A CVV attack alert is a notice that someone is testing card numbers at volume. The test uses the card verification value, the 3 digit code on the back of most cards or the 4 digit code on the front of American Express cards. The alert comes from a card issuer, a card network, a payment processor, or a fraud tool inside a gateway. It points to card testing. Other names for the same event are card enumeration and a BIN attack.
What the attacker is doing
The attacker submits many card numbers to one checkout page or one authorization endpoint. Small amounts are common, often under $1. A live card returns an approval. A dead card returns a decline. The attacker keeps the approvals and drops the rest. Volume carries the value. One card number is worth little. Ten thousand numbers with matching CVV codes have resale value on carding markets.
Triggers for the alert
- Authorization attempts from one IP address across many card numbers in a short window.
- A decline rate that jumps above the normal range for a merchant account.
- Card numbers used in sequence inside one bank identification number range, also called a BIN range.
- Small authorization amounts repeated against the same merchant.
- Address verification and CVV checks that fail on most attempts.
- Many different card numbers tied to one device fingerprint or one shipping address.
- Traffic patterns that skip the normal path through a site, such as direct calls to the payment endpoint.
Who sends the notice
Visa runs Account Attack Intelligence and publishes fraud disruption reports. Mastercard runs similar monitoring. Both send notices to issuers and acquirers. The acquirer passes the notice to the merchant. A gateway or a fraud vendor can raise the same flag without a network notice. Issuers also send account alerts to cardholders when they see test charges.
What a consumer should do
- Read the card statement line by line, including pending charges.
- Call the number on the back of the card and ask for the fraud team.
- Request a new card number. A new CVV comes with it.
- File a report at IdentityTheft.gov and keep the confirmation number.
- Check the other cards in the same wallet for small test charges.
What a merchant should do
- Require CVV verification on every card-not-present order. Do not store the CVV after authorization.
- Turn on address verification and set a rule for mismatches.
- Add 3-D Secure for high risk orders.
- Set rate limits per IP address, per card, and per device.
- Block or review orders under $1 that come in bursts.
- Review the alert with the acquirer and document the response.
Legal status
In the United States, card number misuse falls under 18 U.S.C. § 1029, the access device fraud statute. Penalties include fines and prison terms. PCI DSS Requirement 3.2.1 bars storage of sensitive authentication data, including the CVV, after authorization. The rule exists because a stored CVV is a target.
Numbers and limits
Public counts of CVV attacks are incomplete. The FTC and the FBI Internet Crime Complaint Center publish aggregate complaint totals, not attack counts. The share of card-not-present fraud caused by card testing is not published in a single figure. Treat any one statistic with care.