# Mastercard Threat Intelligence
source: https://developer.mastercard.com/mastercard-threat-intelligence/documentation/index.md

## Overview {#overview}

Mastercard Threat Intelligence provides payment-focused cyber threat intelligence to help issuers and acquirers detect, monitor, and respond to emerging fraud and ecosystem threats. It combines Mastercard network insights with cyber threat intelligence to help organizations assess risk, investigate suspicious activity, and support fraud and security operations.

The Mastercard Threat Intelligence API provides programmatic access to this intelligence through REST APIs. You can use the API to evaluate merchant domain risk, identify vulnerabilities affecting payment and e-commerce software, and investigate card testing activity using structured search, filtering, sorting, and pagination capabilities.

The service supports issuer and acquirer workflows related to merchant risk assessment, fraud investigation, cyber-security monitoring, and operational decision-making. By enabling direct integration with internal applications and workflows, the API enables threat intelligence data to be incorporated into automated monitoring, investigation, and risk management processes.

### What You Can Do {#what-you-can-do}

The Mastercard Threat Intelligence API provides three intelligence insights.

|   |              Capability Area              |                                                                                                    Description                                                                                                     |                       Primary Users                       |
|---|-------------------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------|
|   | **Merchant Threat Intelligence**          | Assess merchant domain risk using payment-related fraud and cyber threat indicators.                                                                                                                               | Acquirers, merchant onboarding teams, merchant risk teams |
|   | **Payment Ecosystem Threat Intelligence** | Identify high-risk vulnerabilities affecting payment and e-commerce software.                                                                                                                                      | Issuers, acquirers, cybersecurity teams                   |
|   | **Card Testing**                          | Investigate suspected card testing activity, merchant behaviors associated with card testing, and transactions linked to card testing patterns. Issuers find compromised cards. Acquirers find affected merchants. | Issuers, acquirers, fraud operations teams                |


Merchant Threat Intelligence   
Merchant Threat Intelligence helps you evaluate the risk associated with merchant web domains. You submit one or more merchant domains with a reason for the inquiry. The API returns risk intelligence related to malware, phishing, payment fraud, suspicious hosting, suspicious activity, and other cyber indicators associated with a domain. This capability can be used during merchant onboarding, underwriting, investigation, and ongoing portfolio risk monitoring.

<br />


Payment Ecosystem Threat Intelligence   
Payment Ecosystem Threat Intelligence provides visibility into high-risk vulnerabilities that may affect payment and e-commerce software. The service returns Common Vulnerabilities and Exposures (CVE) records with risk scores, severity labels, lifecycle phases, and affected products. This intelligence enables organizations to prioritize remediation efforts and assess exposure across their payment ecosystem.

<br />


Card Testing   
Card Testing intelligence provides insight into card testing activity occurring across the payment ecosystem. The API exposes three complementary views that support issuer and acquirer investigations:

<br />

|         View          |                             Purpose                             |
|-----------------------|-----------------------------------------------------------------|
| **Observed Testing**  | Merchants confirmed to have been used for card testing activity |
| **Testing Behaviors** | Merchant behaviors indicative of card testing risk              |
| **Transactions**      | Authorization attempts identified as card testing events        |

These capabilities help organizations identify compromised cards, monitor merchant exposure, investigate suspicious activity, and take preventative actions before downstream fraud occurs.

## How It Works {#how-it-works}

![How It Works](https://static.developer.mastercard.com/content/mastercard-threat-intelligence/uploads/how-it-works-mti-api-v3.png)
![Authenticate](https://static.developer.mastercard.com/content/mastercard-threat-intelligence/uploads/how-it-wors-step1.svg)
Step 1: Authenticate   
Your application obtains an access token using OAuth 2.0 and sends it with each request. ![Choose a capability](https://static.developer.mastercard.com/content/mastercard-threat-intelligence/uploads/how-it-wors-step2.svg)
Step 2: Choose a capability   
You call the endpoint for Merchant Threat Intelligence, Payment Ecosystem Threat Intelligence, or Card Testing. ![Shape the request](https://static.developer.mastercard.com/content/mastercard-threat-intelligence/uploads/how-it-wors-step3.svg)
Step 3: Shape the request   
You narrow results with free-text search, field filters, date and numeric ranges, sorting, and pagination. ![Mastercard resolves the query](https://static.developer.mastercard.com/content/mastercard-threat-intelligence/uploads/how-it-wors-step4.svg)
Step 4: Mastercard resolves the query   
The service evaluates your request against its intelligence, combining payment network visibility with cyber threat research. ![Receive a structured response](https://static.developer.mastercard.com/content/mastercard-threat-intelligence/uploads/encrypt_entire.svg)
Step 5: Receive a structured response   
Results return as JavaScript Object Notation (JSON) with categories, risk scores, severity labels, timestamps, and pagination details. ![Act on insights](https://static.developer.mastercard.com/content/mastercard-threat-intelligence/uploads/improved.svg)
Step 6: Act on the insights   
You feed the intelligence into onboarding, fraud investigation, cybersecurity, and risk decisions.

