or scale; the characteristics above come from cardholder reports and media coverage, and the scale cannot be independently verified. This article treats it as an apparent mass fraud event.

Mastercard Again, Brazil Again: An Almost Exact Replay of SPDB 2025

On September 9-11, 2025, Shanghai Pudong Development Bank's Mastercard "World" credit cards went through a nearly identical wave: hundreds of cardholders, every fraudulent charge pointing to Brazil, tightly synchronized timing, amounts from thousands to tens of thousands of yuan - including already-canceled cards and a card with 649 yuan of available credit that was hit for nearly 20,000. SPDB's card center issued a statement in the early hours of September 13, 2025 acknowledging unauthorized transactions and a joint emergency response with Mastercard. Caixin reported at the time that the likely cause was credential stuffing (card data bulk-harvested at some point in the chain, then cashed out in a coordinated run on the acquiring side).

Put the two events side by side:

  • Both are Mastercard-network foreign-currency credit cards from Chinese banks;
  • Both target card products aimed at overseas/student use (GBP and other foreign-currency accounts);
  • Both fraud waves concentrated in Brazil, in overnight hours;
  • Victims in both events overwhelmingly had the card bound to Apple Pay;
  • Both show the same combination: card never left the holder, card-not-present transactions, silent risk control.

The same script repeating within a year rules out a one-off breach of a single bank's internal systems. The more plausible common factor sits downstream: a leakage channel for bulk card data (PAN + expiry + CVV) somewhere in the acquiring, payment or merchant chain serving Chinese cardholders' overseas spending. Brazil has long been a card-fraud hotspot: lax acquiring-side risk controls, loosely integrated merchants, and card-not-present flows that often skip mandatory 3-D Secure. For a Chinese bank's Mastercard that has only ever been used for overseas online payments, once raw card data leaks, Brazil is the path of least resistance for testing and cashing out.

Is Apple Pay the Culprit? Almost Certainly Not - but It Reveals the Depth of the Leak

The reflexive first take is "Apple Pay got hacked." From a payments-architecture standpoint the opposite is true: Apple Pay uses device-bound dynamic tokens (DPAN). The token lives inside the secure-element handshake between the Apple device and the issuer; merchants and acquirers never see the real card number. If the leak had come from the Apple Pay rail itself, attackers would hold tokens that cannot be reused elsewhere - they could not fabricate card-not-present charges at Brazilian merchants.

The more coherent explanation: what leaked is raw card data (PAN/expiry/CVV), and its circulation has nothing to do with Apple Pay. "Only ever used Apple Pay" is a demographic marker, not a leak path: these holders are students and cross-border shoppers whose earlier overseas online purchases - flights, subscriptions, foreign e-commerce - are exactly where raw card data was exposed. The Apple Pay correlation reflects who holds these cards, not how they leaked. Until the bank publishes findings, this remains an architecture-based inference; an issuer-side or processor-side compromise cannot be excluded - notably, the SPDB incident was never publicly traced to a root cause either, which is itself an industry transparency failure.

The Cardholder View: Why Traditional Foreign-Currency Credit Cards Are Structurally Exposed

Two incidents in two years expose not one bank's failure but a structural weakness of the "Chinese bank foreign-currency credit card" product in card-not-present fraud:

  • Raw card data with a long life: one PAN lives for years, CVV is printed on the card, and every overseas card-not-present payment distributes the full raw data set. Once leaked, it stays valid until the card is replaced - in the SPDB case even canceled accounts were hit, showing limit and status checks were bypassed on the attack path;
  • Incomplete 3-D Secure coverage: whether a challenge appears depends on the acquiring merchant's configuration; Chinese-issued Mastercards clear many Latin American merchants with CVV alone, no extra authentication;
  • Silent risk control: many holders learned of charges after the fact - no warning before, no block during. A synchronized burst of small overnight charges is the most recognizable fraud pattern there is;
  • Detection falls on the cardholder: in both events the first wave of discovery came from cardholders and social media, not from the banks proactively reaching out.

