Bloomberg reports (paywalled) that Sam Altman told OpenAI employees the company is open to slowing the pace of AI development alongside other leading labs as concerns grow over increasingly capable systems and recent incidents in which models escaped human control. OpenAI has already paused development once this year for security work and is now pushing for mandatory U.S. AI safety requirements. Anthropic has also signaled interest in coordinating on the pace of new releases. Here are some of the details Bloomberg reported, as summarized by Reuters:
– Altman told employees in a company-wide meeting that the ChatGPT maker could pace development alongside other AI labs, but some may not agree, the report added.
– Safety warnings from AI researchers this week, along with several recent incidents where AI models from developers including OpenAI escaped human control, have prompted alarm and calls for tighter safety regulations.
– Jacob Coxon, a former Anthropic and OpenAI researcher, publicly accused the companies earlier this week of racing toward AI advancements without acting responsibly.
– An Anthropic spokesperson said on Thursday said that the company is interested in working with the AI industry on the pace of releasing new AI tools.
– OpenAI said in July that AI acceleration for frontier model development may be so high that the world will “need to pace the rate of AI advancement” at some point in the future.
– In August, OpenAI paused much of its model development for two weeks to bolster its defenses after its AI agents escaped containment and hacked open-source platform Hugging Face.
– OpenAI said on Wednesday that it was pushing for mandatory national AI safety requirements in the United States, citing concerns that advanced AI systems could accelerate its own development.
You want Retro? We did, when we started our retrocomputing challenge. [Peter] decided that transistors weren’t retro enough, and sent us this lovely homebrew relay computer, complete with 16- bit CPU, which is rather more bits than one normally associates with clicky clacky contacts.
The architecture is very simple– it just uses an accumulator register, ACCU, and goes from there. All mathematics and save/load operations go through ACCU. There whole instruction set is only 19 commands, and he’s used that set to program such lovely things as calculating 3 digits of Pi– which only took 8 minutes of glorious clicking. There’s a demo video of that embedded below. [Peter] has even implemented a display by hooking his computer to a 32×32 LED matrix, but don’t expect it to relay updates really quickly.
If this computer looks familiar, it’s because its earlier incarnation was one of the more “extra” entries in last year’s one-hertz challenge, where it was used to blink an indicator lamp. Yes, even relay computers apparently get started with the “blinky” sketch.
Advertisement
If you want in on the fun, our retrocomputer challenge runs until October 27th, so there’s lots of time left to turn back the clock.
Creative Assembly says it was ‘a big deal’ to have player customization be a ‘must-have’ part of Total War: Warhammer 40,000 for fans of the tabletop game and hobby
Total War: Warhammer 40,000 battle product owner Dave Petry says it was important to implement player customization in the game
He says it was a “big deal” to bring those customization options from the hobby forward to the game
Petry adds that it was “awesome” to bring in the “core” features from the hobby
Total War: Warhammer 40,000 offers plenty of player customization options, which Creative Assembly has now revealed was an essential feature it wanted in the game from the start.
In an interview with TechRadar Gaming at Gamescom, battle product owner Dave Petry, alongside lead designer Joy Dey, said player customization in all aspects was always a “must-have,” as the studio wanted to simulate the same experience for fans of the tabletop Warhammer game and beloved hobby.
“The second we picked this up, we knew we had to make a big deal of being able to tell your own story within this universe to bring in your own identity and get to be part of all of it,” Petry said.
“We’re trying to create an authentic sense of the lore and the kind of combat that’s there, but the love for the tabletop absolutely is present,” Petry said.
As for customization, Petry told us that it was “awesome” to bring in the “core” features from the hobby, and teased aesthetic unit personalization, loadout customization, and late-game progression.
Advertisement
Petry also confirmed that the game will feature the actual real-life paint colors used by Games Workshop too, so fans will be able to use the same ones they know and love and recreate their real-life armies or favorites in the game.
