Back to JournalDigital & Crypto

Virtual Card Numbers Explained: Safer Online and Subscription Spending

14 min readLast updated: 2026-07-18

By the NorwegianSpark Editorial Team · Written with AI assistance.

A phone held to a contactless card reader on a shop counter

Disclosure: This article may contain affiliate links. If you click and make a purchase, we may earn a commission at no extra cost to you. See our full disclosure.

Every time you type your real card number into a website, you hand that merchant a key to your account and trust them to keep it safe. Most do. Some get breached. A virtual card number lets you stop trusting and start controlling — a disposable or locked stand-in for your real card that you can cancel, cap, or tie to a single merchant without ever touching your actual account.

What a Virtual Card Number Actually Is

A virtual card number is a real, working card number generated by your provider that draws from the same account as your physical card but carries its own number, expiry, and security code. You use it exactly like a normal card online. The difference is that it is disposable: if it leaks in a data breach, you delete that one number and your physical card — and every other virtual card — keeps working untouched.

Think of it as a firewall between the merchant and your money. The merchant only ever sees the stand-in. Your real card details never leave your banking app.

The Mechanism: What Happens Inside the Authorisation

The part most explanations skip is where the substitution actually occurs. Your real card number — the industry calls it the primary account number, or PAN — is the single credential that identifies your funding account to the card network. When a merchant charges you, that number travels from the merchant to their acquiring bank, across the network, to your issuer, which approves or declines.

A virtual card inserts a second number into that chain. Your issuer mints a fresh PAN from its own range, records internally that this number maps to your account plus whatever rules you attached, and hands it to you. The merchant charges the virtual number. The network routes it to your issuer exactly as it would any other card. Your issuer looks up the mapping, applies your rules — is this merchant allowed, is this within the limit, is this card still alive — and only then approves against your real balance or credit line.

Two consequences follow, and they are the whole point. First, the rules live at the issuer, not the merchant, so a merchant cannot ignore or override them. Second, the merchant never receives anything that identifies your underlying account, so a breach of their database yields a number that is already fenced in.

The card networks formalised this logic separately. Under the EMVCo payment tokenisation framework, the industry standard is to remove "the most valuable data to a fraudster, the primary account number (PAN)," and replace it with a token that "is constrained in how it can be used. For example, to a specific merchant, device or payment scenario." EMVCo's stated aim is that tokenisation "reduces the value of stolen or compromised payments information, as an EMV Payment Token should not be usable beyond a specific merchant, device or payment scenario." A merchant-locked virtual card applies exactly that principle at the level you control.

Virtual Cards, Network Tokens and Wallets Are Not the Same Thing

People conflate three different mechanisms, and the differences decide which one protects you.

MechanismWhat the merchant ends up holdingWho sets the rulesStrongest at
Real card typed inYour actual PAN, expiry, CVCNobodyNothing — this is the exposed case
Apple Pay / Google PayA device-bound network tokenThe network and your issuerIn-app and tap-to-pay, not typed checkouts
Network token on fileA merchant-bound token, provisioned invisiblyThe network and the merchantCard-expiry continuity, not your control
Virtual card numberA separate PAN you generatedYou, at your issuerAny typed card field, on any site

The practical distinction: wallet and network tokens are provisioned for you and can be updated without your involvement, which is convenient but means you did not choose the boundary. A virtual card number is a credential you created, named, capped and can destroy on demand. It is the only one of the four that works in an ordinary web checkout form where you must type sixteen digits.

Why the Online Channel Is Where the Damage Concentrates

Card fraud has migrated decisively to remote payments. The Federal Reserve's study of US payments fraud found that the fraud rate by value for remote card payments reached 18.71 basis points in 2016, against 9.34 basis points for in-person payments — roughly double. Over the same year, in-person card fraud fell from $3.68 billion to $2.91 billion while remote card fraud grew from $3.40 billion to $4.57 billion. Chip cards made counterfeiting a physical card hard; they did nothing about a number typed into a form.

Put that basis-point figure in terms you can feel: 18.71 basis points is $1.87 of fraud per $1,000 of remote card spending, versus $0.93 in person. Small per transaction, but it is the number that decides how many merchant databases are worth attacking.

Europe attacked the same problem from the authentication side. In the joint ECB and EBA assessment, total EEA payment fraud across all instruments reached €4.3 billion in 2022 and €2.0 billion in the first half of 2023, with card fraud on EEA-issued cards representing 0.031% of the total value of card payments. Crucially, the report found that "fraud rates for card payments were ten times higher when the counterpart was located outside the EEA, where the application of SCA is not legally required." Strong customer authentication works — but it only binds where the law reaches. When you buy from a merchant outside that perimeter, the number itself is the last line of defence, which is precisely when a merchant-locked or single-use card earns its keep.

The Three Types, and When to Use Each

Single-use cards are generated for one transaction and expire the moment it clears. Ideal for a one-off purchase from a site you do not trust or will never use again — a marketplace seller, a ticket reseller, a shop you found through an ad.

