What a CVV attack signature is
A CVV attack signature is the set of traits a payment processor or fraud engine records when someone tests card numbers. The signature is not one data point. It is a cluster: attempt volume, timing, decline codes, ticket size, device data, and geography. Acquirers and fraud vendors match live traffic against these clusters. A match raises the risk score for the whole session.
Signals inside the signature
- Attempt volume: dozens or hundreds of authorization requests from one IP, device ID, or card BIN range in a short window.
- Small tickets: repeated $0.01 to $2.00 authorizations. Testers pick low amounts to limit loss if a charge settles.
- Decline mix: a high share of CVV mismatch, invalid card number, and do not honor responses inside one burst.
- Sequential data: card numbers that climb by one, or the same BIN with different last four digits.
- Repeat attempts: one card tried several times with different amounts or expiration dates.
- Identity gaps: billing address, ZIP, and cardholder name that do not match issuer records.
- Time clustering: bursts inside minutes, often at low-traffic hours for the merchant.
- Shared device signals: one browser fingerprint, one user agent, or one proxy pool across many cards.
Why response codes matter
Issuers return distinct codes for CVV failure, address mismatch, and closed accounts. A shopper who mistypes a card produces one or two declines. A tester produces a run of them. Fraud engines weight the ratio, not just the count.
How processors and merchants react
Most gateways apply velocity limits per IP, per card, and per BIN. They add CAPTCHA or 3-D Secure step-up, block the device fingerprint, and send the order to manual review. Acquirers can place a merchant on a chargeback monitoring program when test traffic turns into fraud losses.
Limits of the signature
No single signature catches all testing. Attackers rotate proxies, devices, and BINs. Detection depends on cross-merchant data sharing, and small merchants often lack that view.