Card Testing

Card testing is fraudsters validating stolen cards on your checkout in small bursts, at your cost.

What card testing is

Card testing is fraudsters validating stolen card numbers on your checkout: small or zero-value transactions fired in bursts, often by bots, to learn which cards in a stolen batch still work before spending them elsewhere.

Why card testing matters

The store is the test lab and pays for the privilege: authorization fees on every attempt, dispute costs on the successes, and a decline-rate spike that can flag the merchant account itself as risky. The fraudster’s real purchase usually happens at someone else’s store, on your validated card.

Card testing signatures

  • Bursts of small orders or failed authorizations in minutes
  • One product, many cards; or many tiny custom amounts
  • Sequential card numbers and rotating identities
  • Donation, gift card, and low-price items as favorite targets

Frequently asked questions

How do stores stop card testing?

Friction where bots operate: bot defense on checkout, velocity limits per card, IP, and device, address and CVC verification enforced, and risk rules on the tiny-order patterns. Gateways offer card-testing protections worth switching on before the wave, not after.

What’s the damage if it goes unnoticed?

Fee bleed, chargebacks on the hits, and a processor reading your soaring decline rate as merchant risk: some stores discover card testing through a warning letter rather than the dashboard.

Related terms

Fraud Detection · Payment Gateway · Chargeback · Triangulation Fraud