Back to all articles

When Your Card Expires or Gets Reissued

Card networks push your new number to merchants automatically — except when they don't, and the gaps are worth auditing after any reissue.

When Your Card Expires or Gets Reissued

Two Massachusetts banks, The Village Bank and Main Street Bank, sent breach notices in 2026 telling customers that a merchant-side compromise had exposed their Mastercard debit card number, expiration date, and security code — and that a new card was already in the mail. Nobody asked for this. The card simply changes, and every merchant billing the old number has to deal with it somehow, usually without telling you how.

How the new number travels without you doing anything

Visa's Account Updater (VAU), Mastercard's Automatic Billing Updater (ABU), and American Express's Cardrefresher all do the same basic job: they let an issuer push a new account number, new expiration date, or closure notice out to the merchants who already have your old card on file. Visa's own developer documentation puts a number on how often this matters — on average, 30% of the accounts in an issuer's VAU portfolio get a new number, new expiry, or closure in a given year. The standard flow has the merchant's acquirer query VAU right before processing a charge, then forward any update to the merchant within two business days; a "Real Time" version works inside VisaNet and can return the new data within a single authorization step. Mastercard's ABU explicitly lists lost, stolen, expired, and reissued cards as the change types it carries, and a card is typically enrolled by default the moment you hand a merchant your number for recurring billing. Amex runs the leanest version: Cardrefresher only pushes data outward to a merchant's processor — there's no merchant-side query step at all.

Where the update quietly never arrives

None of this works unless three separate parties have opted in: the card network, your issuing bank, and the merchant's payment processor. Miss one link and nothing updates — the subscription just hits a hard decline at the next billing date, indistinguishable from a merchant that never signed up for any updater service in the first place. Visa and Mastercard route enrollment through acquirers, so a merchant can't sign up on its own; Discover and Amex are the only two networks that let a merchant enroll directly, and Discover charges for the privilege — a one-time $500 setup fee plus $0.10 per update received, and even then only for cards whose issuing bank has also joined Discover's program — a strange thing to charge for when Visa and Mastercard hand the same service out for free. If you want to see which of your merchants are actually wired up, Chase's mobile app has a "Stored Cards" tool (More → Stored Cards) that lists everyone holding your card from the past nine months, flags which ones auto-update versus which don't, and in some cases offers a one-tap cancel — Chase says those providers "usually cancel unwanted subscriptions within three business days."

The one case where the update is supposed to stop — and sometimes doesn't

Expiration and routine reissue are the easy case: the network just pushes the new data through. Confirmed fraud is supposed to be different. Visa's protocol includes a "Contact Cardholder Advice" response — telling the merchant to reach you directly instead of silently updating — and an issuer-level opt-out that can persist for up to two years, or indefinitely, until the issuer removes it. Visa frames the whole service as existing to reduce "the chance of declined payments, service interruptions, [and] late fees" — and that's the tension I keep bumping into: a system built to make updates happen by default was never going to be good at making them stop.

UK consumer group Which? surveyed 2,079 adults in March 2026 and found 61% of card-fraud victims from the prior two years saw more fraud on their replacement card within three months of getting it. Opt-out availability varied by bank: Starling offered no general opt-out at all, only auto-opting customers out after fraud was already confirmed; Monzo let customers opt out only during the card-ordering flow itself; Barclays, HSBC, Lloyds, Nationwide, NatWest, and Santander offered no opt-out whatsoever. Which?'s own senior researcher, Faye Lipson, had fraudulent Uber charges flagged in July; her bank reissued the card; in August, the same fraudulent Uber account was charged again using her brand-new card details, because the updater had pushed them straight to the account the fraudster had saved. Her bank needed a third card and a full account wipe to break the link. UK Finance's defense of the default-on design — blocking merchants from updates "can cause unintended consequences" — is technically true, and I don't see how it helps anyone whose new card just got charged by the same fraudster twice.

What to actually check after any reissue

Here's what I'd run before assuming the new card "just works" the way the old one did:

  1. Pull at least 12-13 months of statements against the old card, not just the last one — annual charges (membership fees, storage, software licenses) are the ones nobody remembers signing up for, and they're exactly the type most likely to survive silently or vanish silently.
  2. If your issuer has a tool like Chase's Stored Cards, check it first — it already knows who has your new number and who doesn't.
  3. For anything not flagged as updated, log in and change the card manually. A hard decline from a dead card number doesn't resolve itself on retry the way a low-balance soft decline sometimes does.
  4. If the reissue followed confirmed fraud, specifically check whether the merchant tied to that fraud somehow still has working card details — that's the exact failure mode in the Lipson case, and it's worth a second reissue if it shows up.
  5. Note the difference between a reissue (same account, new number) and closing the account outright, which merchants handle differently — see what happens when you cancel a credit card entirely if that's your situation instead.

Annual billers are the easiest thing to lose track of in this audit — see the annual renewal trap for the pattern. Running the statement pull through something like Subnesio turns step one into a filtered list instead of 13 months of line-by-line scrolling.

Your bank solved its fraud problem the day it mailed the new card. Whether your subscriptions did too depends on who, if anyone, checked the merchant side.

Frequently asked

Do I need to update my card on file after my card is reissued?
Only for merchants that aren't enrolled in your network's updater service (Visa VAU, Mastercard ABU, or Amex Cardrefresher) through both your issuer and the merchant's processor. If any one of those three links is missing, the charge won't update itself and will hard-decline at the next billing date.
Why did a fraudulent charge follow my card after I got a new number?
The same account-updater service that keeps legitimate subscriptions running can also push your new card details to a merchant account a fraudster saved under the old number, unless your issuer specifically flagged the reissue as fraud-related and applied an opt-out or contact-cardholder response.
How do I find out which merchants already have my new card number?
Some issuers, like Chase through its in-app Stored Cards tool, show which merchants on file auto-update versus which require a manual change. Otherwise, pull your last 12-13 months of statements against the old card and check each recurring charge by hand.
Is a card reissue the same as cancelling a card outright?
No. A reissue keeps the same underlying account and just changes the number, which is what lets updater services silently carry subscriptions forward; closing the account entirely triggers a different, 'closed account' response that forces merchants to contact you directly instead.
S
The Subnesio Journal
Notes on subscription management, written by people who got tired of forgetting their own renewals.
Try Subnesio

We use analytics (PostHog, EU servers) to improve Subnesio. No ads, no selling data. Privacy Policy