Answered September 2026

It can be legitimate to give those card details by phone, but only after you independently verify that you called Mint’s official number—the request alone does not prove the agent is genuine.

“I just came to the US on a student visa and don't have a credit card yet. I tried to buy a phone and plan on the Mint Mobile website, but my debit card and Apple Pay failed. When I called sales, they asked for my full debit card number, expiration, and security code to make the purchase on my behalf. Is it normal to share card details this way in the US?”

Summary

The request is not automatically a scam: verified merchants do take card details for telephone payments. You can avoid guessing by ending the current call and redialing Mint’s number from its own Help Center before giving any information.

Your safest route depends on whether you independently verified the number and whether you already disclosed the card details.

You called Mint’s verified numbercan be legitimate

If you dialed 800-683-7392 using Mint’s own Help Center—not a search ad, callback, or text—collecting card data by telephone is a recognized merchant process. The FTC’s rule is not to disclose an account number unless you initiated the call, while PCI DSS requires the merchant not to retain the after authorization (Mint Help Center; FTC debit-card guide, p. 4; PCI guidance, pp. 3–4).

The number was not verifieddo not share

Do not continue the purchase on that call. Hang up and contact Mint at 800-683-7392 or mintmobile.com/chat; the FTC specifically warns against relying on top search results for business contact information (Mint Help Center; FTC, Jan. 30, 2026).

You already shared the detailsact now

If the number or agent now seems doubtful—or an unfamiliar charge appears—contact the card issuer immediately using the number on the back of the card. CFPB guidance says to cancel and replace the card when stolen data is used, and a covered U.S. debit-card error should be reported within the deadlines (CFPB, June 17, 2025; 12 CFR 1005.6 and 1005.11).

Verifying the official number makes the call safer, but Mint’s published contact page does not confirm its internal telephone-order procedure.

Read the full explanation

Watch out for

A search result is not verificationDo not trust a sales number merely because it appeared first in search results. The FTC warns that scammers buy ads to place fake numbers at the top; use Mint’s published number, 800-683-7392, or mintmobile.com/chat instead (FTC, Jan. 30, 2026; Mint Help Center).
A recorded CVV is a problemPCI DSS allows a merchant to collect card data for authorization, but forbids retaining the afterward—even in encrypted form. If the call is recorded, ask whether payment details are excluded from the recording; do not continue if the agent says your CVV will remain in it (PCI DSS telephone-payment guidance, pp. 3–4).
Never share an account verification codeThe printed CVV requested for the card transaction is different from an account verification code. The FTC says to keep account verification codes to yourself, so end the call if the agent asks for a one-time code used to verify your bank, Apple Pay, email, or other account (FTC, Jan. 30, 2026).
Two different reporting clocksIf only your debit-card number is misused and you still have the card, report unauthorized transactions within 60 days after the statement was sent. If the physical card or another access device is lost or stolen, notifying the bank within two business days limits liability to the lesser of $50 or the unauthorized transfers made before notice; report immediately rather than waiting for either deadline (FTC debit-card guide; 12 CFR 1005.6(b)).
New-account and writing exceptionsIf a disputed transfer occurred within 30 days after your account’s first deposit, the bank may use 20 business days instead of 10 for its initial response and, in specified cases, as long as 90 days for the investigation. After an oral dispute, the bank may also require written confirmation within 10 business days and must give you the address (12 CFR 1005.11(b)(2), (c)(3)).

Next steps

These steps let you verify the seller first and protect your bank account if anything already went wrong.

Before sharing card details

End and independently verify the call

If you did not obtain the number directly from Mint’s website, end the call. Dial 800-683-7392 yourself or open mintmobile.com/chat; do not use a callback number, texted link, or sponsored search result (Mint Help Center; FTC, Jan. 30, 2026).

Requirements

Mint’s published support number: 800-683-7392
Official chat: mintmobile.com/chat

On the verified line

Set limits before paying by phone

You may provide the card number, expiration date, and CVV if you are comfortable proceeding. Do not provide any account verification code or allow remote access to your phone or computer; PCI DSS also prohibits storing the CVV after authorization (FTC, Jan. 30, 2026; PCI guidance, pp. 3–4).

Requirements

Exact phone-and-plan total
Confirmation that payment details are excluded from any retained call recording

Immediately if details were shared

Secure the card if the call now seems suspicious

Call the bank or card issuer using the number printed on the back of the card. Tell it the card details may be compromised and request cancellation and replacement; CFPB guidance says to act immediately when you suspect an unauthorized debit or charge (CFPB, June 17, 2025).

Requirements

The physical debit card or issuer’s official app

As soon as a charge appears

Report any unauthorized debit

For a covered U.S. consumer debit account, give the bank oral or written notice immediately and no later than 60 days after it sent the statement showing the error. If the bank requires written confirmation after your oral report, send it within 10 business days to the address the bank provides (12 CFR 1005.11(b)).

Requirements

Your name and account number
Transaction type, date, and amount
Why you believe the transaction was unauthorized

Legal sources

The answer comes from Mint Mobile’s own Help Center, the Federal Trade Commission, the Consumer Financial Protection Bureau’s Regulation E text, and the PCI Security Standards Council.

