A bank identification number, or BIN, is the first six to eight digits of a payment card that identify the issuer, the network, and the type of card. Those digits let a merchant route the transaction correctly and let a fraud team judge risk before a single dollar moves.
What is a BIN?
Every payment card number starts with a block of digits that acts like a routing label. That block is the bank identification number, sometimes now called the issuer identification number, or IIN. It was six digits for decades and is expanding to eight as the pool of numbers runs short. The rest of the card number identifies the individual account, with a final check digit.
When a card is used, systems read the BIN to answer basic questions instantly: which network is this, which bank issued it, is it credit or debit, and is it a consumer or commercial product. That is enough to route the transaction to the right places and to apply the right pricing and rules.
For fraud and risk work, the BIN is a compact risk signal. It links a card back to its issuer and product, which lets a team spot mismatches, apply issuer-specific rules, and recognize when many cards being tested all trace to the same narrow BIN range.
What the digits actually tell you
A BIN lookup turns a string of numbers into a short profile of the card. The main fields a team reads are below.
What the BIN reveals | Why it is useful |
Card network | Tells the system which network rules and routing apply to the transaction. |
Issuing bank | Identifies the bank behind the card, so issuer-specific patterns and risk can be applied. |
Card type | Credit, debit, or prepaid, which changes both the risk profile and the cost. |
Product level | Consumer, commercial, or premium, useful for both pricing and fraud scoring. |
Issuing country | The country of the issuer, which can be checked against the customer and shipping details. |
What it looks like in practice
A checkout starts seeing a wave of tiny authorizations, most of them declined. A fraud analyst pulls the card numbers and notices that almost all of them share the same BIN, meaning they trace to one issuer and one card product.
That is the fingerprint of a BIN attack: a fraudster took a known BIN and generated valid-looking card numbers around it, then ran them through the site to find live ones. The team rate limits by BIN, adds a challenge on that range, and alerts the issuer, cutting the testing off before the working cards can be sold or cashed out.
Why BINs matter for fraud teams
The BIN is one of the cheapest risk signals available, because it is present on every transaction and needs no extra data from the customer. It lets a team catch mismatches, such as a card issued in one country paired with a billing address and device that sit somewhere else entirely, and it lets rules treat prepaid, commercial, or high-risk issuer ranges differently from ordinary consumer credit.
It is also how fraud at scale gives itself away. Card testing and BIN attacks tend to cluster within narrow BIN ranges, so watching authorization patterns by BIN surfaces an attack far faster than watching individual cards. The flip side is that BINs are coarse: a single BIN covers many real customers, so a BIN signal should sharpen a decision, not make it alone.
What to watch in the data
- BIN concentration. A sudden cluster of new cards sharing one BIN, especially with high decline rates, points to a BIN attack or a leaked card batch.
- Country mismatch. An issuing country that does not line up with the customer's address, device, or IP deserves a closer look.
- Prepaid where it is odd. Prepaid BINs on products that expect a durable account can signal throwaway cards used for fraud.
- Commercial cards in consumer flows. Business-card BINs appearing in a consumer signup can hint at misuse or testing.
- Stale or invalid BINs. Card numbers with BINs that no active issuer owns are a sign of generated or fabricated card data.
Quick questions
Is a BIN the same as the full card number?
No. The BIN is only the leading six to eight digits that identify the issuer, network, and product. The remaining digits identify the specific account, ending in a check digit, and those are the sensitive part that must be protected.
Is a BIN sensitive data on its own?
The BIN alone is not enough to charge a card, and BIN directories are widely available. It becomes sensitive only when paired with the rest of the card number, expiry, and security code, so BINs can be used in risk logic without exposing a full account.
What is a BIN attack?
A fraudster takes a known BIN and generates many candidate card numbers around it, then tests them at merchants to find the ones that are live. Clusters of low-value authorizations sharing a BIN are the classic sign, and rate limiting by BIN is a common defense.
Why are BINs moving from six to eight digits?
The supply of six-digit BINs was running out as more issuers and card products came online. Expanding to eight digits enlarges the pool, but it means older systems and BIN tables need updating to read the longer prefix correctly.
Can I block a whole BIN?
You can, but with care. A single BIN covers many legitimate customers, so a blanket block risks turning away good users. It is usually better to add friction or rate limits on a suspect BIN rather than to decline it outright.
O que saber junto com Bank Identification Number (BIN)

Relatório de Fraude e AML 2026
Esqueça as previsões. Este relatório detalha com o que as equipes de fraude e AML estão realmente lidando, e como responder.

