BitPay upgraded its fraud-monitoring system today to consider signals across all cards in an account. Previously, each card's risk score was calculated independently - a fraud attempt on Card A did not affect the risk score on Card B. The new model considers signals across the entire account, so a successful attack pattern on one card is detected and propagated to other cards automatically.
Common scenario: an attacker gains access to Card A and tests small charges, looking for one that succeeds (a card where the small-charge pattern slips past 3DS). With per-card scoring, this is hard to detect - each individual charge looks legitimate in isolation. With account-level scoring, the cluster of small charges on Card A raises the risk score on Card B (same account) and triggers an alert, even before any of the test charges has succeeded.
Operators running 100+ card programs benefit most from this upgrade. A fraud pattern across 30 cards is invisible to per-card scoring but obvious to account-level scoring. The risk for large operators running multiple ad accounts or vendor streams drops significantly with account-level signals.
Operators can still see per-card risk scores in the history feed. Account-level signals are surfaced in aggregate form ('3 high-risk charges across cards this week, all routed to the same merchant') but not exposed at the individual-card level when triggered by a different card. Privacy and security boundaries are maintained.