Answer first
A CVV attack IOC is an observable artifact left behind when someone tests stolen card numbers against a payment endpoint. The attack itself is a series of authorization requests. The IOC is the trace: declined attempts, repeated card numbers, one device hitting many cards, or a burst of orders inside a short window. No single IOC proves an attack. Investigators pair two or more before they act.
Payment gateway IOCs
- Decline rate above 30 percent on one gateway segment inside 15 minutes.
- Authorization attempts with CVV mismatch on more than 20 percent of a batch.
- Card numbers that differ only in the last four digits, sent in sequence.
- Many BINs from the same issuer country, all under one merchant account.
- Repeated $0.00 or $1.00 authorization holds used to check validity.
Card testing produces volume, not value. Fraud teams watch attempt counts more than settled revenue.
Network and device IOCs
- One IP address behind 50 or more authorization attempts in an hour.
- One device fingerprint linked to more than five card numbers in a day.
- Requests with a user agent that does not match the device type in the header.
- Traffic from hosting providers, proxies, or VPN exit nodes during checkout.
- Time zone, billing country, and IP geolocation that disagree across three fields.
Order and account IOCs
- Order rate that jumps 10 times above the same hour last week.
- New accounts created and used for checkout in under 60 seconds.
- Several accounts sharing one shipping address or one email domain pattern.
- Cart contents that are small, identical, and near the floor limit.
- Email addresses with random strings and no history on the domain.
Thresholds in practice
The numbers above are examples. They are not standards. Each merchant sets its own baseline from its own traffic. A shop that sells 20 orders a day will flag 3 declines from one IP. A marketplace will not. Baselines come from at least 30 days of normal data, split by hour and by channel.
What IOCs do not tell you
IOCs show pattern, not intent. A shared corporate NAT can look like one device with many cards. A gift card reseller can look like a card tester. Analysts confirm with order review, issuer contact, and chargeback data before blocking a segment.
Logging requirements
PCI DSS requires logging of access to cardholder data and system components. Keep gateway request logs with timestamps, IP, device ID, response code, and card BIN. Retain them for the period your acquirer requires. Without those fields, most of the IOCs above cannot be reconstructed after the fact.