FAQs

What is a fallback authorization on a chip card?

A fallback authorization allows a card transaction to use the magnetic stripe after the chip fails to read at a chip-enabled POS terminal, ATM or ITM. Payment systems introduced fallback as a transaction-continuity measure, but the weaker authorization path creates fraud exposure. When an issuer approves fallback, it gives up dispute and chargeback rights and assumes liability for unauthorized losses.

How do criminals use skimmed card data in fallback attacks?

Criminals use skimmed card data by deliberately causing a chip transaction to fail and prompting a magnetic-stripe authorization instead. If the financial institution permits fallback, the transaction can proceed through the weaker path. The issuer then forfeits chargeback rights and bears resulting unauthorized fraud losses, making fallback especially attractive when bad actors possess compromised magnetic-stripe information.

Does every chip-card fallback transaction indicate fraud?

No. A legitimate cardholder can experience fallback when a chip or merchant terminal fails to process correctly. However, the article recommends treating every fallback transaction as a red flag because the same path is also used in fraud attacks. Financial institutions should investigate the activity, identify problematic merchants or terminals and educate cardholders to report chip-read failures.

Why does approving fallback shift fraud liability to the card issuer?

Approving fallback shifts fraud liability because the issuer authorizes a magnetic-stripe transaction even though the card and terminal support chip technology. Under the framework described in the article, that approval causes the issuer to forfeit dispute and chargeback rights. Credit unions and banks must therefore weigh transaction convenience against the possibility of absorbing unauthorized fraud losses.

How can credit unions block fallback fraud at ATMs and ITMs?

Credit unions can block ATM and ITM fallback by allowing only POS 05 chip authorizations and, where supported, POS 07 contactless authorizations with Merchant Category Code 6011 for electronic cash disbursements. This configuration declines magnetic-stripe fallback attempts. Institutions should coordinate the change with their ATM/ITM authorization provider and keep terminals chip-enabled and updated.

How should financial institutions monitor POS fallback authorizations?

Financial institutions should establish monitoring that detects and flags fallback transactions, then regularly review authorization reports for suspicious activity and recurring merchant or terminal problems. The article also suggests considering limits on POS fallback amounts within a 24-hour period. Identified noncompliant merchants or problematic terminals should be reported to the appropriate card association.

What should cardholders do when a chip card fails to read?

Cardholders should use a contactless chip-card feature or mobile wallet when the terminal supports it instead of automatically swiping the magnetic stripe. They should also report chip-read failures to their financial institution. These actions help the issuer investigate possible card or terminal problems, address merchant compliance and reduce exposure to magnetic-stripe fallback fraud.