Sign up for breaking news, reviews, opinion, top tech deals, and more.
“In terms of what you can do, not just the aesthetic customization, colors, etc, etc,” he went on, “but being able to specialize your units throughout a campaign and, over that campaign, take your intercessors, specialize them towards using, say, like bolt rifle, auto bolt rifles, or stalkers, leveling them up, kitting them out in different ways, and you know potentially ultimately getting them to be like stern guards.
“All of that sort of stuff is absolutely part of that core hobby that you experience this way.”
A black Volkswagen Jetta rolled through an Express Lane in Solano County with a blank bumper where a rear plate should have been. A California Highway Patrol cruiser in the next lane caught that empty space on dashcam, then saw the same car moments later with a full, readable California plate sitting in place. That change was the whole stop.
Officers stopped a Jetta, and there was just one driver inside. After speaking with the motorist, CHP Solano learned that the strange hardware on the bumper was intended to avoid paying Express Lane costs and Bay Area bridge tolls. The office later posted the encounter with a short line that has already traveled farther than the car did that day. “Now you see it, now you don’t.”
【Wireless Apple Carplay & Android Auto】Enjoy seamless wireless carplay and android auto connectivity for your phone’s music, map navigation…
【OTA Updates】Keep your device up to date with over-the-air firmware updates, so you’re always one step ahead. This wireless CarPlay screen…
【Phone Mirroring Link & Four Audio Outputs】This 9-inch CarPlay screen supports mirroring for both iOS and Android phones. The double-DIN car…
On body camera footage, that hardware appears to be quite typical. An officer picked up a small remote that functions similarly to a key fob, hit a button, and a black shield swooped over the plate, erasing the numbers. With another squeeze, the cover fell back out, revealing a standard licence plate. In the video coverage, that panel is described as a sliding cover or a raised shield, which is basically the same type of motorized frame you can buy online as plate hiders, flippers, and curtains, and a driver can hide the tag on the way up to a bridge, then revert it before the cameras get a clear look.
Advertisement
Tolls in that section of the state do not require a person at a booth to check your plate because Express Lanes and Bay Area bridges combine FasTrak readers with overhead cameras. If the transponder does not respond, the camera captures a photo of the rear plate, and the agency sends the bill to the owner. Cover the plate for a few seconds, and the snapshot comes back empty. Pay by plate only works if you are prepared to display your plate, which is why there is a removable cover like this.
California has previously excluded the concept from the Vehicle Code. Section 5201.1 states that you are not permitted to operate a vehicle with a removable frame, flipper, or any other device designed to conceal a license plate from view or electronic readers. The base fine is $250, before the state and county add extra costs and take it from there. Section 5201 still requires plates to be properly attached, visible, and readable at all times. If you don’t pay your tolls, you’re also breaking another law, 23302(a)(1), which will result in civil penalties and a DMV hold, prohibiting you from renewing your registration. The same chapter was tightened in 2025 and 2026, including any goods that seek to peel or paint over a plate’s reflective coating, preventing cameras from locking on it. [Source]
Scriptocalypse: Microsoft announced the deprecation of the VBScript environment a few years ago, asking companies and power users to switch to modern scripting systems. Now, the company is warning organizations that depend on VBScript that Windows activation might even become impossible after the language is gone.
Microsoft is asking organizations that rely on the Slmgr.vbs tool to switch to PowerShell, as the old script will soon stop working along with the rest of the VBScript language. Companies that use the script to manage Windows activation should act soon, as Microsoft is likely to accelerate VBScript deprecation in future Windows upgrades.
As explained in Microsoft’s own documentation, Slmgr.vbs is a Visual Basic Script included in Windows to manage OS activation from the command line. The script can install and change product keys, activate Windows, check the current activation or licensing status, and much more. The tool is specifically designed to provide enterprise organizations with a flexible way to manage multiple OS activations, which has nothing to do with KMS servers or other “unofficial” methods designed to achieve the same results without paying Microsoft a dime.
