Credit card testing is a fraud technique where someone runs a batch of stolen or guessed card numbers through small charges to learn which ones still work. The numbers that authorize are kept for bigger purchases or resold, while the rest are thrown out. Merchants see it as a short burst of tiny orders, many of them declined.
What does credit card testing look like in practice?
The pattern is volume plus small amounts. An attacker fires hundreds of authorization requests in minutes, each for a few cents to a few dollars, because a small charge is what most banks approve without a second look.
Most runs target one merchant at a time, often a donation page, a gift card checkout, or a subscription signup form. Those pages allow a charge with no shipping address, so the attacker never has to handle physical goods.
Why do attackers bother with tiny charges?
A single decline tells the attacker nothing useful. A mix of declines and approvals does. An approved micro-charge confirms the card is live, the number is typed right, and the account has not been closed or frozen.
Why card testing costs merchants money
Every attempt lands on the merchant's authorization record, and a spike in declines can trigger penalties from the processor or the card network.
- Chargebacks: the cardholder disputes the small charge and the merchant pays a fee per dispute.
- Processor fees: a high fraud ratio can bring monthly fines or a frozen account.
- Lost revenue: real customers get caught by the anti-fraud rules a merchant turns on to stop the attack.
- Reputation: a site tied to card testing can land on network watchlists.
How do payment processors spot card testing?
Processors look at velocity and repetition, not the size of any single order. Clusters of attempts from one IP range, one device fingerprint, or one email domain are the clearest signal.
- Many different cards used on one account or IP in a short window.
- Sequential card numbers that share the same bank identification number (BIN).
- Repeated declines followed by one approval.
- Checkout times far below human speed.
Machine learning models score these signals and rule-based systems catch the rest. No single signal proves fraud, so processors weigh several at once before they block a checkout.
How merchants reduce card testing
- Turn on CVV and AVS checks. Requiring the three- or four-digit code and a matching billing address blocks most bulk attempts.
- Add rate limits. Cap how many payment attempts one IP, device, or email address can make per hour.
- Set a minimum order amount. A floor of a few dollars removes the cheap transactions testers prefer.
- Use a CAPTCHA or bot filter at checkout. Scripted attacks stall when the form needs a human action.
- Challenge high-risk BINs and countries that never match your real customer base.
- Watch your decline rate daily. A jump from a steady baseline is the earliest warning you get.
No single step is perfect on its own. Fraud teams stack them, then review the false positives so real customers do not get locked out of their own accounts.
What should cardholders do?
Cardholders face the fallout when their number gets tested, since even a small charge they do not recognize is a sign the card is compromised.
- Check statements for charges under a few dollars.
- Report unknown charges to the issuer and ask for a new card number.
- Freeze the card in the issuer's app while the dispute is open.
Federal law caps a cardholder's liability for unauthorized charges at $50 in most cases, and many issuers waive even that. Reporting the charge fast matters more than the amount.
Is credit card testing illegal?
Yes. In the United States, using someone else's card number without permission falls under wire fraud, access device fraud, and identity theft statutes, and penalties rise with the number of cards involved. Possessing or trafficking stolen card data is a separate crime on its own.
Card networks also treat testing as a violation of their operating rules. A merchant that looks the other way risks losing the ability to accept cards at all.
Frequently asked questions
Does a small charge mean my card was tested?
Not always, but it is a common pattern. Verify any small charge you do not recognize with your issuer before you assume it is a billing error.
Can a merchant just refund a test charge?
Yes, but the dispute often arrives before the merchant notices the charge. A refund does not erase the dispute fee in most card network rules.
How long does a card testing attack last?
Most runs last minutes to a few hours before checkout rules or processor models shut them down. Repeat attempts on the same site are common, which is why limits stay in place after the first attack.
Does card testing affect the cardholder's credit score?
No. Unauthorized charges and chargebacks do not appear on a personal credit report. Damage to the cardholder is limited to the lost card number and the time spent disputing it.