Computer Network & Information Services.
Internet service providers, hosting and online information services.
- MCC
- 4816
- Category
- Utility Services
- Cardflo support
- Yes
What MCC 4816 covers
Merchant Category Code 4816 is the ISO 18245 identifier used by the card networks for computer network & information services. Acquirers, issuers and regulators use this code to set interchange, scheme fees, fraud rules and reporting categories for every transaction your business processes.
Internet service providers, hosting and online information services. Choosing the right MCC is critical: an incorrect code can lead to higher interchange, surcharges, or, in regulated categories, declined transactions and account holds.
This MCC encompasses internet service providers (ISPs), web hosting companies, data processing firms, and other online information service providers. Services generally involve recurring monthly or annual billing, with ticket sizes ranging from low-cost personal hosting plans to high-value enterprise network solutions.
Chargebacks often arise from 'services not rendered' (e. g. , website downtime, internet outage), 'not as described' (e. g. , slower speeds than advertised, missing features), or unauthorised use of services (e. g. , phishing sites hosted on a server, account takeover generating unexpected charges).
Fraudulent sign-ups are a concern, particularly for domain registrations or hosting, where services can be quickly exploited.
Compliance with PCI DSS is critical for handling cardholder data in this sector.
Cardflo's secure payment gateway, coupled with its advanced fraud detection and recurring billing capabilities, supports these merchants in managing continuous revenue streams while mitigating the risks associated with digital service provision and online fraud.
Providers in this sector need robust fraud screening for new accounts, especially given the potential for rapid service exploitation in cases of account takeover or fraudulent sign-ups.
For recurring services, focus on transparent service level agreements (SLAs) and proactive communication regarding any service interruptions, which often lead to 'services not rendered' disputes.
Given the varying ticket sizes, from small hosting plans to large enterprise contracts, configure your acceptance gateway to dynamically apply 3DS based on transaction value and customer risk profile. Acquirer partners will scrutinise dispute rates for higher-risk hosting activities.
Acquirer and acquirer assessment stance.
Medium-risk standard board with monitoring. Risk factors include potential for service abuse by fraudsters (e. g. , hosting illegal content), high churn, and service-related disputes.
Robust fraud prevention and clear service level agreements are essential. Reserves may be considered for newer entities or those with high churn/dispute rates.
Dispute and chargeback profile.
Common dispute reason codes are "13.1 / 4853 (services not as described)" and "10.4 / 4837 (fraudulent transaction)". 'Services not as described' often stems from service outages, speed discrepancies, or unfulfilled features.
To defeat this, provide detailed service logs, uptime monitoring reports, SLA documentation, and customer support interaction records. 'Fraudulent transaction' arises from stolen credentials used for hosting or domains, or account takeover.
Compelling evidence includes KYC/KYB data, IP address logs, device fingerprinting, and proof of legitimate service usage by the authenticated account holder.
See also: chargeback management · payment response codes · Compelling Evidence 3.0.
Book a scoping call to see how Cardflo would set you up.
How Cardflo handles MCC 4816
- Placement with acquirers that actively board MCC 4816 businesses in your region.
- Recurring-billing infrastructure designed for utility and metered-service bill runs.
- Surcharge-rule support that meets local utility-regulator requirements.
- Dunning and decline recovery flows tuned to long-tenure subscriber bases.
- Settlement and reconciliation aligned to monthly utility billing cycles.
- Dedicated onboarding manager familiar with regulated utility processing.
Payment methods typically enabled.
Onboarding checklist.
What acquirers typically ask to see when boarding MCC 4816. Cardflo collects this once and reuses it across every acquirer we route you through.
- Business registration and beneficial-owner documentation (KYB, UBO).
- Regulator licence or equivalent authority to bill for the metered service.
- Recurring-billing policy, including advance notice of upcoming charges and cancellation flow.
- Six months of processing statements or ledger extract demonstrating billing cadence.
- Cardholder-consent workflow evidence for stored credentials.
- Chargeback ratio and dispute history covering the last six months, including any Visa or Mastercard monitoring-programme status.
See also: Know Your Customer (KYC) · high-risk merchant · smart routing.
Talk to an acquiring specialist about your MID setup.
Common questions
What are the common chargeback reasons for web hosting and ISP services?
Common chargeback reasons include 'services not rendered' (e. g. , prolonged downtime, failure to activate service), 'not as described' (e. g. , inadequate bandwidth, missing features), and 'unauthorised transaction' (stolen credentials used for new accounts or upgrades).
'Fraudulent transaction' is also prevalent where services are provisioned to bad actors using stolen payment information for illicit activities like phishing or malware distribution.
How can internet service providers manage their fraud risk effectively?
ISPs can manage fraud by implementing multi-factor authentication for account access and changes, utilising advanced fraud screening tools at sign-up (including IP analysis, device fingerprinting, and email risk scoring), and collaborating with industry bodies to identify and block known fraudsters.
Limiting initial service allowances or requiring upfront payments for new customers from high-risk regions can also be effective.
Are there specific PCI DSS implications for web hosting companies and ISPs?
Yes, web hosting companies and ISPs typically have significant PCI DSS implications, especially if they directly store, process, or transmit cardholder data on their infrastructure, or if they offer payment gateways as part of their service.
They often fall under PCI DSS Level 1 or 2. Even if they outsource direct payment processing, their network infrastructure must be PCI compliant to ensure a secure environment for any transmitted card data.
What specific data should internet service providers (ISPs) retain to combat 'service not rendered' chargebacks during network outages?
ISPs should diligently log and retain detailed records of network performance and customer interactions to combat 'service not rendered' chargebacks during outages. This includes comprehensive incident reports outlining the cause, duration, and affected areas of any outage.
Maintain logs of service agreements (SLAs) with customers, demonstrating adherence or notification of breaches. Records of customer support calls, tickets, and email communications related to the outage, including any proactive service credit offers, are crucial.
This evidence proves service provision outside the outage and efforts to resolve issues, justifying continued billing for the period.
How can web hosting companies effectively prevent and resolve 'unauthorised transaction' disputes where a scammer used a stolen card to host content?
Web hosting companies must implement robust onboarding and ongoing monitoring to prevent and resolve 'unauthorised transaction' disputes arising from fraudulent content hosting. At sign-up, utilise advanced fraud tools that analyse IP reputation, email velocity, and geo-location, combined with strong identity verification (KYC).
For existing accounts, monitor for unusual activity, such as sudden resource spikes or domain changes, which might indicate an account takeover.
In a dispute, provide account creation details, IP logs, server access logs, and any evidence from your content monitoring systems showing the nature of the hosted content. This demonstrates due diligence in preventing abuse.
Other MCCs in Utility Services
Related features.
Related guides.
Ready to improve your payments setup?
Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.