As the company first announced in 2023, VBScript will soon disappear from Windows after being part of the operating system’s convoluted lineage for almost 30 years. Modeled after the Visual Basic programming language, VBScript was designed as a powerful automation technology for programmers and users looking to exert greater control over the Windows operating environment.
Advertisement
According to Microsoft’s latest timeline for VBScript deprecation, the technology is now available as a Feature on Demand (FOD) on Windows and is enabled by default. At a later stage, VBScript’s FOD will no longer be enabled by default, and users will need to manually install the feature if they need it.
Finally, a future Windows release will completely remove VBScript. At that point, Slmgr.vbs and other automation solutions will stop working altogether.
Microsoft said that Slmgr.vbs can be easily replaced with PowerShell, where the OSLicense module provides the automation features currently available through VBScript. OSLicense requires Windows PowerShell 5.1 and can be used to manage activation information, invoke new licensing instances, and more.
One potential issue with adopting the OSLicense module is the version of Windows used by organizations. The PowerShell component is available in client versions of Windows 11 after installing the August 2026 Preview update (KB5120998) or later. Meanwhile, Windows Server will provide support for the new module with the next major release of the enterprise-focused operating system.
Advertisement
Either way, Redmond said organizations should start checking their scripts, command-line tools, and group policies right now. Companies using Slmgr.vbs and other VBScript-based “dependencies” are advised to thoroughly check their IT automation procedures so they can ease the pain that comes with changing decades-old conventions.
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022.
44-year-old Oleksii Oleksiyovych Lytvynenko was arrested by the Irish national police (An Garda Síochána) in July 2023 at the request of the United States and was extradited last year.
Lytvynenko and his Conti accomplices deployed ransomware on victim networks in the United States and abroad, stealing data and encrypting devices to extort Bitcoin ransom payments.
“From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000,” the Department of Justice said on Thursday.
Advertisement
“Lytvynenko joined that conspiracy as both an intruder and a developer — personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities,” added Assistant Attorney General A. Tysen Duva.
The defendant pleaded guilty to conspiracy to commit wire fraud in June 2026 and was facing a maximum sentence of 20 years in prison.
He admitted to joining the Conti ransomware operation in September 2021, controlling the stolen data of eight U.S. victims and four overseas victims, and sending ransom notes as part of the cybercrime gang’s double extortion attacks between 2020 and June 2022.
Lytvynenko also admitted to joining a team run by another Conti conspirator, where he coded a “loader,” which is a type of malware designed to load the software needed to carry out attacks.
Conti evolved into a cybercrime syndicate that controlled multiple malware operations, including BazarBackdoor and TrickBot, and it shut down two years later, in 2022, after increased law enforcement pressure and leaked internal chats.
Seven TrickBot/Conti members were sanctioned in February 2023, after a massive leak of personal information and internal conversations belonging to Conti and TrickBot members, known as the ContiLeaks and TrickLeaks.
Advertisement
In September 2023, the U.S. and the United Kingdom also sanctioned and charged nine Russian nationals associated with Conti and TrickBot for attacks against over 900 victims worldwide, while the Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) doxed the leader of the TrickBot and Conti cybercrime gangs in May 2025, claiming he is a 36-year-old Russian named Vitaly Nikolaevich Kovalev using the alias “Stern.”
According to court documents, the Conti cybercrime gang has targeted more than 1,000 victims worldwide and collected over $150 million in ransom payments while active.
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
What you post online is only part of the story. A new review of research into social media privacy warns that platforms and third parties can potentially infer sensitive details about people from seemingly ordinary digital activity, including their political opinions, religious leanings and shopping habits.
The findings, as reported by Techxplore, published in the International Journal of Management Concepts and Philosophy, point to a widening gap between the amount of personal information generated online and the legal and ethical protections designed to safeguard it. The researchers examined privacy breaches, regulatory frameworks, and the responsibilities of both social media companies and their users.
