Carding, from stolen data to cash
Card data is stolen through phishing, malware on shoppers' devices, skimming code injected into checkout pages and data breaches. It is then sold in bulk on underground shops and chat channels, priced by country, issuer and whether it has been checked. Buyers are called carders.
Carders prefer items that are easy to resell and fast to deliver: gift cards, electronics, luxury goods, game currency, travel and digital subscriptions. The goal is to turn a card number into money before the cardholder or the bank notices.
Carding is organized like a supply chain, with separate roles for stealing data, checking it, placing orders and reselling. That is why defenses at a single step leak.
How a carding operation works
- 01
Buy the data
The carder buys card numbers, sometimes with the cardholder's name, address and email, often called fullz when a full identity is included.
- 02
Validate
Unchecked cards are run through card testing on some other merchant's site to find the live ones.
- 03
Disguise the buyer
The carder uses a browser profile and a proxy IP near the cardholder's billing address, so the order looks like it comes from the real owner.
- 04
Place orders
Purchases are made, often through fresh accounts or guest checkout, and shipped to drop addresses, reshippers or delivered as codes.
- 05
Cash out
Goods and gift cards are resold. Weeks later the cardholder disputes the charge and the merchant absorbs a chargeback.
Carding vs card testing vs BIN attack
| Carding | Card testing | BIN attack | |
|---|---|---|---|
| Stage | Spending the cards | Checking stolen cards | Guessing card numbers |
| Order value | Normal to high | Tiny or zero | Tiny or zero |
| Volume per site | Low, careful | High, automated | Very high, automated |
| Main loss | Goods, chargebacks | Fees, declines, disputes | Fees, issuer blocks |
How carding shows up and how to stop it
Carding orders are designed to look normal, so single checks rarely catch them. What gives them away is inconsistency: a device that claims to be one thing but renders like another, an IP address from a residential proxy pool that happens to sit near the billing address, a brand-new account placing a high-value order for resellable goods, and several cards tried by the same actor under different names.
Kavra assesses the checkout request itself: the real device behind the browser, the network it came from and links to other accounts on the same actor, with a clear recommendation to allow, verify or block. Risky orders can be stepped up with 3-D Secure or held for review while real customers pay without friction. See payment fraud prevention for the full approach, and how it applies in e-commerce and retail.