Answer first
Card test data is a set of card numbers and field values that a payment processor publishes for use in a sandbox. The numbers pass format checks and issuer simulation. They carry no funds and identify no person. The "v2" tag is a vendor revision label, not an industry standard.
What the data set holds
A typical set covers 5 to 20 card brands and 3 to 10 outcome cases per brand. Each record names the expected result.
- PAN, a 16 digit number in a reserved test range
- Expiration date, often a fixed future month
- CVV or CVC, 3 or 4 digits
- AVS postal code and street address
- Cardholder name
- Expected authorization result: approval, decline, or error
- Decline code, such as insufficient funds or stolen card
- 3-D Secure outcome: authenticated, challenged, or failed
What changes between v1 and v2
Revision notes from processors list the same four edits. New BIN ranges. Added decline codes. Added 3DS test cases. Renamed API fields. A v2 file can break a test suite that hardcoded a v1 decline string. Pin the version in your fixtures and record the date you pulled it.
Test numbers and live numbers
Processors issue test PANs in reserved ranges. Stripe uses 4242 4242 4242 4242 for a Visa approval case. A live PAN must never enter a test environment. PCI DSS v4.0 requires controls when production account data is copied into non-production systems. Truncation or hashing is a common method for fixtures that need realistic values.
Card testing attacks are a separate topic
Fraud teams use the phrase "card testing" for a different act. An attacker submits many small authorizations to a merchant to find live cards. The merchant sees the traffic in its own logs. Signals include a jump in attempts from one IP address, many BINs from one session, amounts under $1, and a decline rate above 80 percent. Detection happens at the merchant, not in the sandbox.
Controls for merchants
- Rate limit by IP address and by card fingerprint.
- Require CVV and AVS on the first charge.
- Set velocity rules per card, per email, and per device.
- Route high-risk traffic to 3-D Secure.
- Alert when the decline rate moves more than 10 points in an hour.
Where test data comes from
One source is valid: the processor whose sandbox you call. Stripe, Adyen, Braintree, PayPal, and Worldpay each publish their own set under their own license terms. Numbers posted on forums or sold on marketplaces are live or stolen card data. Use of them falls under 18 U.S.C. 1029. There is no legal market for card numbers.