Your digital trail says more than your posts
The central concern is not necessarily what users deliberately share. Instead, researchers highlight what can be inferred from their activity after it has been collected, indexed, and analysed.
Every interaction can contribute to a broader “digital trail” containing information about activities, locations and interactions. According to the research review, this trail can potentially be searched and analysed by third parties or, at the very least, by the platforms themselves. Even mundane online behaviour can provide clues about personality traits, purchasing patterns, political opinions and religious affiliations.
Advertisement
Unsplash
That creates a privacy problem that is easy to overlook. You might never explicitly state a political preference, religious belief or particular consumer habit, yet your online behaviour could still provide enough signals for someone else to make an educated inference.
The researchers argue that privacy is therefore not simply about keeping secrets. It is about maintaining control over who can access and interpret information about you. They connect that control to personal autonomy, civil liberties and democratic participation.
Why stronger privacy rules may be needed
The findings matter because social media has transformed privacy from something people could largely manage themselves into something increasingly shaped by algorithms, platforms and data analysis. Not just this; last year the city of New York decided to start treating social media with warning labels, like cigarettes.
Representative Image of child using FacebookUnsplash
The review calls for greater legal accountability and transparency from social media companies, alongside better digital literacy so users can understand and manage the risks associated with sharing information online.
The familiar argument that people who have “nothing to hide” have little reason to worry about privacy also comes under scrutiny. The researchers frame privacy as a right to decide who gets to see into the personal aspects of our lives – not as a tool for concealing wrongdoing.
For users, the takeaway is straightforward: your social media profile is potentially more revealing than the information you consciously put on it. Likes, interactions, locations and other seemingly harmless activity can form a larger picture when analysed together.
Advertisement
What happens next will depend on how regulators, platforms and users respond. The researchers’ call for stronger accountability and transparency suggests that privacy protections may need to evolve alongside the increasingly sophisticated ways online behaviour can be analysed.
Larry Ellison has cancelled a trading plan that would have let him sell up to 50 million Oracle shares by 24 October, a day after the plan was disclosed and with no stock sold under it. The instrument is a Rule 10b5-1 plan, an American safe harbour with no European counterpart, because EU market abuse rules bar managers from dealing in the 30 calendar days before results instead.
Larry Ellison has cancelled the plan that would have let him sell up to 50 million Oracle shares, a day after it was disclosed, Bloomberg reported.
“No Oracle stock was sold under that plan, and he has no other plans to sell any of his Oracle stock,” the company said.
The plan was adopted on 22 June and would have run to 24 October. The shares were worth about $8.75B then and about $7.5B now, after a 16% fall. Oracle described it as a 10b5-1 plan in its statement.
Advertisement
Ellison controls about 40% of the company and is its executive chair and chief technology officer.
The timing was the problem. Oracle reported shrinking gross margins on Thursday, its shares fell 1.7% on Friday, and the same week it raised the cost of its job cuts to $2.8B.
A Rule 10b5-1 plan is a piece of American market plumbing with no European equivalent.
An executive who adopts one while not holding inside information can let trades execute later on a fixed schedule, including in periods when selling at their own discretion would draw questions. The rule dates from 2000, and the SEC tightened what has to be disclosed about these plans in 2022.
Advertisement
Europe closes the window instead.
Under the Market Abuse Regulation, a person discharging managerial responsibilities may not deal in the company’s shares during the 30 calendar days before an interim or year-end report.
There is no adopt-in-advance exemption from that.
Europe also discloses different things. It publishes transactions rather than intentions, within three working days of each deal, once EUR 5,000 has been reached in a calendar year. A plan that never traded would have left no trace at all.
Advertisement
None of which suggests Ellison did anything improper. No shares were sold, and the plan was disclosed exactly as American rules require, which is the only reason anybody knew about it.
But the two regimes would have produced different weeks. Europe would never have published a plan for the market to read, and would not have let one run through the results of a company sitting one notch above junk.