Merchant-locked cards bind to the first merchant that charges them and reject everyone else. This is the workhorse for subscriptions: one card for your streaming service, another for your gym, another for your cloud storage. If any of those merchants is breached, or quietly passes the number on, no one else can charge it.

Budget or recurring cards stay open but carry a hard spending limit you set. These suit variable bills where you want a ceiling: cloud computing, ad spend, or a service with a history of creeping price rises.

What the Law Actually Gives You — and Where Virtual Cards Sit

This is the part that changes how you should use them, and almost nobody explains it.

Your statutory protection depends on the rails underneath the card, not on whether the number is virtual. The US Federal Trade Commission sets out the tiers plainly, and the gap between credit and debit is large.

SituationCredit cardATM / debit card
Reported before any unauthorised useNot responsibleNot responsible
Reported within 2 business days of learningMaximum $50Maximum $50
More than 2 business days, within 60 days of statementMaximum $50Maximum $500
More than 60 calendar days after statement sentMaximum $50All money taken, and possibly more
Number used, card never lost or stolenNot responsibleNot responsible if reported within 60 days of statement

Read the bottom row carefully, because that is the virtual-card scenario: your number leaks, your card stays in your pocket. On a credit card you are not responsible for charges you did not authorise, full stop. On a debit card the same outcome is conditional on you noticing and reporting within 60 calendar days of the statement being sent.

Now the uncomfortable part. Most fintech virtual cards — the ones issued by multi-currency accounts and business spend platforms — run on debit or prepaid rails, not credit. In the US, prepaid accounts were brought under a dedicated regime: the CFPB's prepaid rule requires institutions to investigate and resolve errors, to provisionally credit a disputed amount if the investigation runs long, and caps responsibility at $50 "as long as the consumer promptly notifies their financial institution." That is real protection, and it is a floor, not the ceiling a credit card gives you.

The honest conclusion: a virtual card number reduces your operational exposure enormously and your statutory exposure not at all. It shrinks the blast radius, shortens the time a leaked number stays valid, and removes the merchant's ability to bill you again. It does not upgrade a debit card's legal position to a credit card's. If you are buying something high-value, high-dispute-risk, or from a merchant you genuinely doubt, the strongest combination is a credit card behind a virtual number — not a virtual number instead of a credit card. Outside the US the specifics differ, but the structural point holds everywhere: check which rails your provider uses before assuming the protection.

A Worked Example: What a Spending Cap Is Actually Worth

Take the failure mode virtual cards are best at — the subscription that creeps upward while you are not looking.

Suppose a business tool bills you €19.99 a month. You put it on a budget virtual card with a hard limit of €25 a month, chosen as roughly 25% headroom above the expected charge. Eighteen months later the provider raises the price to €27.99 with an email you never opened.

On your ordinary card, that charge clears silently. You pay €8 a month more than you agreed to. Over the next 24 months before you happen to audit your statements, that is €8 × 24 = €192 you did not decide to spend, on one line item.

On the budget card, the €27.99 authorisation exceeds the €25 ceiling and is declined. You get a failed-payment email the same day. You then make an actual decision: accept the new price and raise the limit, or leave. The card did not save you €192 by being clever. It saved you €192 by converting a silent default into a visible choice — which is the entire mechanism, and it is why the limit should sit just above the expected charge rather than comfortably above it. A €100 ceiling on a €19.99 subscription catches nothing.

Scale that across a business with, say, twelve tools on one shared card and the arithmetic stops being a rounding error. It is also why the audit matters more than the tooling: a virtual card with a lazy limit is a virtual card that never fires.

Where to Get Virtual Card Numbers

Not every bank offers them, and the good implementations differ by who you are.

Wise, available in most countries worldwide, gives personal and business users disposable virtual cards alongside its multi-currency account. Because Wise converts at the mid-market rate with no foreign-transaction fee on currencies you hold, a Wise virtual card is doubly useful for international online shopping — it protects the number and kills the FX markup at once. For the currency side of that, see our guide to cards that eliminate foreign transaction fees.

Wallester Business, for EEA and UK companies, is built around virtual cards at scale: you can issue a large number of virtual expense cards, each with its own limit and rules, and assign them to staff or specific vendors. For a company drowning in shared-card chaos, this is the structural fix — every subscription and every employee gets a controllable card of its own. The setup path is covered in our walkthrough on opening a Wallester business expense-card account.

Airwallex, a global business account, offers virtual cards with team spend controls as part of its multi-currency platform, which is why it appears so often across our business credit cards coverage. For a business paying international SaaS tools and contractors, a per-vendor virtual card keeps both the security and the accounting clean — the reconciliation benefit is often worth more staff hours than the security benefit is worth in avoided fraud.

For travellers and location-independent workers, virtual cards are close to essential — you are constantly entering card details into unfamiliar booking sites and local services. Our digital nomad finance guide treats them as a core part of the stack, and freelancers running a one-person business will find the same tools in our roundup of money tools for the self-employed.

