A card testing bot is an automated script that sends large numbers of small payment attempts through an online checkout to find out which stolen card numbers are still valid. The bot reads the authorization response and flags the cards that approve. Merchants see the result as a burst of tiny orders, a sharp rise in declined transactions, and a wave of chargeback fees.
How does a card testing bot work?
Card numbers are loaded into the tool in bulk, often in the hundreds of thousands. The bot submits them to a payment form one after another and records which ones return an approval code. Merchant pages that lack bot defenses are the usual target because a single approval reveals a live card.
Attackers spread the traffic across residential proxies, cloud hosts, and rotating device fingerprints so each individual IP stays under rate limits. Transactions are kept small, usually a few dollars or less, because low amounts rarely trigger manual review. The confirmed numbers are then resold or used for larger purchases elsewhere.
What are the warning signs of a card testing attack?
- A sudden cluster of small-dollar orders, often $1 or less, within minutes.
- Authorization decline rates that jump well above your normal baseline.
- Many card numbers arriving from a narrow set of IP ranges, devices, or email domains.
- Checkout traffic that spikes during off-peak hours or from regions you do not serve.
- Repeated billing details, disposable email addresses, or mismatched address and zip data.
Why is card testing expensive for merchants?
Every declined attempt still carries an authorization cost, and each fraudulent approval can end in a chargeback with a fee attached. Card networks monitor excessive fraud and chargeback ratios and can place a merchant in a monitoring program or raise processing rates. If goods ship before the fraud is caught, the merchant loses both the product and the revenue.
How do you stop card testing bots?
- Rate limit checkout, payment, and account endpoints by IP, device, and card fingerprint.
- Turn on bot challenges or CAPTCHA for payment attempts and high-risk sessions.
- Require CVV and address verification, and block transactions that fail both.
- Set velocity rules on card BINs, email addresses, and order totals.
- Apply 3-D Secure or step-up authentication when a transaction scores as risky.
- Send real-time alerts when decline rates or small-order volume crosses a threshold.
Does card testing harm the cardholder?
The account holder usually sees a series of small pending charges or a card freeze once the issuer detects the pattern. In the United States, federal law limits a cardholder's liability for unauthorized charges, so the direct financial loss falls on the issuer and the merchant. A card that appears in a testing run is a strong signal that the number was exposed in a data breach.
Is card testing illegal?
Yes. Using payment card numbers without authorization violates federal statutes including 18 U.S.C. 1029 and can also support wire fraud and computer fraud charges. Merchants and processors that knowingly pass card testing traffic through their systems carry their own liability.