Tip from SmartRetry Avoid rapid automated retries, as hammering the issuer during a file lock can prolong the concurrency block. Instead, schedule a multi-hour backoff or temporarily pause batch processing for that specific BIN to give the issuer's database sync time to clear.
Visa
Visa Issuer Response Code 28: File Update File Locked Out
Last updated: September 25, 2026
About 28 - "File update file locked out"
Key details
- 28
- Issuer Response Codes
- 28
- File update file locked out
What it means
Visa response code 28 indicates that an issuer or network file required to process an update or inquiry is temporarily unavailable or locked out. This is a transient technical system error on the issuing bank or network side, rather than a reflection of the cardholder's account standing. It specifies that the endpoint or file could not be accessed at the exact moment of processing.
Classification & retryability
Implement a delayed retry strategy with backoff. Do not attempt rapid immediate retries, as the file lock or unavailability is temporary but may take a short time to clear. If the error persists after multiple spaced attempts, halt automated retries.
Why does code 28 occur?
- The issuing bank or network is undergoing temporary system maintenance affecting file access.
- A transient technical glitch caused the required file for the update or inquiry to be locked at the moment of processing.
- An internal synchronization issue at the issuer is temporarily blocking data inquiries or updates.
How to solve 28?
Treat the decline as a temporary system or network error. Wait for a short period to allow the issuer's file lock to clear, then resubmit the transaction using a delayed backoff schedule. If subsequent attempts return the same code, escalate the issue to your payment processor or acquirer with the transaction identifiers and timestamps.
Solving as a merchant
Pause immediate retries and utilize a delayed retry approach. Do not advise the customer that their card is invalid or prompt them for a replacement card solely based on this code. Instead, monitor your transaction logs, and if the code recurs persistently, contact your acquirer to investigate the endpoint lock or unavailability.
Solving as a customer
Since this is a backend technical issue at the issuer or network level, the customer does not need to take immediate action regarding their card. If the merchant cannot resolve the error after delayed retries, the customer may be asked to provide an alternate payment method to complete the checkout.
Frequently asked questions about this topic
Author
Kyle Regacho
Focused on payment recovery, decline codes, and authorization optimization at SmartRetry. Helps payment teams turn failed transactions into recovered revenue
Read all articles >Articles you may find interesting:
View all
Turning Payment Declines into Revenue with Context-Aware Retry Logic
Blind retries waste fees and damage issuer trust. By analyzing decline codes and timing reattempts around payroll cycles, payment teams can successfully salvage recurring revenue without customer disruption.

Why Payments Fail: Decoding Decline Codes and Modernizing Retry Logic
Surface-level decline messages conceal critical issuer signals. Discover how intelligent retries, network tokens, and behavioral timing protect MID health and systematically recover lost recurring revenue.

Decoding Payment Declines: Turning Authorization Failures into Recovered Revenue
Blindly retrying failed transactions hurts authorization rates and risks network fines. Discover how decoding issuer responses turns card declines into recovered revenue.

The Real Cost of Payment Declines and How to Recover Lost Revenue
Payment failures cost merchants billions in uncaptured revenue and customer churn. Discover how data-driven retries and response code intelligence help teams recover failed transactions and protect conversion.