Glossary

What is card testing?

Card testing is when fraudsters use a merchant's checkout, donation form or card-update page to find out which stolen card numbers are still live. They run many small or zero-value authorizations, usually with bots, keep the cards that pass, and sell or use them later. The merchant is left with fees, declines and disputes.

How card testing works

Stolen card data is sold in bulk, and much of it is dead: cards already cancelled, expired or blocked. A list of checked, working cards is worth far more. So fraudsters need a place to check them, and any page that sends a card to a payment processor will do.

A script submits card after card, often for a tiny amount, a free trial or a card-on-file update that triggers an authorization. Each approval marks a live card. Each decline is discarded. The attack is usually spread across many IP addresses, often residential proxies, and across new guest sessions or throwaway accounts, so no single visitor looks busy.

For the merchant, the signs are a sudden rise in small authorizations, a high decline rate, many different cards from what looks like many different visitors, and later a wave of disputes when cardholders spot charges they never made. Processors may add fees or review the account when decline rates stay high.

Where card testing hits

  • Donation forms and pay-what-you-want pages, where a one dollar charge looks normal.
  • Subscription and free-trial signups that run a card check before the trial starts.
  • Saved-card and billing-update pages behind a login, often reached with throwaway accounts.
  • Payment APIs called directly, skipping the checkout page entirely.

Small online merchants and nonprofits are hit often because their payment volume is low, so a test run stands out to fraudsters as easy and to nobody else until the invoice arrives.

Card testing vs BIN attack vs carding

The three terms overlap and are often used loosely. This is how they differ in practice.

TermWhat the fraudster hasGoal
Card testingFull stolen card numbers, often with expiry and security codeFind out which cards are still live
BIN attackOnly the first digits of a card rangeGuess valid numbers, expiry dates or codes by brute force
CardingCards confirmed as workingSpend them: buy goods, gift cards or services to resell

How to detect and stop card testing

Rules on amount and decline rate help, but attackers tune their traffic to stay under them. The more reliable signal is the visitor itself: an automated browser, a spoofed device, many cards tried from one actor that keeps changing IP address and fingerprint.

Kavra assesses every checkout and card-entry request and tells your backend whether a real person is paying or a script is cycling cards, so you can stop the attempt before it reaches your processor. For the full playbook, with attack steps, warning signs and a prevention checklist, see card testing attack prevention.

FAQ

Frequently asked questions

Something else? Talk to our team.

Why do fraudsters make small charges on stolen cards?

Small charges are less likely to be noticed by the cardholder or flagged by the bank, and they still prove the card works. A one dollar donation or a zero-value card check tells the fraudster the number, expiry and code are valid, so the card can be sold at a higher price or used for a larger purchase elsewhere.

Which websites are targeted by card testing?

Any site with a payment form that responds quickly and does not ask for much else. Donation pages, low-price digital goods, subscription signups with a card check, and card-update pages in account settings are frequent targets, because a single authorization gives the answer without shipping anything.

Does card testing cost the merchant money?

Yes. Each authorization attempt can carry a processor fee, and a flood of declines can raise your risk profile with the processor. When some test charges succeed, cardholders dispute them, which adds chargeback fees and pushes up your dispute ratio. Support and engineering time spent on cleanup adds to the cost.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.