Even Anonymous Credit Card Data Can Be Used to Identify You (2024)

New research shows the ease in which we can re-identify supposedly anonymous credit card data with credit card user's personal information.

By William Herkewitz
Even Anonymous Credit Card Data Can Be Used to Identify You (1)

Whether you're making a phone call, sending a text, or just buying a cup of coffee with your credit card, you're creating a constant stream of electronic data. It turns out this data could be used to track you—even if it doesn't have your name on it.

According to Yves-Alexandre de Montjoye, an MIT computer scientist, even totally private metadata—that is, data completely stripped of all person information like names and phone numbers—may not be as anonymous as we'd like to believe. In a new study, he and his colleagues took an anonymized credit card record of 1.1 million people. The researchers found that more than 90 percent of the time, comparing just 4 simple pieces of outside information (for example, if someone shopped at a specific store on a given day) was enough to identify someone. This means that the researchers could connect real people's identities (for example, William Herkewitz) to their anonymous avatar in the "private" data set (say, shopper#2232_8) for every single interaction that was recorded. Having even more specific information, like the exact price someone paid at restaurant, made re-identification 22 percent more likely.

"The takeaway is that we really need to rethink what it means when something is 'anonymized'. With regard to this data, anonymous is not a binary term; it's not black and white. And when we run the risk of reconnecting personal information, we should take that into account when we release and share data," de Montjoye says.

Redefining "Anonymous"

The new research could spur governments to update what is known in privacy law as PII— legalese for personally indefinable information. This is important, because how PII is defined by government bodies underlies how, if, and when your potentially private information is shared or released. For example, your credit card company would have to evaluate exactly how much of a risk there is of you getting re-identified before they could release anonymous metadata that you're included in, even if its been scrubbed of your private info.

For years, privacy policy experts like Paul Schwartz at the University of California, Berkeley, have argued that government policy and law should reflect a more nuanced view identifiable information—which he calls PII 2.0. The new definition, Schwartz stated in a Bureau of National Affairs bulletin back in 2012, should consist of "…two categories of PII, 'identified' and 'identifiable' data," alongside non-identifiable data, and "treat them differently." This would allow lawmakers to differentiate between shades of data that are technically anonymous, but, as the new study shows, run the risk of re-identification.

Data For Good

While de Montjoye agrees that PII 2.0 is the logical next step, he also emphasizes that we should pursue methods to make use of anonymized data—such as the credit card data he used in his study—without giving ourselves the ability to manipulate it and sacrifice privacy. He points to the openPDS project, which he is part of, that lets scientists and researchers "ask questions and get answers from such data, without giving them complete control over it," he says.

Much of this information is stored, and, government surveillance aside, "there are actually a lot of genuinely good uses for that data, if we are conscientious about people's privacy," de Montjoye says. "In the sciences, we can use it in fascinating new ways to answer really old sociological questions, as well as questions about the economy and consumption."

Even Anonymous Credit Card Data Can Be Used to Identify You (2)

William Herkewitz

Science & Technology Reporter

William Herkewitz is a science and technology journalist based in Berlin, Germany. He writes about theoretical physics, AI, astronomy, board games, brewing and everything in between.

Watch Next

Even Anonymous Credit Card Data Can Be Used to Identify You (3)

Advertisem*nt - Continue Reading Below

Security

Save 30% on the Arlo Pro 4 Security Cam at AmazonCould AI Really Have Thoughts and Feelings?How Memes Could Save Us From the SingularityDeepfakes Are Everywhere—Here’s How to Spot Them

Advertisem*nt - Continue Reading Below

WormGPT: What is it and Should You Be Worried?From Popular Mechanics for Siren MarineThe Siren 3 Pro Is Making Boating Easier Can We Contain AI Before We Reach SingularityHow to Find Hidden Cameras In Your Airbnb
Why Russian ‘Hybrid Warfare’ Failed in UkraineSuperhuman Algorithms Could 'Kill Everyone'Report: Global Catastrophic Cyber Event ComingWiFi Signals Can See People Through Walls

Advertisem*nt - Continue Reading Below

Even Anonymous Credit Card Data Can Be Used to Identify You (2024)

FAQs

Even Anonymous Credit Card Data Can Be Used to Identify You? ›

A security researcher has shown it's possible to identify the owner of a credit card from among millions of "anonymized

anonymized
Data anonymization has been defined as a "process by which personal data is altered in such a way that a data subject can no longer be identified directly or indirectly, either by the data controller alone or in collaboration with any other party." Data anonymization may enable the transfer of information across a ...
https://en.wikipedia.org › wiki › Data_anonymization
" charges by knowing just a handful of that person's purchases.

What type of data is credit card information? ›

Account Data represents all the data that can be found on a credit card. Account Data is further broken down into either Cardholder Data (CHD) or Sensitive Authentication Data (SAD). Cardholder data (CHD) includes the 16-digit PAN, expiration date, and cardholder name.