Mint Mobile Help: How do I contact Mint Mobile?

This is Mint Mobile’s published support number, chat address, and operating schedule.

Mint Mobile Help: How do I contact Mint Mobile?

If you have a question about your service, please call our Mint support team by dialing 611 from your Mint phone or 800-683-7392, or chat with us at mintmobile.com/chat. Our customer care humans are available 7 days a week 5AM-7PM PST.

Read the full text

FTC, Lost or Stolen Credit, ATM, and Debit Cards

The FTC permits a clear distinction between an outgoing call you initiated and an unverified incoming call, and states the card-number-only reporting rule.

FTC, Lost or Stolen Credit, ATM, and Debit Cards

pages 3–4

Don’t disclose your account number over the phone unless you initiate the call. If someone makes unauthorized transactions with your debit card number, but your card is not lost, you are not liable for those transactions if you report them within 60 days of your statement being sent to you.

Read the full text

PCI DSS Information Supplement: Protecting Telephone-based Payment Card Data v2.0

PCI’s own guidance recognizes telephone card payments but forbids retaining the security code after authorization.

PCI DSS Information Supplement: Protecting Telephone-based Payment Card Data v2.0

pages 3–4

The following information and guidance is intended to provide payment security advice for merchants and service providers who accept and/or process payment card data over the telephone. The Payment Card Industry Data Security Standard (PCI DSS), however, stipulates that the three-digit or four-digit card verification code or value printed on the card (CVV2, CVC2, CID, or CAV2) cannot be retained after authorization, and full primary account numbers (PANs) cannot be kept without further protection measures. It is a violation of PCI DSS Requirement 3.2 to store any sensitive authentication data, including card validation codes and values, after authorization even if encrypted.

Read the full text

FTC Consumer Alert: How to handle unexpected calls

The FTC explains how to verify a company independently and warns against sharing account verification codes.

FTC Consumer Alert: How to handle unexpected calls

Verify the story by contacting the company or bank yourself. Do not rely on top search results to find a company’s contact information—scammers often buy paid search ads so their fake numbers appear at the top of the listings. And no matter who says they’re calling, never share your personal or account information, don’t grant anyone remote access to your phone or computer, and keep account verification codes to yourself.

Read the full text

CFPB: Watch accounts closely when card data is hacked

The CFPB says to contact the issuer immediately and replace a card when its data is being misused.

CFPB: Watch accounts closely when card data is hacked

Contact your bank or card provider immediately if you suspect an unauthorized debit or charge. If a thief takes money from your bank account by debit, or charges items to your credit card, you should cancel the card and have it replaced before more transactions come through.

Read the full text

12 CFR 1005.6

Regulation E supplies the two-business-day physical-device rule and the 60-day statement rule.

12 CFR 1005.6

(b)(1), (b)(3)

If the consumer notifies the financial institution within two business days after learning of the loss or theft of the access device, the consumer's liability shall not exceed the lesser of $50 or the amount of unauthorized transfers that occur before notice to the financial institution. A consumer must report an unauthorized electronic fund transfer that appears on a periodic statement within 60 days of the financial institution's transmittal of the statement to avoid liability for subsequent transfers.

Read the full text

12 CFR 1005.11

This provision states when and how to notify a bank about a debit-account error.

12 CFR 1005.11

(b)(1)(i)–(iii)

Is received by the institution no later than 60 days after the institution sends the periodic statement or provides the passbook documentation, required by § 1005.9, on which the alleged error is first reflected; Enables the institution to identify the consumer's name and account number; and Indicates why the consumer believes an error exists and includes to the extent possible the type, date, and amount of the error, except for requests described in paragraph (a)(1)(vii) of this section.

Read the full text

12 CFR 1005.11(b)(2)

A bank may require written confirmation after an oral error report, but must provide the destination address.

12 CFR 1005.11(b)(2)

(b)(2)

A financial institution may require the consumer to give written confirmation of an error within 10 business days of an oral notice. An institution that requires written confirmation shall inform the consumer of the requirement and provide the address where confirmation must be sent when the consumer gives the oral notification.

Read the full text

12 CFR 1005.11(c)(3)

New-account and certain debit transactions can receive longer investigation periods.

12 CFR 1005.11(c)(3)

(c)(3)(i)–(ii)

The applicable time is 20 business days in place of 10 business days under paragraphs (c)(1) and (2) of this section if the notice of error involves an electronic fund transfer to or from the account within 30 days after the first deposit to the account was made. The applicable time is 90 days in place of 45 days under paragraph (c)(2) of this section, for completing an investigation, if a notice of error involves an electronic fund transfer that: Was not initiated within a state; Resulted from a point-of-sale debit card transaction; or Occurred within 30 days after the first deposit to the account was made.

Read the full text

These are the official company, FTC, CFPB, Regulation E, and PCI rules published on the cited dates; rules and contact details can change.

This is general information about official processes, not legal advice; SettleKit is not a law firm.

Join the SettleKit newsletter

We research the hard parts of settling in the US and write articles you will not find anywhere else. Subscribe to get each new article by email.

One email per new article. Unsubscribe anytime.

This is likely not your only questionCheck out SettleKit, the best source on the internet for newcomers to the US.
Build your free roadmap