What is card testing in a payment gateway?
Card testing is the practice of pushing small, low-value transactions through a payment gateway to learn whether stolen or guessed card numbers are active. The gateway authorizes, declines, or flags each attempt, which makes it the first line of defense. Legitimate businesses test checkout flows with sandbox test cards, never with live card numbers.
Attackers typically target donation pages, free trials, or guest checkout because those flows do not require a stored account. A single gateway can receive thousands of low-value attempts in minutes. Each approved attempt confirms a working card and can trigger chargebacks later.
How do payment gateways detect card testing?
Gateways combine rule-based filters with machine-learning risk models to separate normal shopper behavior from automated probing. No single signal proves fraud, so detection depends on patterns across many transactions.
Velocity and BIN checks
Velocity rules count how many authorization attempts come from one IP address, device, card BIN, or email in a short window. A spike in $0.50 to $2.00 charges from one IP is a classic card-testing fingerprint. BIN-level monitoring also catches sequential card numbers issued from the same bank.
CVV, AVS, and 3-D Secure
Requiring the CVV and matching the billing address through AVS raises the cost of testing because attackers rarely have both. 3-D Secure adds an issuer authentication step that stops most automated attempts before authorization. Gateways can also force a challenge when the risk score crosses a threshold.
Machine learning risk scores
Risk engines score each transaction using device fingerprints, proxy detection, email age, and historical fraud linked to the card or IP. Consistent declines followed by new card numbers in the same session push the score higher. Merchants see these scores in the gateway dashboard and can block or review them.
What are test card numbers and how are they used?
Test card numbers are published by gateway providers for sandbox mode and they never touch a real bank network. Developers use them to confirm that an integration handles approvals, declines, and error codes correctly. Common test values include 4242 4242 4242 4242 for a successful Visa charge and 4000 0000 0000 0002 for a generic decline.
Sandbox cards only work with an API key or test mode toggle, so they cannot be used on a live storefront. Using live cards in a sandbox is a violation of most gateway terms and can lead to account termination. Real card numbers should never appear in test scripts, logs, or screenshots.
How do merchants reduce card testing attacks?
Layered controls cut down successful card testing without blocking real customers. Most gateways let merchants enable these settings without writing custom code.
- Enable CVV and AVS checks as required fields for every transaction.
- Turn on 3-D Secure for high-risk regions, guest checkout, and new devices.
- Set velocity limits per IP, card, and email, such as a maximum of three attempts per hour.
- Use CAPTCHA or a bot filter on donation and free-trial forms.
- Block known proxy and data-center IP ranges at the gateway or CDN level.
- Monitor decline-to-approval ratios and alert on sudden spikes in small charges.
When an attack succeeds, the merchant pays interchange fees, chargeback fees, and possible monitoring program fines. Fast detection limits the damage and preserves the merchant account.
FAQ
Does card testing hurt the cardholder?
Yes. Cardholders may see temporary holds, fraud alerts, or unauthorized charges that require a replacement card. Issuers often close the compromised card number after a burst of small test charges.
Can a payment gateway stop all card testing?
No gateway stops every attempt, but risk rules and 3-D Secure reduce successful tests to a small fraction. Merchants should treat card testing as an ongoing operational risk, not a one-time fix.
Is using a test card number illegal?
No. Test card numbers are designed for sandbox environments and cannot be charged. Using real card numbers without authorization is illegal and violates card network rules.
What is the difference between a test card and a real card?
A test card routes through a simulated authorization system and produces a fixed result. A real card routes through the issuer, affects a real credit line, and can generate a chargeback.