AI is constantly being shoved in our faces. From your laptop to your phone, every new gadget now ships with some features built around AI. Over the last couple of years, even Apple has tried to make Apple Intelligence sound like the next big thing on the iPhone.
With iOS 27, the argument finally became worth listening to. Siri AI is a great example of this. It can search through personal information and understand what is on your screen before answering specific or broader general questions. Visual Intelligence looks through your phone’s camera to understand what you’re seeing, and a lot more.
All of this is impressive, till you see what Apple has in store with the Apple Watch Series 12 and Watch Ultra 4. The way it approaches AI in the wearables is different. It isn’t just a smaller secondary screen with a language model, and that’s why it works.
Apple
The Apple Watch doesn’t waste time
An iPhone gives Apple plenty of space to demonstrate AI, which is not the case for the Watches. Its tiny screen actively discourages long interactions, and I think that limitation is forcing Apple toward more interesting ideas. Take the new Audio Intelligence suite, for example. Each of the new features under it serves to make the users’ lives easier.
Sound Recognition can identify important noises such as alarms, sirens, doorbells, or a crying baby and alert you. Automatic Shazam identifies music around you and surfaces the result in Smart Stack. Live Rewind can recover the previous 15 seconds of speech when you missed something someone said. Siri Recap can turn conversations into short summaries you can revisit later.
Live Rewind can be really useful… if you ignore the privacy concerns
Live Rewind is probably the best example. I can just double-press the Digital Crown and get the previous 15 seconds as text if I missed something important in the conversation. Adding to its functionality, you can even ask Siri about it or have it saved for later. On the iPhone side, there isn’t any such interaction. By the time I’ve taken my phone out, unlocked it, and started recording, it’s already too late.
A lot of the new AI gadgets are all about seamless, display-free interactions. And just like those devices, the new Apple Watch changes how we interact with AI thanks to its physical proximity. A wearable has access to situations an iPhone sitting in my pocket can’t interact with quite as naturally, and Apple is beginning to build intelligence around that advantage.
Apple
We made a similar argument about Siri Recap recently. The privacy implications of a smartwatch listening to conversations deserve scrutiny. Though Apple’s implementation avoids retaining raw recordings and processes audio inside a hardware-isolated Secure Exclave on the S11 chip. Live Rewind also gives people nearby an audible and visual indication when it has been activated.
Why an iPhone can’t match the Apple Watch
Fitness and health features are what make the Apple Watch so popular. It knows much more about what my body is doing at any particular moment. Workout Buddy uses Apple Intelligence to provide spoken motivation based on personal workout data, and watchOS 27 expands the information it can incorporate. It can now operate while you exercise without carrying your iPhone, even if Apple still requires a paired Apple Intelligence-enabled iPhone and compatible Bluetooth audio hardware.
Series 12 and Ultra 4 also gather heart-rate measurements every five seconds and HRV as frequently as every five minutes through the new Health Sensing System. This data feeds Apple’s new Readiness experience, which combines activity, sleep, vitals, and training information into a score that updates as your condition changes throughout the day.
Apple
Apple’s redesigned Health app uses Apple Intelligence to interpret longer-term health information, while new vision-based AI assessments can combine the iPhone camera with Watch data to evaluate flexibility, strength, balance, movement mechanics, and VO2 max.
Siri AI on your wrist just works
Ironically, even Apple’s more conventional chatbot-style AI arguably gains something by being on the Watch. Siri AI brings the same personal-context understanding, conversational abilities, and broad knowledge available on the iPhone to watchOS 27. But on a phone, Siri is competing with other AI services like ChatGPT and Gemini.
Advertisement
Apple
With the Apple Watch, however, I can change an activity goal halfway through a run. Maybe even find something from my personal info or ask about my training without ever having to reach for my phone. Even watchOS 27’s smaller intelligence features play into this whole thing. The app grid can surface Siri-suggested apps based on usage, and something like Smart Stack recommendations can appear around context such as where you parked or someone’s birthday.
