Citi Hong Kong is preparing to launch a virtual credit card featuring a dynamic Card Validation Code (CVC) in partnership with Mastercard, adding a rotating security layer to online transactions as digital commerce and card-not-present fraud continue to grow.
The bank announced the upcoming product on September 4, with the service expected to become available to eligible Citi Mastercard credit-card customers in Hong Kong through the Citi Mobile App in the coming months.
A CVC That Changes for Online Transactions
Unlike a conventional physical credit card, the new virtual card will generate a one-time-use CVC for each new transaction.
If the generated code is not used within its validity period, it will refresh when the customer views it again through the Citi Mobile App.
The idea is straightforward: even if a customer’s card information is exposed during an online transaction, a fraudster should have a much harder time reusing the stolen credentials because the verification code is temporary.
The virtual card will operate alongside customers’ physical cards rather than replacing them. Citi expects customers to use the virtual version for activities such as e-commerce purchases, subscriptions, recurring payments and mobile-wallet transactions.
Card-Not-Present Fraud Drives the Need
Citi’s move comes as more consumer spending moves online.
The bank said approximately 80% of the credit-card fraud attempts it sees are connected to card-not-present transactions, where the physical card is not presented to a merchant.
These transactions can include online shopping, subscriptions and other digital purchases.
Citi Hong Kong also reported that the combined volume of domestic e-commerce and recurring transactions increased by more than 20% year over year in 2025, with foreign-currency transactions recording even stronger growth.
That combination of growing digital commerce and persistent fraud risk is pushing banks and payment networks toward security systems that do not rely solely on static card credentials.
Mastercard Tokenization Underpins the System
The new virtual card uses Mastercard’s tokenization infrastructure, which replaces sensitive payment information with digital credentials designed to reduce exposure of the underlying card details.
Mastercard said around 40% of transactions on its network are now tokenized, illustrating how digital credentials are becoming increasingly common across payment systems.
For Citi, combining tokenization with a dynamic CVC adds another layer to the security architecture.
Instead of requiring customers to abandon their existing physical cards, the approach separates online spending from physical-card usage. Customers can therefore use the virtual card for digital merchants while keeping their physical card credentials away from those transactions.
Digital Security Becomes Part of the Payment Experience
The Citi-Mastercard initiative reflects a broader shift in digital banking. Security features are increasingly being integrated directly into payment products instead of being treated as separate fraud-prevention tools operating behind the scenes.
Dynamic credentials can potentially reduce the value of stolen card information because a compromised code may no longer be useful for another transaction.
The challenge, however, will be balancing stronger security with convenience. Consumers are unlikely to embrace additional authentication steps if they make everyday payments significantly more complicated.
Citi’s virtual-card approach attempts to address that issue by placing the functionality inside the existing Citi Mobile App.
Hong Kong Becomes a Test Case for Dynamic Credentials
The upcoming rollout positions Hong Kong as an early market for Citi’s dynamic-CVC approach.
As e-commerce, recurring payments and mobile wallets continue expanding, static card credentials are becoming increasingly difficult to protect on their own.
Citi’s new virtual card illustrates how banks and payment networks are responding by combining tokenization, temporary credentials and app-based controls into a single consumer-facing payment product.
If successful, similar dynamic-card systems could become more common across other markets as financial institutions look for ways to reduce online fraud without sacrificing the convenience that consumers expect from digital payments.
This website uses cookies.