Card testing is the use of small transactions to check whether stolen card numbers work. The goal is not the merchandise. The goal is an approval. Numbers that approve get used for larger purchases or sold to another buyer. Merchants, card networks, and issuers treat the activity as fraud.

credit card testing scheme

This guide covers how the pattern appears in transaction data and which controls stop it. It does not cover how to get or test stolen numbers.

read more

What the transaction pattern looks like

A card testing run shows up as volume, not as size. One merchant can receive hundreds of authorization attempts in minutes. Common markers:

more on this topic

  • Many attempts from one IP address, device fingerprint, or email domain.
  • Card numbers that run in sequence inside one bank identification number (BIN).
  • Ticket sizes under a few dollars, repeated in a loop.
  • Decline rates above 50% on a single checkout session.
  • Billing addresses that match and shipping addresses that change.
  • Attempts spaced seconds apart, at hours when the merchant's normal traffic is low.

Why attackers pick small merchants

Large retailers run velocity checks and machine scoring on every order. Small merchants often run none. Attackers also favor stores that deliver digital goods, because delivery is instant and no address check applies. A store with a weak checkout can be used to validate thousands of numbers in one night.

Request declined

Detection signals fraud teams track

  • Authorization attempt rate per IP, per card BIN, and per device.
  • Ratio of declines to approvals on one session.
  • Number of distinct cards used against one customer account.
  • Time between card entry and submit.
  • Repeat use of a payment page with no cart or shipping step.

Controls that reduce loss

  1. Rate limit the payment endpoint by IP, device, and card BIN.
  2. Add CAPTCHA or a bot check after a set number of failures.
  3. Require CVV and AVS checks on first orders, and block on mismatch.
  4. Set velocity rules: cards per IP per hour, orders per card per day, orders per device per week.
  5. Route high-risk orders to manual review before capture.
  6. Hold orders from countries where the merchant does not ship.
  7. Log every authorization attempt with IP, timestamp, BIN, and outcome. Card testing is often found in logs after the chargebacks arrive.

Cost when testing succeeds

Each fraudulent approval carries a chargeback, a fee, and the cost of the goods. High chargeback ratios can push a merchant into a monitoring program. Some processors add reserves or close the account. Fees per chargeback run from $15 to $100 depending on the processor and the card network.

What cardholders can do

A charge of a few cents or a few dollars from an unknown merchant is a signal. Report it to the issuer, request a new card number, and check the account for follow-up charges. The major card networks and the American Bankers Association publish contact routes for this.