*** ** * ** ***

### Threat Intelligence Workflows {#threat-intelligence-workflows}

#### Merchant Risk Assessment {#merchant-risk-assessment}

Organizations can submit one or more merchant domains for evaluation. The API returns risk indicators, categorized findings, timestamps of observed risks, and overall domain report information. This information can support merchant onboarding, due diligence, underwriting, and ongoing monitoring activities.

#### Vulnerability Assessment {#vulnerability-assessment}

Security teams can search high-risk vulnerabilities affecting payment and e-commerce software using free-text search and vulnerability filters. Results include severity labels, lifecycle phases, risk scores, affected products, Common Vulnerabilities and Exposures (CVE) identifiers, and vulnerability descriptions.

#### Card Testing Investigations {#card-testing-investigations}

Card testing intelligence enables fraud operations teams to search and investigate:

* Merchants directly associated with observed card testing activity.
* Merchants exhibiting card testing behavior classifications.
* Card testing authorization attempts with strong indicators of fraud.

Search capabilities support filters, sorting, date ranges, risk scores, merchant identifiers, terminal identifiers, institution identifiers, and transaction attributes.

## Good to Know {#good-to-know}

### Onboarding {#onboarding}

To access the Mastercard Threat Intelligence API in Production, you must onboard through Mastercard Developers and obtain access to the required product capabilities. Access to the API may depend on your organization's enrollment and authorization level. Access to a capability, and to specific data, is scoped to your organization. See [Quick Start Guide](https://developer.mastercard.com/mastercard-threat-intelligence/documentation/quick-start-guide/index.md) for more details.

### Testing Information {#testing-information}

The API provides a Sandbox environment that enables developers to validate connectivity, authentication, request construction, filtering behavior, and response handling before moving to Production. No product enrollment is required for Sandbox. Customers create a project, obtain keys, and can immediately begin Sandbox testing. Sandbox testing should be completed before requesting Production access.

### Mastercard Threat Intelligence UI {#mastercard-threat-intelligence-ui}

Mastercard Threat Intelligence UI provides a user-friendly interface for customers who prefer to explore and analyze intelligence without direct API integration. The UI is accessible through [Mastercard Connect](https://www.mastercardconnect.com) and allows authorized users to search and review threat intelligence, analyze threat details and context, and investigate indicators surfaced through Mastercard Threat Intelligence.

In addition to the capabilities exposed through Mastercard Threat Intelligence API, the UI provides access to additional intelligence content and reporting, such as:

|   |          UI Capabilities          |                                                                                                                                                                                                                                                                                        Description                                                                                                                                                                                                                                                                                        |
|---|-----------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
|   | **Payment Intelligence Reports**  | Facilitates cross-functional intelligence sharing, providing timely, comprehensive, and actionable insights. They offer in-depth reports using our network-level visibility to identify the most pressing trends, risks, and payment fraud subject-matter expertise. This is complemented by the Threats \& Trends capability offered under Payment Ecosystem Threat Intelligence, which provides ongoing situational awareness through curated highlights on emerging payment threats, fraud schemes, threat actor activity, and industry developments affecting the payments ecosystem. |
|   | **Digital Skimming Intelligence** | Provides customers with quantitative data that allows users to understand skimmer impacts while promoting collaboration to combat skimming activity by leveraging Mastercard's ongoing work with industry partners to disrupt malwares targeting the payment card ecosystem.                                                                                                                                                                                                                                                                                                              |

### Data Protection {#data-protection}

Returned data may contain sensitive threat intelligence information, merchant identifiers, transaction attributes, and fraud indicators. You should ensure appropriate controls are implemented to govern access, storage, retention, and operational use of the data within your organization.

### Region Availability {#region-availability}

This API service is available globally; however, certain use cases are restricted to specific regions and will expand over time.

## Next Steps {#next-steps}

After becoming familiar with the capabilities of the Mastercard Threat Intelligence API, continue with the following documentation sections:

1. **[Quick Start Guide](https://developer.mastercard.com/mastercard-threat-intelligence/documentation/quick-start-guide/index.md)** -- Learn how to obtain access, create a project, generate credentials, and make your first API request.
2. **[API Basics](https://developer.mastercard.com/mastercard-threat-intelligence/documentation/api-basics/index.md)** -- Understand authentication, security requirements, environments, and client configuration.
3. **[Use Cases](https://developer.mastercard.com/mastercard-threat-intelligence/documentation/use-cases/index.md)** -- Explore common issuer, acquirer, fraud operations, and cybersecurity workflows supported by the API.
4. **[API Reference](https://developer.mastercard.com/mastercard-threat-intelligence/documentation/api-reference/index.md)** -- Review endpoint specifications, request schemas, response schemas, and error models.
5. **[Testing](https://developer.mastercard.com/mastercard-threat-intelligence/documentation/testing/index.md)** -- Validate your integration using Sandbox test scenarios and operational workflows before moving to Production.
