Card Testing Procedure: How It Works and How Merchants Stop It

Card testing is a fraud tactic where criminals run small charges on stolen card numbers to see which ones still work. The procedure uses bots or scripts to submit many card numbers to a payment page in a short time. Valid cards get flagged for later use, while declined cards are discarded.

card test patterns

What is card testing?

Card testing (also called card checking or carding) is the step between stealing card data and using it. Criminals buy lists of card numbers from data breaches or dark web markets. They do not know which numbers are active. Card testing tells them which ones are.

read more

A single test charge is often small, like $1 or a donation amount. The goal is not the money. The goal is the approval or decline response from the payment processor.

related article

How does the card testing procedure work?

The procedure follows a simple loop. A script takes a list of card numbers. It sends each one to a merchant's checkout page. The script records which cards get an approval code and which get declined.

credit card testing patterns

Tests often target small merchants with weak fraud controls. Donation pages, free trials, and guest checkout forms are common targets. These forms let a criminal test many cards without creating an account.

The whole process can run for hours or days. Bots rotate IP addresses and user agents to avoid simple blocks.

Signs of card testing on your site

Watch for these patterns in your payment logs:

These signs do not prove an attack. But they raise the odds that your site is being tested.

How merchants prevent card testing

Prevention focuses on making the test loop slow and costly for the attacker. No single fix stops all card testing. Layers of controls work better than one tool.

Rate limiting and CAPTCHA

Rate limits cap how many payment attempts one IP address or session can make. A limit of 5 attempts per hour blocks most scripts. CAPTCHA on checkout forms stops basic bots but not advanced ones.

Address verification and CVV checks

Require the CVV and billing address for every transaction. These checks do not stop all tests, but they raise the failure rate. Attackers often lack the full cardholder data.

Fraud rules and machine learning

Payment processors and fraud tools score each transaction. They look at velocity, device fingerprints, and geolocation. A score above a set threshold triggers a manual review or block.

Some merchants use a test charge detector. It flags any transaction under a set amount from a new customer. That flag can hold the order for review.

What to do if your site is hit

If you see card testing signs, act fast. The longer the test runs, the more fees you pay in chargebacks and processor penalties.

  1. Block the IP addresses or IP ranges involved.
  2. Turn on CAPTCHA for all checkout attempts.
  3. Lower your velocity limits for a few days.
  4. Contact your payment processor and report the attack.
  5. Review your refund policy for test charges.

Processors may charge a fee for each declined test. Too many declines can put your merchant account at risk.

Why card testing matters for merchants

Card testing costs merchants in three ways. First, you pay transaction fees on each test, even declined ones. Second, chargebacks from valid cards used later hit your account. Third, high fraud rates can lead to account termination.

Stopping card testing protects your revenue and your ability to accept cards.

How to detect card testing early

Set up alerts for unusual payment activity. Look for a sudden rise in declined transactions or a drop in average order value. Both can signal a test attack.

Review your logs for repeated card numbers across different orders. A single card used many times in one hour is a red flag.

Use a fraud dashboard that shows real-time data. Many payment processors offer this tool for free.

Common targets for card testing

Criminals pick targets with weak payment controls. Small online stores and nonprofits are frequent victims. These sites often lack fraud tools and have low transaction volumes, so a test attack stands out less.

Subscription services and digital goods are also common targets. The attacker can test a card and get an instant delivery of a product or service. That makes the test more valuable.

The role of payment processors

Payment processors see card testing across many merchants. They use network-level data to spot patterns. When they detect an attack, they may block the IP or flag the merchant account.

Some processors offer fraud prevention tools as part of their service. Stripe Radar, for example, uses machine learning to block card testing attempts.

FAQ

Is card testing illegal?

Yes. Card testing uses stolen card data without permission. It violates laws like the Computer Fraud and Abuse Act in the US and similar laws in other countries.

Can card testing hurt my SEO?

Card testing does not directly change your search rankings. But it can slow your site and raise bounce rates. Both can hurt user experience signals.

How long does a card testing attack last?

Most attacks last from a few hours to a few days. Some bots keep testing until they are blocked or the card list is used up.

Do I need a fraud tool to stop card testing?

Not always. Basic rate limits and CAPTCHA block many attacks. A fraud tool adds a layer for advanced bots and high-volume attacks.

More

Read our complete guide: Buy CVV Cheap: Pricing, Risks, and What First-Time Buyers Need to Know