The head of America’s Credit Unions is warning that a bill pushed by Sens. Dick Durbin (D-IL) and Roger Marshall (R-KS) to break up the Visa-Mastercard duopoly on credit card processing could leave consumers more exposed to fraud and data breaches.
Scott Simpson, president and CEO of the trade association, raised the concern during a Tuesday policy event in Washington, D.C. that included Treasury Secretary Scott Bessent, in an exchange with Breitbart News economy columnist John Carney.
The legislation in question, the Credit Card Competition Act (CCCA), was first introduced by Durbin and Marshall in 2022 and reintroduced in January. The senators say the bill would inject competition into a credit card market long dominated by Visa and Mastercard, which together control more than 80 percent of it. The bill was originally cosponsored by then-Sen. JD Vance (R-OH), along with Sens. Peter Welch (D-VT), Josh Hawley (R-MO), and Jack Reed (D-RI).
Under current rules, merchants accepting a given credit card are tied to whatever payment network that card runs on and must pay the fees that network sets. The CCCA would change that by requiring banks holding more than $100 billion in assets to give merchants a choice of at least two networks to process a transaction — with at least one of those options being neither Visa nor Mastercard.
Supporters of the bill argue it would cut merchants’ operating costs and that those savings would ultimately reach consumers. Critics counter that merchants are likely to pocket the savings themselves, and that card companies may respond by scaling back consumer rewards to offset lost revenue.
Simpson’s remarks add a security dimension to that debate. He told Carney that the current interchange system, which sets the fees and rules issuers rely on, exists in part to fund fraud protection and secure contracts with consumers — protections he said come at a cost to the issuing institution.
“That’s what the interchange system is built for — is to establish contracts with the American consumers and reliable protection. Well, that protection comes at the expense of the issuer,” Simpson said.
Carney had raised the issue directly, noting that “a lot of people are worried about fraud and cybersecurity, and this could impact the ability of issuers to be able to, especially I think credit unions, but all issuers to be able to deal with fraud and cybersecurity.”
Simpson went on to argue that retailers, unlike card issuers, have historically had less incentive to invest in protecting consumer data.
“We look at the biggest data breaches in the history of our country and they tend to come from retailers because they don’t have incentives. They’re not incentivized by the system to protect that data, and so it gives us zero confidence as issuers,” Simpson said.
The exchange underscores a central fault line in the fight over the CCCA: whether shifting more control over payment routing to merchants would genuinely benefit consumers through lower prices, or whether it would trade cost savings for weaker safeguards against fraud and data theft.
