A TD Visa card transaction was approved for $3,200 [1] despite the cardholder entering the wrong PIN three times [2].

The incident raises questions about the efficacy of PIN-based security for high-value transactions. While many users expect a card to lock after multiple failed attempts, certain banking protocols allow a transaction to proceed through alternative verification methods.

Mark Sach‑Anderson, an auto‑repair shop owner in Etobicoke, Ontario, recorded the event at his place of business. Video evidence shows the transaction was authorized after the third incorrect entry [2]. The purchase totaled $3,200 [1].

According to the reports, the approval occurred because of TD's chip‑and‑signature fallback protocol. This system allows a transaction to be authorized after multiple incorrect PIN entries instead of locking the card immediately. This mechanism is designed to ensure commerce continues if a user forgets their code, provided a signature can be obtained.

A TD Bank spokesperson said the occurrence was "standard protocol" [3].

Sach‑Anderson's experience highlights a gap between consumer expectations of digital security and the actual operational rules of payment processors. Most consumers assume that three failed PIN attempts trigger a security freeze to prevent unauthorized access. In this case, the fallback system bypassed that restriction to complete the payment.

TD Visa card transaction was approved for $3,200 despite the cardholder entering the wrong PIN three times.

This incident illustrates the persistence of 'fallback' security measures in the banking industry. While chip-and-PIN technology was introduced to reduce fraud, the ability to revert to a signature-based authorization means that a stolen card could potentially be used for large purchases even if the thief does not know the PIN. It suggests that the convenience of preventing legitimate users from being locked out of their funds currently outweighs the strict enforcement of PIN security for some financial institutions.