A merchant data breach process comprises processing daily payment transaction data with a risk and compliance platform to obtain a fraud score for each constituent transaction. Constituent transactions with high risk fraud scores are sorted into a table according to the transaction date, cardholder, and merchant. The table data is scored according to suspected card visits, highly probable visits, and all card visits. The scores are normalized according to merchant size grouping through the use of multipliers. The normalized scores are summed together day-by-day into a final score. A timely warning of an underlying and expanding security rupture caused by a merchant data breach is issued for damage control and law enforcement.