Company card compromised: kill the card, save the autopays, prove the damage

Tuesday, 08:40. A bank text about a $1,340 charge at an electronics retailer arrives, and nobody in the team bought so much as a cable. The card is a shared one — it has paid the software stack, the ads, and the flights for two years, and nobody can name every service riding on it. That combination — one card, many services, no list — is how a one-hour fraud turns into a two-week outage of the whole company's payments, because cancelling the card kills every autopay at once. This runbook is the sequence that keeps the fraud small and the damage boring: freeze first, enumerate before the declines start, replace deliberately, reconcile line by line, report in writing, and make the next card harder to abuse. The invoice fraud checklist covers the fake-invoice cousin of this incident; this page is the plastic itself. The one rule that runs the whole page: the card is dead in the first hour, but the list of what it was feeding exists before you call the bank.

1. The first hour: freeze the card, don't debate it

2. Enumerate every autopay before the declines arrive

3. Replace the card on your schedule, not the bank's

4. Reconcile the fraud window line by line

5. Report, document, and close the loop

6. Make the next card boring before it's urgent

The whole discipline fits one sentence a five-person team can keep: freeze within the hour, enumerate before the declines, migrate by rank, reconcile the window, report in writing, and end the single card forever. A compromised card handled this way costs one afternoon and one ledger table. Handled the usual way, it costs the domain, the hosting, the ads, and a week of every owner's attention — for the same thirty dollars of fraud.