Card Testing Detection Program: Merchant Guide
What a card testing detection program does
A card testing detection program finds small authorization attempts made to check if stolen card numbers work. The program collects data on each attempt, scores it against known test patterns, then blocks or flags the attempt. Three parts do the work: data capture, scoring rules, and an action step.
read more
Test traffic looks different from real buying. A buyer picks an item, enters a shipping address, and pays once. A script sends hundreds of authorizations in minutes with no cart, no address, and no session history.
Top Card Testing Detection Solution for Online CVV Sales
Signals the program reads
- Authorization amount: test charges cluster at $0.00 to $1.00.
- Card velocity: one card number used at 20 merchant accounts in a day.
- IP and device: one fingerprint sends 200 attempts in an hour.
- BIN range: sequential numbers pulled from one bank identification number.
- Email and phone: disposable domains and area codes that do not match the billing state.
- AVS and CVV results: repeated mismatches on postal code and security code.
Rules and thresholds
Build thresholds from your own baseline, not from a vendor default. A common starting set: 3 declines from one IP in 60 minutes, 5 attempts on one card in 24 hours, 10 failed CVV checks from one device in 1 hour, and 25 authorization attempts from one BIN in 10 minutes. Log every attempt before the block. Logs give you the false positive count.
card testing detection platform
Velocity limits and challenge steps
Velocity limits cap attempts per card, per IP, per device, and per BIN. When a limit trips, the program can decline the charge, hold it for manual review, request 3-D Secure, add a CAPTCHA, or add the IP to a block list. A 3-D Secure challenge stops most scripts, because the script cannot pass the issuer step.
more on this topic
Response steps after a test burst
- Block the IP, the device fingerprint, and the card range.
- Void the test authorizations the same day, before the batch settles.
- Pull the order list and cancel orders tied to the same session.
- File a fraud report with your acquirer and the card networks.
- Change the page or endpoint the script hit. Remove any response that confirms a card is valid.
Metrics to track
- Authorization attempts per hour.
- Share of attempts under $1.00.
- Block rate and false positive rate.
- Chargeback count per month, sorted by BIN.
- Time from the first test attempt to the block.
Compliance and reporting notes
PCI DSS requires logging and monitoring of access to cardholder data, which covers authorization logs. Visa and Mastercard both run fraud reporting programs for acquirers. Report test bursts to your acquirer within the window stated in your merchant agreement.
Unknown: no public source states the share of test traffic across all processors. Network reports go to members only, and the numbers move by merchant category.