Citi Hong Kong is preparing to launch what it describes as the city’s first Virtual Credit Card with a Dynamic Card Validation Code, or CVC, giving eligible Mastercard customers a new way to protect their card details when making online payments.
The service, being introduced in partnership with Mastercard, will generate a new, one time use CVC for each online transaction. Customers will access the virtual card through the Citi Mobile App, allowing them to make digital purchases without routinely exposing the security details associated with their physical credit card.
Citi said the new service is designed to address one of the most persistent problems in digital payments: card not present fraud. These transactions take place when a customer pays online or through another digital channel without physically presenting a card. According to Citi, nearly 80 percent of credit card fraud attempts are linked to such transactions.
One time security code for online payments
The main feature of Citi’s new virtual card is its Dynamic CVC. Instead of relying on a fixed three digit security code, the system generates a unique code for each new transaction.
The code is time limited. If a customer generates a Dynamic CVC but does not use it within the period in which it remains valid, the code will automatically refresh the next time the customer views it in the Citi Mobile App.
That process is intended to make stolen card information considerably less useful to criminals. Even if a fraudster obtains a virtual card number and a previously generated CVC, the information cannot simply be reused indefinitely because the security code changes.
The approach adds another layer of protection to online card payments, where customers may have little visibility into how their card information is stored or processed after a transaction.
For consumers, the distinction is important. A physical credit card generally carries the same card number and security information from one purchase to another. If those details are exposed through a compromised website, fraudulent transaction, data breach or other means, criminals may attempt to use them elsewhere.
A changing CVC reduces that window of opportunity by making the security code specific to a particular transaction and period of validity.

Designed for ecommerce and recurring payments
Citi said eligible Mastercard credit card customers in Hong Kong will be able to access the new Virtual Credit Card through the Citi Mobile App in the coming months.
The virtual card is intended primarily for digital transactions rather than replacing the physical card altogether. Customers will continue to use their physical cards for ordinary in person purchases, while the virtual version can be used for online shopping, subscriptions, recurring payments and mobile wallets.
That distinction could be particularly useful for consumers who regularly enter card details into online services.
Subscription services, for example, often require customers to save payment credentials for recurring charges. Ecommerce platforms can also retain card information to make future purchases faster. A virtual card gives customers another set of credentials to use in these digital environments, reducing the need to expose the details printed on their physical card.
Mobile wallets provide another use case as digital payments become increasingly integrated into smartphones and other connected devices.
The service does not eliminate the need for customers to monitor their accounts or take basic security precautions. Instead, Citi is positioning it as an additional safeguard built into the payment process.
Mastercard technology behind the service
The new offering also draws on Mastercard’s tokenization technology.
Tokenization replaces sensitive payment information with an alternative digital identifier, known as a token, which can be used to process transactions without repeatedly exposing the underlying card credentials.
Helena Chen, senior vice president and general manager for Hong Kong and Macau at Mastercard, said the virtual card would combine the company’s tokenization capabilities with a changing security code to protect cardholders during digital transactions.
“The Virtual Credit Card with Dynamic CVC leverages Mastercard's tokenization capabilities to safeguard cardholders' credentials,” Chen said.
She added that the technology reflects Mastercard’s wider efforts to improve consumer protection as digital commerce expands.
The partnership gives Citi access to payment security infrastructure that is designed for increasingly complex online transactions. For customers, however, much of the underlying technology will remain largely invisible. Their interaction with the service will take place through the Citi Mobile App, where they can access their virtual card and its current Dynamic CVC.
Fraud risk shifts toward digital payments
The move comes as banks and payment networks face a fraud environment that has changed significantly with the growth of online shopping.
Traditional card fraud often involved the physical theft or duplication of a card. Digital commerce has created different opportunities for criminals. Card details can be stolen without the physical card ever leaving the customer’s possession.
A compromised online merchant, phishing attack, malicious software or other form of credential theft can expose payment information remotely. Once criminals obtain usable card details, they may attempt unauthorized purchases through online merchants.
Citi’s estimate that almost 80 percent of credit card fraud attempts involve card not present transactions illustrates why banks are putting greater emphasis on digital security.
Virtual cards address part of that problem by separating online credentials from the physical card. Dynamic CVC technology adds another barrier by ensuring that the security code does not remain static.
The model also gives customers greater control over where their card credentials are used. Instead of entering the information printed on their everyday card whenever an online service requests payment details, customers can use the virtual credentials for digital transactions.
That can limit the potential impact if those details are later exposed.

Citi positions digital security as part of banking experience
Sarah O, head of digital growth and cards and unsecured lending sales at Citi Hong Kong, said the new service was intended to make online payments safer while keeping the process straightforward for customers.
“The upcoming launch of Hong Kong's first Virtual Credit Card with Dynamic CVC reflects how we are leveraging digital innovation to make online payments safer, easier and more reassuring,” she said.
O also pointed to the continuing threat posed by card not present fraud as digital commerce grows.
She said services such as the new virtual card should increasingly be viewed as part of responsible digital banking rather than simply an additional feature offered by a bank.
That reflects a wider shift in the financial services industry. Security tools are increasingly being built directly into banking applications, reducing the need for customers to rely entirely on their own security practices after a transaction has taken place.
Instead of asking customers to respond only after suspicious activity appears, banks are attempting to prevent stolen information from remaining useful in the first place.
What customers can expect
Citi has not said that the virtual card will replace conventional credit cards. Its stated purpose is to provide eligible Mastercard customers with a separate option for digital payments.
Customers will continue to have access to their physical cards for everyday purchases at stores and other locations. For online transactions, subscriptions, recurring charges, ecommerce purchases and mobile wallets, the virtual card will provide an alternative set of credentials.
The Dynamic CVC will change as required, meaning customers will need to obtain the current code through the Citi Mobile App when making transactions that require it.
If a generated code expires without being used, Citi said the system will refresh it automatically when the customer views the code again.
The service is expected to become available to eligible Citi Mastercard credit card customers in Hong Kong over the coming months.
For Citi, the launch represents an attempt to respond to a specific and growing weakness in digital payments: the continued exposure of card credentials during transactions that take place entirely online. By combining a virtual card number, a changing CVC and Mastercard’s tokenization technology, the bank is seeking to make stolen payment details harder to reuse.
For customers, the practical benefit is straightforward. The card in their wallet can remain reserved for physical purchases, while a separate digital card can handle much of their online spending, with its security code changing rather than remaining permanently fixed.


