Situation

A retailer tells you that your payment-card number and expiration date may have been captured.

Contact the issuer, not the breached merchant, for card controls

The breached company can explain the incident, but the card issuer controls the card number, transaction authorizations, alerts, and replacement process. Use the number printed on the card or statement and tell the issuer that the card details were exposed.

Ask whether it recommends replacing the card immediately or monitoring first based on what was exposed.

Review both posted and pending transactions

Look for small test charges as well as larger purchases. An unfamiliar merchant descriptor can be confusing, so search your receipts or ask the issuer before labeling every odd name as fraud.

Report confirmed unauthorized transactions through the issuer’s fraud channel and keep the case number.

Secure the online account that manages the card

If the card issuer’s account password was reused or could also have been exposed, change it and review enrolled devices, contact information, and alert settings. A replacement card number does not fix a compromised online login.

Turn on transaction notifications if available so you can see activity quickly.

Update legitimate recurring payments after replacement

If the issuer changes the card number, make a list of subscriptions and bills that use the old card. Some merchants may receive updated credentials automatically through card-network updater services, while others may fail and require manual changes.

Do not send the new number in response to an unsolicited call claiming to help with the breach.

Use credit protection only for the data that calls for it

A compromised card number alone is a different problem from an exposed Social Security number. If the same breach also exposed identity information used for new-credit fraud, then a freeze or fraud alert may make sense. Match the tool to the data, rather than applying every identity-theft control to every card breach.

Keep the breach notice because it documents why the card was replaced even after the account itself is secured.

Distinguish the card number from the account login

A retailer can expose a card number without exposing the password to your issuer account, and a compromised issuer login can exist without a merchant breach. Ask which problem you are solving. Replacing the card addresses the payment credential; changing the issuer password addresses account access. If both are at risk, do both.

Review digital wallets and stored-card locations after a replacement so you know where the old credential may remain.

Use issuer alerts as a short-term detection layer

Turn on notifications for card-present purchases, online purchases, cash advances, or transactions above a threshold if the issuer offers those options. The exact alert controls differ by card, but immediate visibility can help you report unauthorized activity quickly.

Do not approve an unfamiliar transaction because a caller says approving it is necessary to “reverse” fraud. Use the issuer’s app or known phone number to resolve a questionable charge.

Preserve the merchant notice if the issuer asks why you replaced the card

Most replacement processes are straightforward, but keeping the breach notice can still be useful if multiple cards were affected or if a later fraud investigation asks when you first learned the credential was exposed. Record which card was replaced and the date the new card became active.

Destroy or securely dispose of the old physical card once the issuer tells you it is no longer needed, and update only the legitimate merchants that require the new number.

Example: a merchant says payment data may have been captured

Use the issuer number printed on the card or statement and tell the fraud team exactly what the merchant notice says was exposed. Ask whether the issuer wants to replace the card immediately and whether it sees any suspicious authorization attempts. Review pending as well as posted transactions; small unfamiliar charges can be tests, while odd merchant names can also be legitimate descriptors that the issuer can help identify.

If the issuer replaces the card, activate the new card through a verified channel and update only the subscriptions or bills that truly need the new number. Review digital wallets and saved-payment locations so you know which services have been refreshed automatically and which require action. Secure the issuer’s online account separately if the password or recovery channel might also be at risk.

Keep transaction alerts enabled for the next several weeks and save the merchant breach notice with the card-replacement record. A card replacement is usually narrower than an SSN response. If the same notice also lists Social Security, driver’s-license, or other identity data, add the appropriate identity-protection steps instead of treating the new card as a complete solution.

  • Contact the issuer, not only the merchant.
  • Review pending and posted activity.
  • Replace the card when the issuer recommends it.
  • Secure the issuer login separately.
  • Add credit freezes only if identity data warrants them.

Close the replacement loop

After a new card is active, verify that important recurring payments such as utilities, insurance, and subscriptions are using the correct credential. Some merchants update automatically while others do not, so watch for failed payments as well as fraud alerts. Remove the old card from digital wallets and saved-payment profiles where it remains visible. Keep the issuer’s fraud or replacement confirmation until you are satisfied that all disputed activity and legitimate billing have been handled.

Replace only the card credentials that were actually exposed

If several cards were used with the breached merchant, verify which card numbers were actually involved rather than replacing every card automatically. The breach notice or issuer may identify the affected account more precisely. A targeted response reduces unnecessary billing disruption while still letting you move quickly on the credential that was exposed.

Primary sources used

Check the official source before you submit sensitive information.