If you accept cards online, the fastest way to confirm card testing is to watch authorization volume and decline rates by source rather than waiting for customer complaints. A card testing run looks like a short burst of low-value authorization attempts, most of them failing, arriving from a narrow set of IP addresses, device fingerprints, or email domains. Treat that pattern as the trigger for immediate rate limiting, rule changes, and manual review, because the chargebacks from a successful run arrive three to six weeks later, after the stolen numbers have been resold.
What Card Testing Actually Is
Card testing is the automated probing of stolen card numbers to find which ones are still live. The attacker needs a fast yes or no from your gateway, so they pick merchants with loose velocity controls and cheap or zero-value transactions. Every approval confirms a working card. Every decline tells the attacker to discard that number and move on. The merchant absorbs the cost: gateway fees on failed attempts, fraud dispute fees, higher processing rates, and in severe cases termination by the acquirer.
Indicators Worth Monitoring
- Authorization attempts per IP per hour that exceed your normal ceiling by an order of magnitude.
- Approval rates that collapse during a short window while overall traffic looks ordinary.
- Ticket sizes clustered at the smallest amount your store allows, or repeated identical amounts.
- Many different card numbers attempted from one session, device, or email address.
- Checkout completion times that suggest scripted entry rather than human typing.
- Concentrated decline codes such as do not honor, invalid card number, or CVV mismatch.
- Billing addresses that pass format checks but fail AVS, or ZIP codes reused across unrelated names.
- New accounts created minutes before the first purchase attempt.
- Disposable email domains and free proxy or hosting-provider IP ranges in your order log.
Parameter Bands to Set
Exact numbers depend on your traffic, but these bands are a reasonable starting point for a small to mid-size store. A healthy IP sees fewer than five authorization attempts per hour. Twenty to fifty attempts per hour from one address deserves a challenge. Over one hundred is an active attack and should be blocked at the edge. Approval rate during a burst often falls to somewhere between five and thirty percent, against a baseline of roughly eighty-five to ninety-five percent. Watch for a spike in attempts against a single card BIN range, which suggests a batch of numbers from the same issuer leak. Any order with three or more failed attempts on different cards from the same fingerprint should route to manual review instead of auto-approval.
Common Pitfalls
The first mistake is relying on AVS alone. Testers often have accurate billing data from the same breach that produced the card numbers, so address checks pass while the card is already burned. The second is blocking every decline, which punishes legitimate customers with expired cards and drives good revenue away. The third is ignoring small-ticket attempts because the dollar amount looks harmless; a one-dollar probe that succeeds is the reconnaissance for a much larger fraud order. The fourth is reviewing only completed orders and never looking at the authorization log, where the testing traffic actually lives. The fifth is failing to feed confirmed testing patterns back into your rules, which means the same attacker returns next month with a slightly different setup.
FAQ
How quickly should I react to a suspected run?
Within the same business day. Attacks often last only minutes because the attacker moves on once approvals dry up, so a delayed response means you learn about it from dispute notices instead of your dashboard.
Does 3D Secure stop card testing?
It helps. Authentication challenges raise the cost per attempt and cut approval rates for stolen numbers, but testers will still try cards that are not enrolled, so keep velocity rules active.
What should I document?
Keep timestamps, IP addresses, device identifiers, decline codes, and the rule changes you made. Acquirers ask for this evidence when they evaluate whether you handled the incident responsibly.
Is a zero-dollar authorization a real risk?
Yes. Zero and one-dollar authorizations are the cheapest way to validate a card, and they carry the same dispute exposure once the attacker uses the confirmed number elsewhere or on your store.