# What is card testing?

Source: https://kavralab.com/glossary/card-testing/

**Card testing** is when fraudsters use a merchant's checkout, donation form or card-update page to find out which stolen card numbers are still live. They run many small or zero-value authorizations, usually with bots, keep the cards that pass, and sell or use them later. The merchant is left with fees, declines and disputes.

## How card testing works

Stolen card data is sold in bulk, and much of it is dead: cards already cancelled, expired or blocked. A list of checked, working cards is worth far more. So fraudsters need a place to check them, and any page that sends a card to a payment processor will do.

A script submits card after card, often for a tiny amount, a free trial or a card-on-file update that triggers an authorization. Each approval marks a live card. Each decline is discarded. The attack is usually spread across many IP addresses, often [residential proxies](https://kavralab.com/detect/residential-proxies/), and across new guest sessions or throwaway accounts, so no single visitor looks busy.

For the merchant, the signs are a sudden rise in small authorizations, a high decline rate, many different cards from what looks like many different visitors, and later a wave of disputes when cardholders spot charges they never made. Processors may add fees or review the account when decline rates stay high.

## Where card testing hits

- Donation forms and pay-what-you-want pages, where a one dollar charge looks normal.
- Subscription and free-trial signups that run a card check before the trial starts.
- Saved-card and billing-update pages behind a login, often reached with throwaway accounts.
- Payment APIs called directly, skipping the checkout page entirely.

Small online merchants and nonprofits are hit often because their payment volume is low, so a test run stands out to fraudsters as easy and to nobody else until the invoice arrives.

## Card testing vs BIN attack vs carding

The three terms overlap and are often used loosely. This is how they differ in practice.

| Term | What the fraudster has | Goal |
|---|---|---|
| Card testing | Full stolen card numbers, often with expiry and security code | Find out which cards are still live |
| [BIN attack](https://kavralab.com/glossary/bin-attack/) | Only the first digits of a card range | Guess valid numbers, expiry dates or codes by brute force |
| [Carding](https://kavralab.com/glossary/carding/) | Cards confirmed as working | Spend them: buy goods, gift cards or services to resell |

## How to detect and stop card testing

Rules on amount and decline rate help, but attackers tune their traffic to stay under them. The more reliable signal is the visitor itself: an automated browser, a spoofed device, many cards tried from one actor that keeps changing IP address and fingerprint.

Kavra assesses every checkout and card-entry request and tells your backend whether a real person is paying or a script is cycling cards, so you can stop the attempt before it reaches your processor. For the full playbook, with attack steps, warning signs and a prevention checklist, see [card testing attack prevention](https://kavralab.com/solutions/card-testing/).

## FAQ

### Why do fraudsters make small charges on stolen cards?

Small charges are less likely to be noticed by the cardholder or flagged by the bank, and they still prove the card works. A one dollar donation or a zero-value card check tells the fraudster the number, expiry and code are valid, so the card can be sold at a higher price or used for a larger purchase elsewhere.

### Which websites are targeted by card testing?

Any site with a payment form that responds quickly and does not ask for much else. Donation pages, low-price digital goods, subscription signups with a card check, and card-update pages in account settings are frequent targets, because a single authorization gives the answer without shipping anything.

### Does card testing cost the merchant money?

Yes. Each authorization attempt can carry a processor fee, and a flood of declines can raise your risk profile with the processor. When some test charges succeed, cardholders dispute them, which adds chargeback fees and pushes up your dispute ratio. Support and engineering time spent on cleanup adds to the cost.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
