How card testing with CVV works, in short

Card testing is a fraud attack in which someone runs a high volume of small authorization attempts against a merchant's checkout to learn which stolen card numbers are still active. The CVV field is the deciding test. When an issuer returns a CVV match, the attacker marks that card as live, resells it at a premium, or uses it for a larger purchase. The merchant sees a burst of tiny orders first and a wave of chargebacks weeks later. This guide covers the mechanics from the merchant side, the signals that separate probe traffic from normal shopping, and the controls that stop it.

read more

Why the CVV code matters more than the card number

A card number can be generated or guessed in bulk, but the three or four digit CVV value printed on the card is not present in a basic magnetic stripe dump and is not stored by legitimate merchants. For an attacker, a CVV match is the closest thing to proof that a card record is complete and current. That is why so many probes target checkouts where CVV is required. It is also why the CVV is treated as sensitive authentication data under PCI DSS: merchants may pass it to the issuer during authorization but may not store it afterward, and keeping it is a serious compliance failure.

related merchant card cvv testing services

One point merchants get wrong: a CVV match confirms that the number is live and the code is correct. It does not confirm that the person typing it owns the card. Card testing exists precisely because that gap can be exploited.

read more

How the attack unfolds

  1. Reconnaissance. The attacker studies a checkout to learn which fields are validated, whether AVS is enforced, and whether 3D Secure is triggered.
  2. Probing. A script submits many attempts in a short window, often at low dollar amounts, across many cards from the same device, IP range, or email pattern.
  3. Sorting. Results are split into live cards, cards that fail CVV, and cards that fail address checks. Live cards are kept and the rest are discarded.
  4. Monetization. Validated cards are sold or used for high-value goods, gift cards, or digital items that deliver instantly.

Signals that separate probing from real shoppers

  • Order values clustered under a few dollars, especially repeated on the same account.
  • Many distinct card numbers attempted from one device, IP address, or session.
  • Card numbers submitted in sequence or drawn from a narrow set of BIN ranges.
  • CVV mismatch rates far above baseline, with the same billing details reused across attempts.
  • Disposable email domains, mismatched billing and shipping countries, and accounts created minutes before checkout.
  • Authorization attempts that spike overnight or inside a narrow time window while completed orders stay flat.

Parameter bands worth setting

Exact numbers depend on your catalogue and average order value, but these ranges are a reasonable starting point for a card-not-present store.

Not able to write this guide

  • Attempts per card across the whole site: 1 to 2 per day. Anything higher is a probe.
  • Attempts per device or IP per hour: 5 to 10 for normal retail, 20 or more is a strong alert.
  • CVV mismatch rate: 1 to 5 percent of attempts is typical, 15 percent or higher points to testing.
  • Decline rate on a single BIN or card range: flag when it exceeds 40 percent with meaningful volume.
  • Chargeback ratio: keep it under 0.5 percent of transactions to stay clear of card network monitoring programs.

Pitfalls that let testing through

  • Treating a CVV match as buyer verification instead of a check on the card record.
  • Relying on AVS alone, since address data is often bundled with stolen card records.
  • Blocking every failed attempt, which inflates false declines for legitimate customers who mistype.
  • Ignoring the authorization rate. A sudden rise in approvals on micro-transactions is one of the clearest warnings.
  • Leaving 3D Secure optional on digital goods, where delivery is instant and irreversible.
  • Keeping CVV data in logs or order notes, which violates PCI DSS and turns one breach into many.

FAQ

Does a CVV match prove the buyer owns the card?

No. It shows that the card record is live and the code is correct. Ownership is a separate question, and that is the gap card testing exploits.

Why do attackers use small amounts?

Small charges are less likely to trigger a cardholder alert and keep the cost of a failed probe low. The goal is information, not goods.

Can card testing hurt a merchant that blocks the orders?

Yes. Declined attempts still cost authorization fees at many processors, and fraud that slips through leads to chargebacks, refunds, and possible placement in a network monitoring program.

Does 3D Secure stop card testing?

It raises the cost of testing because challenges interrupt automation, and liability often shifts to the issuer. It does not eliminate attempts, so velocity controls and monitoring still matter.