Virtual Account Numbers: Security, Customer Recognition, and Dispute Handling

Chargebacks?
No longer your problem.
Recover 4x more chargebacks and prevent up to 90% of incoming ones, powered by AI and a global network of 20,000 merchants.
TL;DR:
- A virtual account number (VAN) is a temporary or limited-use number that replaces a customer's real account number for a transaction or set of transactions.
- VANs reduce breach exposure but do not participate in chargeback authorization, review, or liability, so a VAN transaction can still be disputed like any other card charge.
- Expired VANs complicate merchant refunds, which is the single most common source of VAN-related friction and can escalate a normal return into a chargeback.
- Bank support for VANs has narrowed: Capital One's Eno remains active while programs like Bank of America's ShopSafe have been discontinued.
- Winning a VAN-linked dispute still requires standard transaction evidence: authorization records, delivery confirmation, and customer communication, not proof that the VAN was secure.
A virtual account number is a temporary, limited-use number a bank or card network generates in place of your real account number for a transaction, but it does not decide who wins a dispute if that transaction is later challenged. Virtual account numbers (VANs) reduce the chance your real card data leaks in a breach. They do not remove the operational work of proving what happened when a customer disputes a charge.
Statista reports 3,322 data compromises in the United States in 2025, affecting 278.83 million individuals. Every one of those incidents is a reason merchants and banks keep investing in tools like VANs. This guide covers how VANs work, where they sit in the payment and dispute lifecycle, who is responsible when something goes wrong, and what evidence a VAN transaction actually produces when a chargeback lands.
The Role of Virtual Account Numbers in eCommerce Transactions
A virtual account number is a temporary code used for online transactions instead of a permanent one, keeping the customer's real account information private. Banks offer VANs as part of their fraud prevention programs, and cardholders typically opt in and generate numbers through an app or browser extension.
Once activated, the issuing bank generates a proxy number tied to the real account for that specific transaction, or for a defined merchant and time window. Because the proxy number carries no reusable value outside its defined scope, intercepting it does not expose the underlying account. This is a related but distinct approach from tokenization, which typically works behind the scenes at the processor level rather than being generated by the cardholder. Both belong to the same broader ecommerce fraud prevention toolkit, just applied at different layers of the transaction.
A widely cited 2022 estimate suggests card-not-present fraud would cost eCommerce businesses more than $200 billion annually by 2025. Whether or not that exact figure landed, the direction was right: card-not-present fraud has kept climbing, and VANs are one of the few consumer-facing tools that directly reduce exposure by limiting what a stolen number can do.
Where Virtual Account Numbers Sit in the Payment and Dispute Lifecycle
A VAN only ever touches one part of a much longer transaction lifecycle, and understanding where it sits explains both its value and its limits:
- Authorization: the merchant's processor authorizes the charge against the VAN, which the issuing bank maps back to the real account behind the scenes
- Capture and settlement: funds settle normally, and the transaction posts to the cardholder's statement, often under the VAN or a merchant-linked reference rather than the real account number
- Refund: the merchant issues a refund to the number used for the sale, which becomes a problem if the VAN has since expired
- Reversal or chargeback: the issuer initiates what is a chargeback the same way it would for a standard card, tied to the underlying account, not the expired VAN
Every one of these states after authorization depends on record-keeping, not on the VAN itself. Once a VAN expires, it stops being useful for anything except identifying which original transaction it belonged to.
Who Is Responsible When a VAN Transaction Goes Wrong
A VAN transaction touches four parties, and each one owns a different piece of the outcome:
| Party | Responsibility in a VAN transaction |
|---|---|
| Issuing bank | Generates and maps the VAN to the real account, sets spending limits and expiration, and rules on disputes tied to the account |
| Card network | Sets the chargeback reason codes and liability rules that apply regardless of whether a VAN or a standard number was used |
| Acquirer or processor | Authorizes and settles the transaction as your payment service provider, and routes the dispute back to the merchant when the issuer files one |
| Merchant | Owns fulfillment, refund logistics against an expired VAN, and evidence collection when a dispute arrives |
Notice that the merchant carries the most operational weight here despite having the least control over whether a customer used a VAN in the first place. That asymmetry is the core reason VAN-related disputes need a documented process rather than ad hoc handling.
What Are the Benefits of Using Virtual Account Numbers?
Some programs let account holders set usage parameters on their VAN, including a spending cap, a merchant lock, and a usage window. Here are the benefits that matter most for fraud prevention:
- Breach containment: VANs keep the real account isolated from a merchant-side breach, since a compromised VAN carries no reusable value once its scope expires
- Reduced exposure per incident: each transaction can generate a unique number, so a compromised VAN cannot be reused for unrelated purchases
- Spending controls: usage caps limit the damage even if a VAN is intercepted while still active
- No credit score impact: using a VAN does not affect a cardholder's credit profile, since it is not a separate line of credit
- Subscription control: a VAN set to expire blocks unwanted automatic renewals without requiring the customer to cancel with the merchant directly
- Billing error visibility: a capped or single-merchant VAN makes an overcharge or duplicate billing attempt easier for the cardholder to spot
Where VANs Create Customer Confusion and Merchant Risk
The same features that make VANs useful for fraud prevention create predictable failure points for merchants. Two show up most often:
Refund routing failure: the most common complaint. A customer pays with a VAN, later requests a return, and the merchant tries to refund the original number only to find it has expired. If the merchant does not have an alternative refund path ready, the customer often escalates straight to their bank rather than waiting, which can turn a normal return into a chargeback instead of a refund.
