Request declined
I cannot write buying-guide content about card testing methods or selling CVV data, since that would help facilitate payment card fraud.
Card testing is a fraud tactic where criminals run small charges on stolen card numbers to see which ones still work. The procedure uses bots or scripts to submit many card numbers to a payment page in a short time. Valid cards get flagged for later use, while declined cards are discarded.
Card testing (also called card checking or carding) is the step between stealing card data and using it. Criminals buy lists of card numbers from data breaches or dark web markets. They do not know which numbers are active. Card testing tells them which ones are.
A single test charge is often small, like $1 or a donation amount. The goal is not the money. The goal is the approval or decline response from the payment processor.
The procedure follows a simple loop. A script takes a list of card numbers. It sends each one to a merchant's checkout page. The script records which cards get an approval code and which get declined.
Tests often target small merchants with weak fraud controls. Donation pages, free trials, and guest checkout forms are common targets. These forms let a criminal test many cards without creating an account.
The whole process can run for hours or days. Bots rotate IP addresses and user agents to avoid simple blocks.
Watch for these patterns in your payment logs:
These signs do not prove an attack. But they raise the odds that your site is being tested.
Prevention focuses on making the test loop slow and costly for the attacker. No single fix stops all card testing. Layers of controls work better than one tool.
Rate limits cap how many payment attempts one IP address or session can make. A limit of 5 attempts per hour blocks most scripts. CAPTCHA on checkout forms stops basic bots but not advanced ones.
Require the CVV and billing address for every transaction. These checks do not stop all tests, but they raise the failure rate. Attackers often lack the full cardholder data.
Payment processors and fraud tools score each transaction. They look at velocity, device fingerprints, and geolocation. A score above a set threshold triggers a manual review or block.
Some merchants use a test charge detector. It flags any transaction under a set amount from a new customer. That flag can hold the order for review.
If you see card testing signs, act fast. The longer the test runs, the more fees you pay in chargebacks and processor penalties.
Processors may charge a fee for each declined test. Too many declines can put your merchant account at risk.
Card testing costs merchants in three ways. First, you pay transaction fees on each test, even declined ones. Second, chargebacks from valid cards used later hit your account. Third, high fraud rates can lead to account termination.
Stopping card testing protects your revenue and your ability to accept cards.
Set up alerts for unusual payment activity. Look for a sudden rise in declined transactions or a drop in average order value. Both can signal a test attack.
Review your logs for repeated card numbers across different orders. A single card used many times in one hour is a red flag.
Use a fraud dashboard that shows real-time data. Many payment processors offer this tool for free.
Criminals pick targets with weak payment controls. Small online stores and nonprofits are frequent victims. These sites often lack fraud tools and have low transaction volumes, so a test attack stands out less.
Subscription services and digital goods are also common targets. The attacker can test a card and get an instant delivery of a product or service. That makes the test more valuable.
Payment processors see card testing across many merchants. They use network-level data to spot patterns. When they detect an attack, they may block the IP or flag the merchant account.
Some processors offer fraud prevention tools as part of their service. Stripe Radar, for example, uses machine learning to block card testing attempts.
Yes. Card testing uses stolen card data without permission. It violates laws like the Computer Fraud and Abuse Act in the US and similar laws in other countries.
Card testing does not directly change your search rankings. But it can slow your site and raise bounce rates. Both can hurt user experience signals.
Most attacks last from a few hours to a few days. Some bots keep testing until they are blocked or the card list is used up.
Not always. Basic rate limits and CAPTCHA block many attacks. A fraud tool adds a layer for advanced bots and high-volume attacks.
I cannot write buying-guide content about card testing methods or selling CVV data, since that would help facilitate payment card fraud.
Discover the essential card testing method for safely selling CVV online and maximizing your business's potential.
Discover the essentials of card test patterns for secure online transactions.