Blog post from Stripe:
https://stripe.com/resources/more/what-is-a-card-account-upd...
Blog post from Stripe:
https://stripe.com/resources/more/what-is-a-card-account-upd...
like
Visa: Visa Account Updater (VAU) https://developer.visa.com/capabilities/vau Mastercard: Automatic Billing Updater (ABU)
it worked fine for sometime, but the problem is that now the stolen credentials are being refreshed now as well.
Practically, it's of course not that simple or clear-cut. As most things in payments, this too is a trade-off of cardholder inconvenience, support effort, fraud losses etc.
It's bad service from GP's card company though, with network tokens they should be able to see which specific token was abused, and revoke just that one.
It was quite confusing, because a) I received a replacement physical card several months before the card expiry, so by the time my watch stopped working I'd entirely forgotten about it, b) there's no indication anywhere in the Android/Wear OS of what the expiry date is or that it might be expired and c) there's no indication at the point of sale that the virtual card is expired, simply a generic "Declined" message.
The token itself does also have an expiry date (it's a mandatory field in most protocols), but that can be updated as well, I believe.