Vendor-reported figures — source: www.americanbanker.com
Card enumeration attacks represent one of the most disruptive fraud vectors in modern payment networks: automated bots systematically test millions of potential account number combinations, probing authorization endpoints until they identify valid credentials. In the Payment & Transaction sector, where decisioning occurs in milliseconds, the window between a successful enumeration and account monetization is extremely narrow. Fraudsters increasingly began using generative AI to accelerate and scale these attacks, rendering earlier rule-based and traditional ML detection tools insufficiently responsive. These attacks were responsible for approximately $1.1 billion in annual global losses — roughly 10% of total global card fraud — underscoring the systemic risk to issuers and cardholders alike.
Visa upgraded its Visa Account Attack Intelligence (VAAI) platform — originally launched as a machine learning tool in 2019 — by integrating a generative AI model following more than a year of internal experimentation. The new model was trained on over 15 billion annual VisaNet transactions, using noisy data and deep learning techniques to synthesize data patterns that closely resemble known enumeration attack signatures. Rather than replacing existing VAAI infrastructure, the generative AI layer was embedded directly into the scoring pipeline, enabling the system to evaluate up to 182 risk attributes per transaction and return a two-digit risk score within a millisecond. The updated VAAI Score is delivered to card issuers in real time, integrating into existing authorization workflows without requiring changes to issuer-side systems — reducing adoption friction across Visa's global issuer network. No external vendor was identified; the model was developed within Visa's internal risk engineering organization.
The generative AI-enhanced VAAI Score delivered measurable improvements across both detection accuracy and issuer experience. The model incorporates six times the fraud-detection features of its predecessor, substantially expanding coverage of enumeration attack patterns. False positives — a persistent friction point where legitimate transactions are incorrectly blocked — dropped by 85%, protecting issuer revenue and cardholder trust simultaneously. Real-time scoring operates within one millisecond, giving issuers an actionable signal before fraudsters can monetize a compromised account number. The system directly targets the estimated $1.1 billion in annual global losses attributed to enumeration attacks.
Have a similar implementation?
Share your customer's AI results and link it to your vendor profile.
Submit a case study →