What Is a Card Testing Attack?
A card testing attack is a fraud pattern in which someone runs a large number of small payment attempts to learn which stolen card numbers still work. The attacker pushes card data into a merchant's checkout, reads the results, and keeps the cards that get approved. From the merchant's side it looks like a burst of tiny orders, a wall of declines, and chargebacks that arrive weeks later.
Why Fraud Rings Test Cards at All
Stolen card numbers go stale. Cardholders cancel cards, banks reissue them, and a batch bought from a dark market can carry numbers that died months ago.
Testing sorts the live cards from the dead ones. A verified number sells for more than an untested one, and it can fund gift cards, digital goods, or reshipped merchandise.
How a Card Testing Attack Unfolds
The steps hold steady across most campaigns, even when the tools change.
- Someone buys or trades a batch of card numbers, often bundled with names and billing addresses.
- They hunt for a store with a simple checkout, loose fraud rules, and a product that ships fast or delivers by download.
- They push small charges through the payment page, sometimes a dollar or less, and sometimes through donation forms or free trials where no goods change hands.
- Approvals mark live cards. Declines get thrown out.
- The live cards go toward larger purchases or get sold to other buyers.
Signs Your Store Is Being Used as a Test Bench
- Order volume jumps, but the average order value drops to a few dollars.
- One IP address or a small IP range places dozens of orders in minutes.
- Decline rates spike while a handful of approvals slips through.
- Different card numbers appear with the same billing address, email pattern, or device fingerprint.
- New accounts order gift cards, software keys, or other instant-delivery items.
- Traffic arrives from data center IPs instead of home or mobile connections.
- Card verification value checks fail in bulk.
Why Small Merchants Get Hit
Large retailers run layered fraud screening and pay teams to tune the rules. Small shops often run default gateway settings with no velocity caps, no address verification requirement, and no card verification value requirement.
Fraud rings scan thousands of stores at a time, so a weak checkout gets found and reused. The damage goes past lost goods: a wave of chargebacks can push a small merchant over a card network's dispute threshold, which brings monthly fees and a monitoring program.
How to Prevent Card Testing Attacks
Most defenses work by making a test slow, costly, or pointless for the attacker.
- Require the card verification value and address verification. A checkout that demands both rejects a large share of raw card data before an authorization happens.
- Set velocity limits. Cap payment attempts per IP, per card, per email, and per device inside a rolling window.
- Add a challenge. A CAPTCHA or bot check on the payment step breaks scripted testing.
- Use 3D Secure. Strong customer authentication shifts liability for fraud disputes to the issuer when the check passes.
- Block bad sources. Deny traffic from hosting providers and blocklists at the edge, not after the order lands.
- Watch failed attempts. Treat declines as a security signal, not just a payment annoyance.
- Screen new accounts. Hold instant-delivery orders from brand-new customers for manual review or a short delay.
What to Do After an Attack
- Cancel and refund the fraudulent orders before they ship, and stop fulfillment on anything flagged.
- Export the order data and pull out shared IPs, emails, device IDs, and card prefixes.
- Add those patterns to a blocklist in your gateway and your web application firewall.
- Call your payment processor and report what happened. Processors can waive some fees and flag the account for extra monitoring.
- Answer chargebacks with evidence, and refund small charges when fighting costs more than the dispute.
- Tighten the rules before you resume normal traffic, or the same ring will come back.
What an Attack Costs a Merchant
Lost merchandise is the visible cost. Chargeback fees add more, and they run from about $15 to $100 per dispute depending on the processor and the card network. A high dispute ratio can also trigger a network monitoring program with monthly fees and a reserve requirement.
Staff time is the quiet cost. Someone has to review orders, issue refunds, answer disputes, and retune the fraud rules, which pulls hours away from running the store.
Card Testing vs. Carding vs. Account Takeover
People use these terms as if they mean the same thing. They describe different stages of payment fraud.
- Card testing verifies which stolen numbers are active, using small charges that cost little when they fail.
- Carding covers the full trade in stolen card data, from acquisition to cash-out.
- Account takeover targets a customer login instead of a card, then uses the saved payment method inside the account.
FAQ
Is card testing illegal?
Yes. Using a payment card without the cardholder's permission is fraud in every U.S. state and under federal law. Merchants who process such charges on purpose can lose the right to accept cards.
Does a declined charge mean the card was stolen?
No. Declines come from expired cards, low funds, wrong billing addresses, and issuer rules. A cluster of declines from one source is the real signal, not a single one.
Who pays when a tested card turns into a chargeback?
The merchant does, in most cases. The cardholder disputes the charge, the issuer reverses it, and the merchant absorbs the amount plus a chargeback fee unless they win the dispute with evidence.
How long does an attack last?
Most bursts run from a few minutes to a few hours, because the attacker moves to the next store once the blocklist catches up. Repeated waves over several days point to an automated scanner that keeps your domain in rotation.
Key Takeaways
- Card testing uses small charges to find live stolen cards.
- Watch for low-value order spikes, high decline rates, and shared IP or device signals.
- Require CVV and AVS, add velocity limits, and put a bot challenge on checkout.
- Move fast after a burst: refund, blocklist, and call your processor.