To be fair, the Apple Watch is more powerful than the iPhone. Features like Visual Intelligence bring some serious image-generation and editing tools. I just think the Watch is providing a better example of how AI can fit into an existing product without becoming the product.
I like the version of AI that’s all about making interactions feel more natural. It hears the thing you missed and recognizes the song playing nearby without needing any input. Nothing too intrusive, but still present enough to be handy in day-to-day use.
An anonymous reader quotes a report from The New York Times: The chief executive of Anthropic called for a global slowdown of artificial intelligence development in a 3,800-word essay on Saturday, just days after one of the company’s employees quit over concerns about the safety of the technology. Dario Amodei, who co-founded Anthropic to focus on securely and carefully building A.I., wrote that while he believed the technology could bring many benefits, it was advancing at too quick a pace for researchers to continue safely.
“Over the last few months, I have become convinced that fully addressing the risks requires even more prudence — not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up,” Mr. Amodei said. “We must slow the pace at which we improve the capabilities of A.I. models. Progress will still seem fast, and we must make wise use of the time we gain.” […] “Left unchecked, it could outrun our ability to understand and control these systems, and so must be pursued very carefully, if at all,” Mr. Amodei said.
[…] In his essay on Saturday, Mr. Amodei suggested actions that the industry might take to slow down the pace of development.
Mr. Amodei said all A.I. labs could agree to third-party technology assessments from “embedded evaluators,” or outside specialists who can verify best safety practices across companies. He also suggested that countries with democratic governance systems coordinate to create safety standards, which could take the form of regulatory action. He added that it would probably require a global effort working with other nations, including authoritarian ones, to properly coordinate a slowdown.
Mr. Amodei stressed in his essay that he still finds A.I. capable of bringing “incredible benefits” to humanity, including potentially curing diseases and accelerating economic growth. But even so, Mr. Amodei said the risks of A.I. were too great to not proceed with extreme caution. “The measures I propose to advance the frontier at a safe pace will not be easy,” Mr. Amodei wrote. “But I believe we owe it to humanity to try.” Amodei’s essay comes just hours after Bloomberg reported that Sam Altman told OpenAI employees the company is open to slowing the pace of AI development amid similar concerns.
A virtual card number is a substitute payment number linked to an eligible underlying card account. You can use it for supported online or in-app purchases without giving the merchant the number printed on your physical card, which can reduce the usefulness of exposed payment credentials if a merchant is later compromised.
It does not usually create a separate account or credit line, make an unsafe merchant trustworthy, or add new dispute rights by itself. Its main benefit is isolating the credential used at checkout from the number on the physical card.
How Virtual Card Numbers Work
A virtual card number replaces the card number you would normally type at checkout with a different number generated for an eligible account. Capital One describes its virtual card numbers as unique numbers linked to the underlying credit-card account, allowing eligible users to make online purchases without sharing the physical card number.
The number associated with the actual card account is commonly called the Primary Account Number, or PAN. A virtual-card system leaves the underlying account in place while presenting a substitute credential to the merchant.
Advertisement
In practical terms, the process usually works like this:
An issuer or supported payment service generates a virtual card number for an eligible account.
You use the substitute number at an online or in-app checkout instead of the number printed on the physical card.
The merchant submits the virtual credential for authorization through the normal card-payment process.
The virtual credential remains associated with the underlying account so the issuer can authorize and post the purchase there.
The transaction appears on the underlying account rather than creating a separate balance or credit line.
Implementations differ. Capital One currently offers both general-use virtual numbers and eligible merchant-specific numbers. Its general-use number can work with multiple online merchants, while a merchant-specific number is restricted to one merchant. Capital One also notes that not every customer or card is eligible.
A simple example is a physical card whose account number ends in 1234. A supported virtual-card service can provide a different number for checkout while the resulting purchase still belongs to the original account.
