Notice: this post will be updated with new developments, quick updates here
When foreign issue VISA cards in Wallet stopped working for some kinds of Apple Pay in-app purchases from Japanese merchants starting on August 5, the first people to howl in pain were Apple Pay PASMO users who suddenly couldn’t recharge the stored fare balance or renew commuter passes with their Chase Sapphire VISA cards. Chase Sapphire still codes for 3x travel points on PASMO you see and long time resident Suica users had migrated to PASMO when JR East and VISA shut down 3x travel points.
I did the usual duty of talking with Mobile Suica support, official line: there should be no problem, contact the card issuer. I then contacted Wells Fargo card services support, official line: there should be no problem with your VISA, contact the merchant. Entirely expected responses of course but I did confirm that Mobile Suica transaction attempts were not even showing on the Wells Fago system. They said it might be a ‘communications issue’.
I suspected a larger issue than just Apple Pay and an Android Suica user confirmed the same non-JP VISA problem with Google Pay Suica. I also alerted IT journalist Junya Suzuki who focuses on mobile payments. His first thought was something might be going on with the VISA Japan merchant acquirer side of the payment network. Maybe they were tightening online transaction security…or something else. He followed up with JR East PR and posted an article of his investigations that seem to place some responsibility on the JR East side. Everything clear as mud.
This past week a reader asked me if Japan was banning non-JP VISA cards across the board along with a screenshot of Universal Studios Japan advance ticket sales page with a red colored important notice on the top that said: “We apologize that currently Visa and Mastercard credit cards issued outside Japan are not available until further notice.” The DMM site is also not accepting foreign issue VISA and Mastercard.
Finally…proof that the problem is larger than just Mobile Suica and PASMO. I suspect there are other online sites with the same issue, we’re just not hearing about them. The USJ wording suggests that JTRWeb have their hands tied ‘until further notice’ and echos what JR East PR told Suzuki san about the non-JP VISA recharge problem being beyond their immediate control. Something seems to be happening with the VISA acquirer and Mastercard acquirer sides but in different highly selective ways. For example why does Apple Pay Suica work with foreign issue Mastercard and AMEX but not VISA, or why does foreign issue VISA work for Apple Pay in-app purchases with Japanese apps like Starbucks, but not in-app purchase with JR East for Suica recharge?
The impact of recent phishing attacks
It’s important to understand the effect of major phishing attacks that hit docomo, Line Pay, PayPay and other QR code payment services in late 2020, and JR East online services (Mobile Suica, JRE POINT, Eki-Net and VIEW card) in early 2022. Responses to phishing attacks has been slow, varied and sometimes vague. Companies like to say they value customer security but are short sharing details that outline exactly what they’re doing about it.
Docomo quickly suspended, then killed off, their problematic docomo koza e-paymnet service. Japanese credit card issuers responded by upgrading to EMV 3-D Secure v2 for browser and mobile app payments (edit: EMV 3-D Secure is the EMV e-commerce browser and app authentication spec for all members but card brands use their own naming) and are due to phase out 3-D Secure v1 by October 2022.
JR East has upgraded Suica App to 3-D Secure v2 for in-house credit card purchases and JRE POINT to make it more secure, but seemly little else. Scratch under the surface however and you’ll notice unannounced recharge security blocks with Apple Pay. There are also new limits for certain Japanese issue cards registered in Suica App. Recharge with Revolut VISA for example is now limited to 3,000 JPY per day despite the fact that Suica App uses 3-D Secure v2. Clear as mud…again.
Which brings up to the most important point of the whole problem: why is the VISA payment network not accepting foreign issue cards for Apple Pay Suica and Google Pay Suica recharge when those digital wallets offer the highest levels of secure online transactions out there? A bumpy 3-D Secure v2 transition might explain what’s happening with some online sites that have not been updated for the newer protocol, but the transition has been going on for a while now and the USJ site almost certainly uses EMV 3-D Secure v2. And it doesn’t explain what’s happening with Apple Pay Suica/PASMO and Google Pay Suica (Osaifu Keitai) which have nothing to do with EMV 3-D Secure.
The Apple Pay difference
Apple Pay adds a device specific secure element + bio-authorization security with built in tokenization. Apple Pay takes care of all complex tokenization/authorization stuff on their backend. Neither user nor merchant have to deal with 3-D Secure because Apple Pay has its own tokenization that ‘just works’. And because Apple Pay comes with the extra security and guarantees that Apple provides to issuers and merchants, once a card is added to Apple Wallet, it is cleared for all things Apple Pay (ditto for Google Pay). This is why a plastic contactless card that doesn’t work on TfL open loop transit gates works when it is added to Apple Wallet. It’s the Apple Pay difference.
So we circle back to foreign issue VISA again. Why are cards cleared for Apple Pay, cards that worked fine until August 5, suddenly not working? Is JR East shutting down recharge for foreign issue cards like Hong Kong Octopus and China T-Union do without telling us? So far JR East support says that all credit and debit cards that support Apple Pay in-app purchase are good to go. They certainly want inbound visitors to use Suica. What little evidence we have so far points to a change on the VISA side. Everybody else seems to be doing what they always do and haven’t changed anything.
VISA has a history of not playing nice with Japanese stored value cards on mobile. JP issue VISA cards didn’t work for Apple Pay in-app purchases and Suica recharge until last year, it took VISA 5 years to ‘resolve’ that issue. VISA cards still do not work with Mobile WAON and Mobile nanaco on Android and Apple Pay, they likely never will. My take is that VISA is happy with people buying things with VISA, they are certainly happy with people borrowing money with VISA, but they are not happy with people using VISA to move money into stored value prepaid cards for making payments, earning points, etc., that are not VISA.
Who knows? VISA has played hardball in the Japanese market before, maybe they are doing so again. Perhaps they refuse to be an ATM-like recharge backend for Japanese e-money cards unless they also get ATM-like lending rate surcharges, or maybe they want to promote open loop VISA Touch and Stera Transit at the expense Mobile Suica market and mindshare. You get the picture.
Junya Suzuki thinks VISA acquirers are coming under pressure from potential money laundering risks. I think people have the right to move their money where they want to, after all we’re only talking a max Suica balance of ¥20,000 here. Whatever the reason let’s hope it is fixed soon, though I have learned over the years that card brand payment issues are never simple. Time will tell. At the very least I think we can say this is just another skirmish in the ongoing digital payment turf wars.