Can credit card usage be tracked? ›

Credit card activity can be tracked. When you use a credit card for transactions, whether it's for purchases, payments, or withdrawals, a trail of electronic records is generated. These records include the merchant's name, transaction date, amount, and sometimes even the location.

Are credit card payments traceable? ›

The authorities typically track fraudulent credit card transactions by: Checking transaction timestamp and IP address. Using geolocation tracking. Investigating the buyer's data and further account activity.

Can I get a credit card without ID? ›

Not every card issuer will accept an alternative form of identification, such as a passport or an ITIN, but several do. Among the major issuers that are more flexible in their requirements are: American Express (accepts SSN, ITIN, or passport)

Is credit card data personal data? ›

This information could be names, addresses, emails, telephone numbers, and bank or credit card details. It can also include more sensitive information, such as people's health data or their criminal records.

What is the use of credit card data? ›

Use Cases
  • Fraud Detection. One of the main use cases of credit card data is fraud detection. ...
  • Customer Behavior Analysis. Credit card data is also used for customer behavior analysis. ...
  • Risk Assessment and Credit Scoring. Credit card data plays a crucial role in risk assessment and credit scoring.
Apr 15, 2024

How can I find someone by their credit card number? ›

Unfortunately, that is not something that can be done easily. Credit card numbers are confidential, and banks do not provide a way to look up the name and address of a cardholder based on the number. In the US, the information is protected by the Fair Credit Billing Act and the privacy policies of the individual banks.

Are credit card records confidential? ›

Under California law, financial service companies must get your permission first, before they can share your personal financial information with outside companies. This does not apply to sharing with outside companies that offer financial products or services.

What is the most common way credit card data is stolen? ›

Remember: the most common type of individual card theft is through phishing. If a scammer has access to other personal information, it can lead to many other kinds of identity theft.

Are credit card payments anonymous? ›

Some credit card companies and banks offer masking services. These services allow you to carry out transactions with your real credit card or bank account without revealing personal details.

Do credit cards have GPS tracking? ›

In conclusion. Smart chips on credit and debit cards cannot be physically tracked. Their security features help protect your account information, but they do not help you locate a card if it gets lost or stolen.

How private are credit card transactions? ›

When you pay a merchant without using a Privacy Card, you provide your credit or debit card number, CVV, and expiration date. This sensitive data can be intercepted or stolen by third parties, leaving you vulnerable to data breaches and fraudulent card activity.

What is a Nova credit card? ›

These credit cards from our partners are options for newcomers to the United States. Nova Credit helps newcomers use their foreign credit history to apply for products in the U.S.

What credit card does not require SSN? ›

Chase Freedom Rise℠ *: Best credit card for no Social Security number. Capital One Quicksilver Secured Cash Rewards Credit Card *: Best for flat-rate cash back. Petal® 2 “Cash Back, No Fees” Visa® Credit Card *: Best for no deposit requirement.

Can I open a credit card without SSN? ›

Many financial institutions require an SSN on an application for a new account, so not having one can make it difficult to get a credit card, open a checking or savings account, or get a loan. Fortunately, some banks and credit card issuers open up their applications to residents who do not have an SSN.

Is A credit card a nominal or Ordinal? ›

Other examples of nominal data include: your name, your credit card number, and the name of the city where you were born. The key distinction is that nominal values have no natural order to them.

What is the data classification of credit card number? ›

Credit Card information is classified as High Risk Data per Yale's Data Classification Policy. Credit Card Numbers are also subject to the Payment Card Industry Data Security Standards. This is commonly referred to as PCI DSS or PCI.

Is credit card information sensitive data? ›

Examples of Sensitive Data

The clue to sensitive data is to ask whether it includes information that can be used to paint a profile of an individual's financial and health information. The former includes sensitive PII like the following: Social security numbers. Credit cards.

Is credit card information sensitive personal data? ›

Pay particular attention to how you keep personally identifying information: Social Security numbers, credit card or financial information, and other sensitive data. That's what thieves use most often to commit fraud or identity theft.

Top Articles
Latest Posts
Article information

Author: Amb. Frankie Simonis

Last Updated:

Views: 5985

Rating: 4.6 / 5 (56 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Amb. Frankie Simonis

Birthday: 1998-02-19

Address: 64841 Delmar Isle, North Wiley, OR 74073

Phone: +17844167847676

Job: Forward IT Agent

Hobby: LARPing, Kitesurfing, Sewing, Digital arts, Sand art, Gardening, Dance

Introduction: My name is Amb. Frankie Simonis, I am a hilarious, enchanting, energetic, cooperative, innocent, cute, joyous person who loves writing and wants to share my knowledge and understanding with you.