Statement recognition confusion: a VAN transaction can post under a merchant reference the cardholder does not immediately recognize, especially with a merchant-locked VAN generated weeks earlier for a specific purchase. That confusion is a documented driver of friendly fraud, where the cardholder genuinely does not remember authorizing the charge and disputes it in good faith.
Neither failure mode is really about VANs being insecure. Both are about the operational gap between how a VAN behaves and what a merchant's standard refund and customer-recognition workflows assume.
Are There Downsides to Virtual Account Numbers?
VAN adoption remains limited relative to how effectively the technology can reduce fraud. Merchants, particularly in travel, hospitality, and healthcare, run into real friction when a transaction requires physical card verification that a virtual number cannot provide.
- Difficulty with returns: the core issue covered above. When the original VAN has expired, the merchant needs an alternative way to issue the refund, and not every payment stack supports one cleanly.
- Identity verification inefficiencies: some verticals require physical card verification for phone or in-person confirmation of an online order, and a VAN cannot satisfy that requirement. Some states have restricted virtual account numbers as payment for medical providers specifically because of this gap.
- Inconsistent bank support: issuer support for true VANs has narrowed rather than grown. Capital One's Eno remains the most consumer-visible active example; Bank of America discontinued its ShopSafe virtual card service, and several major issuers have shifted toward tokenized digital wallets instead of dedicated VAN generators. Confirm current availability directly with a customer's issuing bank rather than assuming a program is still active.
Evidence a VAN Transaction Produces for a Dispute
A VAN-linked transaction still generates the same evidence categories any card transaction does, plus a few specific to how the number was scoped. Pull these together before you respond to a dispute:
- VAN scope and expiration settings active at the time of the original sale, which explain why a same-number refund failed
- Authorization and settlement records tied to the underlying account, not just the VAN, since the issuer's dispute will reference the real account
- Delivery and fulfillment confirmation, the same core evidence any chargeback process requires regardless of payment method
- Customer communication around the order, particularly useful when statement-recognition confusion is the likely driver of the dispute
- Refund attempt records showing the merchant tried to process a return to the original VAN and what happened when it failed
Most of this evidence needs to be gathered from several systems within your chargeback time limit, which is exactly the coordination problem automated evidence tools are built to solve.
A Merchant Checklist for Handling VAN-Related Disputes
Use this before a VAN-linked dispute reaches your desk, not after:
- Confirm your refund path works for expired VANs. Test whether your payment processor supports refunding to a bank account or issuing a new payment method when the original number has lapsed.
- Flag VAN-originated orders in your order management system. Knowing at a glance which orders used a VAN saves time when a refund or dispute request comes in.
- Route reason codes correctly. A dispute tied to a VAN transaction still uses the network's standard reason codes, such as Mastercard reason code 4870 for counterfeit-related claims; treat it like any other chargeback, not a special case.
- Set clear order confirmation and shipping notifications. Reducing statement-recognition confusion before it becomes a dispute is cheaper than fighting the dispute afterward.
- Centralize evidence collection. Pull VAN scope data, authorization records, and fulfillment proof into one place rather than reconstructing it per dispute.
- Layer in chargeback alerts. Alerts let you resolve a customer complaint directly before it posts as a formal dispute, which sidesteps the VAN refund problem entirely in many cases.
VANs Reduce Breach Risk, Not Dispute Risk
Virtual account numbers do real work protecting customers from the fallout of a merchant-side breach, and that value is not in question. What VANs do not do is simplify your side of the transaction. Expired numbers complicate refunds, unfamiliar statement references drive avoidable disputes, and the evidence you need to win a chargeback still has to come from your own systems, not from the bank that issued the VAN. Merchants who treat VAN orders as a distinct operational category, with a tested refund path and a clear evidence trail, avoid most of the friction; merchants who do not tend to find out the hard way, one dispute at a time. Pairing that operational discipline with Chargeflow's automated dispute recovery closes the gap between what your bank protects and what your business still has to prove.
Virtual Account Numbers FAQ
What is a virtual account number?
A virtual account number (VAN) is a temporary or limited-use number generated by a bank or card network in place of a customer's real account number, used to complete one transaction or a defined set of transactions without exposing the underlying account.
Can a merchant refund a payment made with a virtual account number?
Yes, as long as the VAN is still active. If the VAN has expired, which is common for single-use or short-window numbers, the merchant needs an alternative refund method, such as a bank transfer or a replacement payment on file, since the original number can no longer accept funds.
Do virtual account numbers stop chargebacks?
No. VANs reduce the risk that a stolen number can be reused elsewhere, which lowers breach-driven fraud exposure. They do not change how disputes are filed, reviewed, or resolved, and a VAN transaction can still be charged back through the same reason codes and process as any other card transaction.
Which banks currently offer virtual account numbers?
Availability has narrowed over time. Capital One's Eno remains the most consumer-visible active virtual number generator as of 2026. Some issuers that previously offered similar programs, including Bank of America's ShopSafe, have discontinued them in favor of tokenized digital wallets. Confirm current availability directly with a specific issuer rather than assuming a program is still active.
Why would a customer dispute a charge made with a virtual account number instead of asking for a refund?
Statement recognition is the most common reason. A VAN transaction can post under a merchant reference the cardholder does not immediately associate with their purchase, especially weeks after the order. That confusion leads some customers to dispute the charge with their bank rather than contact the merchant first.
{{cta}}

Chargebacks?
No longer your problem.
Recover 4x more chargebacks and prevent up to 90% of incoming ones, powered by AI and a global network of 20,000 merchants.













.png)
.webp)

.webp)