Card validation attack v6: the short answer
A card validation attack is a card testing attack. An attacker submits many card numbers to a live payment page to learn which numbers authorize. The "v6" tag is a version label used in fraud forums for one generation of checker software. No vendor sells it, and no public specification exists. The label changes. The method does not. An attacker needs a way to test stolen numbers at scale, and a small charge on a real merchant account is the cheap test.
How the tests work
The attacker holds a list of card numbers, called a base or a dump. Each entry has a primary account number, an expiration date, and sometimes a card verification value. The attacker sends each entry through a real payment gateway with a low dollar amount. A response of "approved" or "insufficient funds" marks the number as live. A response of "invalid card" marks it as dead. The attacker keeps the live entries and drops the rest.
The merchant sees a burst of orders from a small set of IP addresses, devices, or email domains. The orders share a shape: low amounts, one item, no shipping preference, and a high decline rate.
Card Validation Attack V8 Buying Guide
Signals that separate a test from a real sale
- Authorization attempts per minute from one IP address or device fingerprint.
- Many card numbers attached to one customer record, or many records on one card.
- Card numbers that run in sequence or increment by one.
- Billing address and IP country mismatch rates above the merchant baseline.
- Decline rate above 30 percent on a single checkout endpoint.
- Traffic to the payment endpoint with no traffic to product pages or cart pages.
Cost to the merchant
Each attempt carries an authorization fee, even when the charge is declined. Networks also charge for excessive declines and for chargebacks on approved test charges. A completed run gives the attacker a verified list, and a verified list sells for more than an unverified one. Merchants pay the fees, the dispute costs, and the staff time.
Controls that cut the volume
Rate limits on the payment endpoint and the account creation endpoint remove the easy path. CAPTCHA on checkout, device fingerprinting, and 3-D Secure shift liability and break most automated runs. Velocity rules keyed to card, IP, email, and device catch the pattern. Blocking authorization traffic from hosting providers and known proxy ranges removes a large share of sources. Declines per endpoint, tracked hour by hour, give the first warning.
Legal position in the US
18 U.S.C. Section 1029 covers access device fraud. That statute reaches possession of card numbers with intent to defraud, and it reaches the sale of card numbers. A card testing run also supports wire fraud and identity theft charges. Anyone who runs a checker, sells one, or buys verified card data falls inside that scope. Sites that advertise CVV sales are a known source of stolen data, malware, and advance fee loss.
What is not known
There is no public record of who wrote the "v6" checker, when it appeared, or how many copies exist. Claims about its accuracy come from sellers and cannot be checked.