Virtual card numbers and tokenized digital wallets can both reduce exposure of the underlying card number, but they are not necessarily the same technical implementation or checkout experience.
Advertisement
A virtual card number may look like an ordinary card number that you or a browser autofill tool enters into an online checkout. A digital wallet can instead use a payment token associated with a device, merchant, or payment context.
The distinction matters because different products support different controls. Some virtual numbers stay the same across many purchases, others are tied to one merchant, and wallet tokens can be restricted to a device or payment environment.
A virtual card vs digital wallet comparison matters when choosing between a manually entered substitute card number and a wallet-based payment token.
Advertisement
Our Recommendations
1
When Buying From a New but Legitimate Online Store
Best for: reducing exposure of your physical card number when trying a retailer you have independently checked but have not used before.
A virtual number can be useful when you trust a merchant enough to make a purchase but would rather not give it the reusable number printed on your card.
Where the issuer supports merchant-specific numbers, the containment can be stronger. Capital One states that its merchant-specific virtual numbers are valid only with the assigned merchant, so that credential cannot simply be reused at another store through the same feature.
Advertisement
The benefit is credential containment, not merchant verification. A virtual number can still successfully authorize a payment to a dishonest seller if you approve the transaction.
Important limitation: a virtual card number can reduce exposure of your physical card number, but it cannot establish whether a merchant is legitimate or whether an order will be fulfilled.
2
Advertisement
When a Merchant Stores Your Card for Future Purchases
Best for: isolating one merchant from the number on your physical card when the issuer supports merchant-specific virtual credentials.
Saved-card checkout is convenient, but it means a merchant or its payment provider retains a payment credential associated with your account. A merchant-specific virtual number can give that merchant a dedicated substitute credential rather than the number printed on your physical card.
This can be useful if you shop repeatedly at one website and want the stored credential for that retailer separated from the card number you use elsewhere.
Advertisement
Important limitation: merchant-specific numbers are implementation-dependent. Other virtual-card services may provide one substitute number that works across multiple merchants.
3
For Subscriptions You Want to Isolate
Best for: recurring payments when the issuer supports a persistent virtual number that can be managed separately.
A persistent virtual number can be useful for subscriptions because the merchant can keep charging the substitute credential without receiving the physical card number.
Advertisement
Capital One states that eligible virtual cards can be used for recurring payments and subscriptions. Its current management tools also let eligible users lock, replace, or delete virtual numbers separately from ordinary purchases made with the physical card number.
That can isolate one recurring merchant from unrelated card activity. For example, a merchant-specific credential used only for one subscription is easier to identify and manage than one physical card number shared across many merchants.
There is an operational consequence. Capital One explicitly states that recurring payments associated with a deleted virtual number will be declined, so legitimate payment details may need to be updated afterward.
Deleting a payment credential is not the same as canceling a contract or subscription. If the service has a cancellation process, follow it rather than relying on failed future charges.
Advertisement
Important limitation: deleting or replacing a virtual number can interrupt legitimate recurring payments, and issuer behavior varies.
4
When You Want Online Purchases Separated From Your Physical Card Number
Best for: routine e-commerce when you want merchants to receive a substitute credential instead of the number printed on your card.
This is the broadest everyday use case. Instead of entering the physical card number at each supported checkout, a virtual-card system can provide a different credential while keeping the same underlying account.
This illustrates the central trade-off: the credential shown to the merchant changes, but the underlying account remains. Spending still posts to that account and remains subject to its credit limit, balance, issuer rules, and other account terms.
Capital One likewise states that its virtual cards are tied to the associated physical-card account. If the physical card is locked, transactions on its virtual cards will not go through.
Important limitation: a virtual number does not separate you from the underlying account’s balance, credit limit, fees, interest, or repayment obligations.
Advertisement
5
For Controlled Business or Vendor Payments
Best for: organizations that need payment credentials with transaction or policy controls.
