Rule: BIN country mismatch
Rule key: bin_country_mismatch · Default weight: 0.7 · Tier: Lite
Compares the card-issuer country (derived from the BIN — the first 6 digits) against the billing country.
| Scenario | Base score |
|---|---|
| Different country, same region (e.g. DE → AT) | 20 |
| Different country, different region (e.g. NG → US) | 60 |
When BIN data is available
This rule requires the payment gateway to expose BIN information on the order. Stripe, PayPal, Square, and Authorize.Net all do; smaller gateways often don\’t. If WooFraudGuard can\’t read the BIN, the rule returns clean (no signal).
To check whether your gateway is supplying the BIN, look at any flagged order\’s detail modal — under the BIN country mismatch row, the metadata will show the BIN (or be empty if it wasn\’t captured).