Card testing fraud is the practice of running stolen card numbers through a merchant's payment page in small batches to learn which ones still work. The fraudster keeps the live numbers and drops the dead ones. The merchant picks up the fees, the chargebacks, and often a penalty from its payment processor.
The attack costs almost nothing to run and hides behind normal-looking orders. A single $1 charge looks harmless. Two hundred of them in twenty minutes do not.
How does card testing work?
Attackers work from lists of card numbers pulled from data breaches, skimmers, or resale markets. What they need from a merchant site is one bit of information: an approval or a decline from the bank.
An approval confirms the card is open. A decline means the number is dead, frozen, or blocked. Each attempt costs cents, so a list of 5,000 numbers can be filtered down to a few hundred live cards.
Small purchase testing
The common pattern uses a real product with a tiny price, such as a $1 sample or a digital download. Attackers place many orders in a short window, sometimes with the same address and sometimes with none. A high order count and a very low average value is the signature.
Donation, signup, and card-on-file pages
Checkout forms that skip CVV or address checks are the easiest targets. Donation widgets and free trial signups often skip both. Stored-card update pages matter too, since a saved valid card lets an attacker buy later without tripping the same alarms.
Why card testing hurts merchants
Every approved test charge is a real authorization. The merchant pays the processing fee, then loses the money when the true cardholder disputes the order.
Dispute volume does more damage than dispute value. Ten $1 chargebacks can push a small merchant past the thresholds that card networks watch.
- Chargeback fees on each disputed test order
- Processing costs on charges that get reversed
- Monitoring program fines when the dispute ratio climbs
- Higher reserve requirements or account termination from the processor
- Lost sales from good customers once fraud rules get strict
What are the warning signs of card testing?
Card testing shows up in patterns, not single orders. Watch the transaction log rather than the individual sale.
- A burst of low-value orders, often $1 or less, in a short window
- Many different card numbers from one IP address or device
- A high share of declines sitting next to a few approvals
- Billing addresses and card BINs from regions you do not serve
- Disposable email domains and guest checkout with no account
- Order timestamps clustered outside your normal business hours
How do you stop card testing?
- Turn on CVV and address verification for every transaction.
- Rate limit by IP address, device fingerprint, and card number.
- Add a challenge such as CAPTCHA to guest checkout and signup forms.
- Block disposable email domains and known proxy or VPN ranges.
- Require 3D Secure for high-risk orders and high-risk regions.
- Set velocity rules: one card, email, or IP gets a fixed number of attempts per hour.
- Review decline logs each week. A spike in declines points to an active attack.
No single control stops the attack. Rate limits slow it, verification makes each attempt costlier, and monitoring tells you when it starts. Speed matters, since a test run can finish in under an hour.
What should cardholders do?
If a small charge you do not recognize shows up, call the number on the back of your card. The issuer can freeze the account, reverse the charge, and send a new card number.
Check statements for charges under $2, since test charges stay small on purpose. Report the charge to the FTC as well if the card was opened in your name without your knowledge.
Frequently asked questions
Is card testing illegal?
Yes. In the US, using a card number that belongs to someone else is access device fraud under 18 U.S.C. 1029, alongside state identity theft laws. Convictions carry fines and prison time, and card networks ban the accounts involved.
Does one small charge mean my card was stolen?
Not always. Some merchants run a $0 or $1 authorization to confirm a card is open before a subscription starts, and the hold drops off. The charge is a problem when larger charges follow it or you do not recognize the merchant name.
How long does a card testing attack last?
Most runs last minutes to a few hours, because the goal is to filter a list before the merchant notices. Some attackers return in waves over several days. Blocking the first wave matters more than writing perfect long-term rules.
Which businesses get hit most?
Any site that takes card payments without strong verification. Nonprofits, donation platforms, digital goods stores, and marketplaces with instant signup are common targets. A merchant with 3D Secure and rate limiting sees far fewer attempts.
Can a fraud tool tell a real card from a stolen one?
No. The only signal is the bank's response to an authorization request. That is why every test attempt lands on a merchant's payment page and shows up in that merchant's logs.