Taming Subscriptions With Merchant-Locked Cards

Here is a practical system. Audit your recurring charges once. For each one you want to keep, issue a merchant-locked virtual card and update the subscription to use it. Now every subscription is isolated: a price rise you did not agree to, a service that will not let you leave, or a breach at any one provider affects that card alone. For anything you are unsure about — a trial, a commitment you are testing — use a budget card with a limit just above the expected charge, so nothing can overbill you.

The side benefit is visibility. Because each card maps to one merchant, your statement reads like a labelled list rather than a wall of processor names you do not recognise.

They also defuse the two most common subscription traps. First, the free trial that silently converts: put a single-use or low-limit card on it and it simply cannot bill you when the trial ends. Second, the subscription you cannot find the cancel button for — freeze or delete the merchant-locked card and the charge fails, no phone call required. It is a backstop, not a substitute for cancelling properly. Killing the card ends the payment; it does not end the contract, and a determined provider can still pursue the debt or send it to collections. Cancel properly, then kill the card as insurance.

The Limitations and Failure Modes Worth Knowing

Virtual cards break in specific, predictable ways.

  • Card-present situations. They generally do not work where the physical card must be produced — hotel check-in, car-hire deposits, anything that swipes or taps. Some venues also insist the card presented at collection matches the one used to book.
  • Refunds to a dead card. If you delete a single-use card and then return the item, the refund is pushed back to a number that no longer exists. Most issuers route it to the underlying account anyway, but not all, and chasing it is slow. Keep the card alive until the return window closes.
  • Pre-authorisation and later capture. Petrol stations, hotels and car hire authorise one amount and capture another, sometimes days later. Single-use cards and tight budget cards decline the capture. Use a merchant-locked card with headroom instead.
  • Incremental and variable billing. Usage-based services — cloud compute, advertising platforms — can spike far above the normal charge. A cap that protects you can also take your production infrastructure offline. Cap deliberately, not reflexively.
  • Address and name checks. Some merchants verify the billing address or cardholder name against the issuing record. Virtual cards issued by a business account may carry the company's details, not yours, and fail the check.
  • Disputes and chargebacks. Your dispute rights follow the underlying account, not the virtual number, but deleting the card early can complicate the evidence trail. Keep the transaction record before you delete anything.

There is also a behavioural trap: spreading spend across many numbers can obscure how much you are actually spending. The fix is the discipline any card demands — track the total, pay the statement in full, and treat the tool as protection, not permission.

Who Should Not Bother

Virtual cards are a poor fit for a few people, and pretending otherwise wastes their time.

If almost all your spending is in person, at a handful of merchants, on a credit card with strong dispute rights, the marginal gain is small — the FTC table above already caps your exposure at $50 and in the number-leak scenario at nothing. If you travel constantly and your bookings routinely require the physical card at collection, you will spend more time working around declines than you save in avoided fraud. If you struggle to keep track of what you have signed up for, adding a dozen card numbers to the pile makes the problem worse, not better; fix the audit first, then add the tooling. And if your provider's implementation is clumsy — cards that take several taps to generate, no naming, no per-card limits — you will stop using it within a month, which is worse than never starting.

The Bottom Line

A virtual card number is the cheapest security upgrade available to an online spender: it costs nothing beyond the account you already have, and it shrinks the damage of any breach to a single merchant. Use single-use cards for one-off buys, merchant-locked cards for every subscription, and budget cards for anything variable — with the ceiling set just above the expected charge, not comfortably above it. Wise covers individuals and travellers worldwide; Wallester and Airwallex bring the same control to EEA/UK and global businesses respectively.

The one thing to keep straight: the virtual number is a containment tool, not a legal upgrade. Your dispute rights come from the rails underneath. Put the strongest rails you have behind the disposable number, and you get both.

For a wider view of where digital money tools sit alongside traditional banking, our sibling sites go deeper: https://bestaiglobalbank.com examines how AI-era banking is reshaping account security, and https://banktopp.com compares the accounts and cards that offer features like these.

This is information, not financial advice. Card features, fees and availability change, and consumer-protection rules differ by country — confirm current details with each provider and your own regulator before relying on them.

Frequently Asked Questions

Are virtual card numbers safe to use?

They are safer than typing your real card number into a website. A virtual card draws from the same account but carries its own details, so if it leaks in a breach you delete that one number and your physical card keeps working. The main limit is that they do not work where the physical card must be present, such as hotel check-in or car-hire deposits.

Do virtual card numbers cost money?

With providers that offer them, virtual cards are usually free to generate as part of the account you already hold. Business platforms may bundle them into a paid tier for large-scale issuing. Any currency conversion or foreign-transaction cost depends on the underlying card, not on the fact that it is virtual.

Can I use a virtual card for subscriptions?

Yes, and it is one of the best uses. A merchant-locked virtual card binds to the first merchant that charges it and rejects everyone else, so one card per subscription isolates each service. If a provider is breached or you cannot find the cancel button, you freeze or delete that single card and the charge fails.

Related Journal Entries