Commercial virtual cards can do more than conceal a broader funding-account number. Business systems can generate credentials for specific transactions, suppliers, or workflows and apply controls to their use.
Mastercard’s current commercial virtual-card material describes unique virtual numbers, workflow approvals, and controls defining how, where, and when a virtual number may be used. Its commercial platform also supports spending limits and restrictions.
Advertisement
This can let a business provide a constrained payment credential for a supplier or purchase without exposing the broader funding-account number.
These are commercial virtual-card capabilities. They should not be assumed to exist on an ordinary consumer virtual card merely because both products use the same general terminology.
Important limitation: amount restrictions, approval workflows, merchant controls, and similar features are commercial product capabilities, not universal consumer virtual-card features.
When a Virtual Card Number Is a Poor Fit
A substitute credential is useful only when the merchant and the later transaction lifecycle can support it. In some cases, the physical card number or another payment method is more practical.
Advertisement
The merchant does not accept virtual cards. Google says certain merchant sites and apps opt out of virtual-card acceptance, while Capital One also notes that some merchants may reject virtual numbers.
You may need to show the original card later. Capital One warns that a virtual number may be unsuitable when a travel reservation, hotel, event, or similar transaction requires the customer to present or swipe the card used for booking because the virtual and physical numbers do not match.
Your account is not eligible. Availability can depend on the issuer, card, account status, network, country or region, browser, device, and payment platform.
A changing credential would interfere with repeat billing. Persistent virtual numbers can support subscriptions, but short-lived or replaced credentials can cause later charges to fail.
You are treating it as protection from a fraudulent seller. A virtual number can still authorize a transaction that you willingly approve.
If an eligible virtual card unexpectedly fails, a virtual card decline can result from merchant acceptance, an expired credential, a billing-address mismatch, insufficient available credit, or issuer restrictions.
How to Get a Virtual Card Number
There is no universal setup process because availability is controlled by the issuer, network, or supported payment platform. Common access methods include an issuer’s website or mobile app and supported browser or Android autofill features.
For example, Capital One currently lets eligible cardholders access virtual numbers through its website and mobile app. Google supports virtual-card enrollment for eligible cards from participating banks or networks in supported regions. American Express lets eligible U.S. cardholders enroll supported cards for its Google-based virtual-card feature.
Before relying on a virtual number, check:
whether your exact card or account is eligible;
whether identity verification or enrollment is required;
whether the credential works only online or in supported apps;
whether it is general-use, merchant-specific, persistent, or temporary;
whether recurring payments are supported;
how the issuer lets you lock, replace, or delete it; and
what happens when the underlying card is locked, replaced, or closed.
Do not assume two issuers implement virtual cards the same way. Capital One, American Express, Google-supported issuers, and commercial Mastercard systems expose different eligibility rules, controls, and checkout behavior.
What a Virtual Card Does Not Protect You From
A virtual card number addresses one main problem: exposing the number associated with the underlying physical card. It does not eliminate the other ways online payments can fail.
Advertisement
Fraudulent merchants: a substitute number can still authorize a purchase from a scam seller.
Account takeover: an attacker who gains access to your issuer account or authentication method may present a different problem from stolen merchant-side card data.
Underlying debt: a virtual credit-card number is still connected to the underlying credit account, so balances, interest, fees, and repayment obligations remain.
Merchant disputes: using a virtual number does not automatically create stronger refund, chargeback, or statutory rights than the underlying account already provides.
Compatibility problems: the feature may not be available for the card, platform, region, or merchant involved in the transaction.
If the goal is broader than concealing a physical card number, compare alternatives to credit cards for online payments by credential exposure, reachable funds, dispute options, and debt risk.
A virtual card number is most useful when you already intend to make a legitimate online purchase and want the merchant to receive a substitute credential instead of your physical card number. Used in that role, it can reduce credential-reuse risk without changing the account that ultimately pays for the transaction.
You must be logged in to post a comment Login