What a BIN test actually is
A BIN test is a low-value authorization attempt made against a card number to find out whether that number is live. The BIN, or bank identification number, is the first six to eight digits of any card number. Those digits identify the issuing institution, the card brand, the card type (credit, debit, prepaid, charge), and usually the country where the card was issued. Someone running a BIN test is not trying to buy anything. They are trying to sort working numbers from dead ones before using them somewhere else.
From a merchant's side of the counter, a BIN test shows up as a string of tiny transactions with no pattern a normal shopper would produce. That is the part worth understanding, because the defense is built on recognizing the shape of the traffic, not on catching a single order.
What the first digits tell you
The BIN is public information by design. Every processor, gateway, and fraud tool reads it on each authorization. What it gives you:
- Issuer and brand. Which bank issued the card and which network carries it.
- Card category. Credit, debit, prepaid, or commercial. Prepaid and gift cards behave differently from a prime credit card.
- Country of issue. Useful when your customers are all domestic and an order arrives from somewhere else.
- Product level. Classic, gold, platinum, and similar tiers, which loosely correlate with spending limits.
None of this proves a card is stolen. A mismatched BIN country and IP country is a signal, not a verdict. Risk teams weigh it with everything else.
Why testing hurts a business
A card testing run costs the merchant money even when every attempt is declined. Each authorization carries a fee. Networks levy penalties when a merchant's decline rate and fraud rate climb past thresholds. A wave of failed attempts can also trip a gateway's own risk rules and get an account frozen mid-day. Chargebacks follow later, often months later, when the real cardholder notices the small charge on a statement.
The damage is disproportionate. A few hundred dollars of fraudulent purchases can trigger thousands in fees and a reserve requirement that ties up working capital.
Signals that a testing run is underway
Most fraud platforms and gateway rules look for a combination rather than one tell:
- Many small orders in a short window, especially amounts under a dollar or two.
- Card numbers that appear sequential or share a narrow BIN range.
- The same device, IP, or email pattern across dozens of attempts.
- High authorization decline rates paired with a spike in attempts.
- Billing and shipping details that change with every order.
- Orders placed at odd hours relative to the customer base.
How to block it
Layer the controls. No single rule stops a determined run, but stacked rules make a target expensive to hit.
- Velocity limits. Cap attempts per IP, per card, per email, and per device per hour. Tune the caps against your real traffic so you do not block loyal customers.
- Require CVV and AVS. Making the security code and address verification mandatory removes the cheapest attack path.
- Turn on 3-D Secure. Authentication shifts liability and stops most automated attempts at the door.
- Block known bad BINs and ranges. Fraud tools publish lists, and your own decline data will show you which ranges keep failing.
- Watch low-value orders. If your average order is $60, a run of $1 charges deserves a manual look.
- Use a fraud scoring service. Machine scoring catches patterns that individual rules miss.
What a legitimate BIN lookup gives you
Merchants use BIN data for ordinary business reasons too. Routing a transaction to the right network, deciding whether to accept a prepaid card, localizing currency, and setting up installment options all depend on it. A BIN checker that returns issuer, brand, type, and country is a normal operations tool. The line between that and fraud sits entirely in what the data is used for, which is why the useful question for any merchant is not whether BIN data exists but how fast their risk rules react when someone abuses it.