Card testing is the practice of submitting small authorization requests against a merchant's payment endpoint to learn which card numbers are still active. From the merchant side it appears as a burst of low-value orders, a high decline rate, and repeated CVV validation failures. The CVV, the 3 or 4 digit code printed on the card, is the field that decides most of those attempts. An issuer that enforces CVV matching declines any request where the code is wrong, so the response itself answers the question of whether the card and the code belong together.
question how does merchant card testing work with cvv?
What a Card Testing Attempt Looks Like to a Merchant
Each attempt arrives as a standard card-not-present authorization. It carries a card number, an expiry date, an amount, and a card verification value: CVV2 or CVC2 for Visa, Mastercard, and Discover, CID for American Express. That code is printed on the card and is not encoded in the magnetic stripe or the chip, which is why issuers treat it as evidence that the person submitting the transaction holds the physical card.
synonym merchant card assessment process
Testers keep amounts small so approvals do not trip issuer fraud models. They also spread attempts across many cards and many BIN ranges in a short window, because the goal is volume rather than a single purchase.
CVV Response Codes Merchants Receive
The authorization response carries a CVV result code. The common values are:
related merchant card cvv testing services
- M: match. The code submitted matches what the issuer holds on file.
- N: no match. The code is wrong.
- P: not processed. The issuer did not validate the code.
- S: the code should have been present on the request but was not.
- U: unknown, or the issuer is not certified for this service.
A cluster of N and S responses from one source is one of the clearest signs of testing. A high rate of M responses followed by immediate voids or refunds points to a tester confirming live cards.
Signals That Appear in the Transaction Stream
- A spike in authorization attempts, including declines, on an endpoint that normally sees steady traffic.
- Many distinct card numbers routed through one IP address, device fingerprint, or network provider.
- Card numbers drawn from sequential or clustered BIN ranges.
- Repeated attempts on the same card with different amounts.
- Billing and shipping details that change between attempts while the contact email stays the same.
- Disposable email domains and auto-generated customer names.
- Orders for digital goods or low-priced items with instant delivery.
Controls That Reduce Card Testing
- Require the CVV on every card-not-present transaction and reject submissions where the field is blank.
- Turn on AVS and decline on a full mismatch of street address and ZIP code.
- Enable 3-D Secure for high-risk orders so the issuer authenticates the cardholder.
- Rate-limit the payment endpoint by IP, device, and card fingerprint.
- Set velocity rules on attempts per card, per email, and per IP in a rolling window.
- Add a challenge such as CAPTCHA to the checkout form.
- Block disposable email domains and known proxy or hosting IP ranges at checkout.
- Review the issuer response mix each week and tighten thresholds when N and S codes climb.
Cost and Liability
Testing attacks generate authorization fees even when the transaction is declined, and they can push a merchant into a card brand monitoring program. Excessive fraud and chargeback ratios carry fines, higher processing rates, and in serious cases the loss of card acceptance. Because CVV data cannot be stored after authorization under PCI DSS, a merchant cannot re-verify a suspicious order later, which makes real-time rules the primary defense.
Response Steps When Testing Starts
- Pull the last 24 hours of authorization logs and group them by IP, device, and BIN.
- Block the top offending IPs and device fingerprints at the edge.
- Raise the CVV and AVS decline threshold for the affected checkout path.
- Notify your payment processor and ask their fraud team to review the traffic.
- Document the event and the rule changes for the next card brand review.