Glossary

What is carding?

Carding is the use of stolen payment card data to buy goods, gift cards or services that can be resold for cash. It covers the whole chain: stealing or buying card numbers, checking which ones work, then spending them online. The merchant usually ships the order and later loses the money when the real cardholder disputes it.

Carding, from stolen data to cash

Card data is stolen through phishing, malware on shoppers' devices, skimming code injected into checkout pages and data breaches. It is then sold in bulk on underground shops and chat channels, priced by country, issuer and whether it has been checked. Buyers are called carders.

Carders prefer items that are easy to resell and fast to deliver: gift cards, electronics, luxury goods, game currency, travel and digital subscriptions. The goal is to turn a card number into money before the cardholder or the bank notices.

Carding is organized like a supply chain, with separate roles for stealing data, checking it, placing orders and reselling. That is why defenses at a single step leak.

How a carding operation works

  1. 01

    Buy the data

    The carder buys card numbers, sometimes with the cardholder's name, address and email, often called fullz when a full identity is included.

  2. 02

    Validate

    Unchecked cards are run through card testing on some other merchant's site to find the live ones.

  3. 03

    Disguise the buyer

    The carder uses a browser profile and a proxy IP near the cardholder's billing address, so the order looks like it comes from the real owner.

  4. 04

    Place orders

    Purchases are made, often through fresh accounts or guest checkout, and shipped to drop addresses, reshippers or delivered as codes.

  5. 05

    Cash out

    Goods and gift cards are resold. Weeks later the cardholder disputes the charge and the merchant absorbs a chargeback.

Carding vs card testing vs BIN attack

CardingCard testingBIN attack
StageSpending the cardsChecking stolen cardsGuessing card numbers
Order valueNormal to highTiny or zeroTiny or zero
Volume per siteLow, carefulHigh, automatedVery high, automated
Main lossGoods, chargebacksFees, declines, disputesFees, issuer blocks

How carding shows up and how to stop it

Carding orders are designed to look normal, so single checks rarely catch them. What gives them away is inconsistency: a device that claims to be one thing but renders like another, an IP address from a residential proxy pool that happens to sit near the billing address, a brand-new account placing a high-value order for resellable goods, and several cards tried by the same actor under different names.

Kavra assesses the checkout request itself: the real device behind the browser, the network it came from and links to other accounts on the same actor, with a clear recommendation to allow, verify or block. Risky orders can be stepped up with 3-D Secure or held for review while real customers pay without friction. See payment fraud prevention for the full approach, and how it applies in e-commerce and retail.

FAQ

Frequently asked questions

Something else? Talk to our team.

Why do carders buy gift cards with stolen cards?

Gift cards are delivered instantly by email, need no shipping address and can be resold on marketplaces or traded for crypto within minutes. By the time the cardholder disputes the charge, the gift card balance is already spent by someone else. That is why gift card purchases on new accounts deserve extra scrutiny.

How do carders match the cardholder's location?

They route their traffic through a residential or mobile proxy with an IP address in the cardholder's city or region, and set their browser timezone and language to match. Simple checks that compare IP location with billing address then pass. Seeing the proxy for what it is, not only where it appears, closes that gap.

Who pays when a carding order goes through?

For online card-not-present purchases, the merchant usually does. The cardholder disputes the charge, the issuer refunds them, and the amount is taken back from the merchant as a chargeback, plus a fee. The goods are gone. Liability can shift to the issuer when the payment was authenticated with 3-D Secure.

See who is really on your site.

Run Kavra on your own traffic in observe-only mode. No risk to your customers, and a clear report of the fraud it finds.