This is part of why virtual cards (card numbers issued by virtual-card platforms) became popular for subscription management and cross-border shopping: a virtual card can be destroyed and reissued at will, with per-card spend caps and merchant restrictions; the "long-lived raw card data" problem is structurally compressed. Virtual-card platforms carry their own risks (platform solvency, balance custody, licensing) covered elsewhere on this site - the point here is not an endorsement but the underlying lesson: on the assumption that raw card data may already be circulating in fraud markets, shortening each card's life and capping each card's exposure is the most effective defense an ordinary user can deploy.

What To Do Now: A Layered Action List

If you hold a BOC Mastercard (whether hit or not)

  1. Check statements now: review every foreign-currency transaction of the past two weeks in the BOC app, focusing on Brazilian/Latin American merchants and overnight hours. Do not rely on SMS alone - both events had delayed or missing alerts;
  2. Lock it: the BOC app's card management offers payment locks that separately disable overseas card-not-present and overseas swipe transactions. If you are not traveling, lock overseas card-not-present around the clock and unlock only when needed - the cheapest defense there is;
  3. Dispute and document: for every suspicious charge, call BOC customer service immediately to file a dispute ("deny transaction"), keeping screenshots of alerts and statements. Under BOC's own security guidance, cardholders whose cards never left them can request stop-payment and denial of transaction. For larger amounts, file a police report - the case receipt is hard evidence for the dispute;
  4. Replace the card: if you see suspicious charges or have a history of frequent overseas online spending, request a replacement (new number). A lock is a switch; only a reissue kills the leaked PAN;
  5. Rebind: after replacement, update Apple Pay and every subscription, and scan for unrecognized merchant authorizations.

If you hold another bank's Mastercard/Visa foreign-currency card

Do not take comfort from "not my bank." SPDB (September 2025) and BOC (September 2026) show this is a chain problem, not a single-bank problem; every foreign-currency card faces the same acquiring environment. Same playbook: lock overseas card-not-present, set transaction limits, review statements regularly, rotate card numbers on heavily used cards. UnionPay-single-brand cards sit on a different network and authentication stack and have far less exposure to this Latin American card-not-present pattern.

Long-term habits

  • Concentrate overseas online spending on one or two cards and rotate them periodically - no workhorse card running naked for years;
  • Keep subscription billing and one-off purchases on separate cards;
  • Enable every transaction alert available (app push beats SMS);
  • On any overnight overseas charge alert, lock first and verify second - both fraud waves struck in the small hours.

Industry View: Three Questions These Two Incidents Must Leave Behind

First, who closes the liability and authentication gap in card-not-present fraud? After raw card data leaks, cardholders are theoretically protected by zero-liability rules and dispute mechanisms, but in practice dispute cycles run long and complaints of stonewalling appeared in both events. Cross-network liability assignment for domestically issued cards defrauded on overseas acquiring rails remains a gray zone; the SPDB incident was never publicly traced, leaving both public information and industry post-mortems empty.

Second, why does risk control only sound after the fact? Overnight, synchronized, small amounts, Latin American merchants, same BIN range - obvious in hindsight. Cardholders are entitled to expect issuers to intercept abnormal patterns and reach out proactively before the fraud completes, not to rely on an internal-source leak on social media to force the issue.

Third, the Apple Pay-issuer coordination gap. What victims received at 2 a.m. was Apple Pay's "card no longer valid" notice, not a bank fraud alert - device-side and issuer-side signals are not connected. For cards bound to Apple Pay, sharing fraud signals between Apple and issuers and stopping losses jointly at both token and PAN level is the most worthwhile engineering fix after two incidents.

Conclusion

From SPDB to BOC, the same script in one year proves the problem is not one card or one bank but the structural chain of long-lived raw card data, incomplete overseas card-not-present authentication, and lagging risk control. For cardholders the conclusion is plain: lock overseas card-not-present, rotate numbers, watch statements, and treat each foreign-currency card's exposure as a budget to be capped. For the industry, two years of public evidence now justify a serious root-cause investigation and remediation - the public can survive a third year, but there is no reason it should have to.

Incident facts in this article are sourced from Sina Finance, Securities Times, Financial News (Jinrong Yixian), Caixin, Observer.com and public cardholder reports (verified 2026-09-26/27). Cause and scale remain subject to Bank of China's official findings.