# What is carding?

Source: https://kavralab.com/glossary/carding/

**Carding** is the use of stolen payment card data to buy goods, gift cards or services that can be resold for cash. It covers the whole chain: stealing or buying card numbers, checking which ones work, then spending them online. The merchant usually ships the order and later loses the money when the real cardholder disputes it.

## Carding, from stolen data to cash

Card data is stolen through phishing, malware on shoppers' devices, skimming code injected into checkout pages and data breaches. It is then sold in bulk on underground shops and chat channels, priced by country, issuer and whether it has been checked. Buyers are called carders.

Carders prefer items that are easy to resell and fast to deliver: gift cards, electronics, luxury goods, game currency, travel and digital subscriptions. The goal is to turn a card number into money before the cardholder or the bank notices.

Carding is organized like a supply chain, with separate roles for stealing data, checking it, placing orders and reselling. That is why defenses at a single step leak.

## How a carding operation works

1. **Buy the data**: The carder buys card numbers, sometimes with the cardholder's name, address and email, often called fullz when a full identity is included.
2. **Validate**: Unchecked cards are run through [card testing](https://kavralab.com/glossary/card-testing/) on some other merchant's site to find the live ones.
3. **Disguise the buyer**: The carder uses a browser profile and a proxy IP near the cardholder's billing address, so the order looks like it comes from the real owner.
4. **Place orders**: Purchases are made, often through fresh accounts or guest checkout, and shipped to drop addresses, reshippers or delivered as codes.
5. **Cash out**: Goods and gift cards are resold. Weeks later the cardholder disputes the charge and the merchant absorbs a chargeback.

## Carding vs card testing vs BIN attack

|  | Carding | Card testing | BIN attack |
|---|---|---|---|
| Stage | Spending the cards | Checking stolen cards | Guessing card numbers |
| Order value | Normal to high | Tiny or zero | Tiny or zero |
| Volume per site | Low, careful | High, automated | Very high, automated |
| Main loss | Goods, chargebacks | Fees, declines, disputes | Fees, issuer blocks |

## How carding shows up and how to stop it

Carding orders are designed to look normal, so single checks rarely catch them. What gives them away is inconsistency: a device that claims to be one thing but renders like another, an IP address from a [residential proxy](https://kavralab.com/detect/residential-proxies/) pool that happens to sit near the billing address, a brand-new account placing a high-value order for resellable goods, and several cards tried by the same actor under different names.

Kavra assesses the checkout request itself: the real device behind the browser, the network it came from and links to other accounts on the same actor, with a clear recommendation to allow, verify or block. Risky orders can be stepped up with 3-D Secure or held for review while real customers pay without friction. See [payment fraud prevention](https://kavralab.com/solutions/payment-fraud/) for the full approach, and how it applies in [e-commerce and retail](https://kavralab.com/industries/ecommerce/).

## FAQ

### Why do carders buy gift cards with stolen cards?

Gift cards are delivered instantly by email, need no shipping address and can be resold on marketplaces or traded for crypto within minutes. By the time the cardholder disputes the charge, the gift card balance is already spent by someone else. That is why gift card purchases on new accounts deserve extra scrutiny.

### How do carders match the cardholder's location?

They route their traffic through a residential or mobile proxy with an IP address in the cardholder's city or region, and set their browser timezone and language to match. Simple checks that compare IP location with billing address then pass. Seeing the proxy for what it is, not only where it appears, closes that gap.

### Who pays when a carding order goes through?

For online card-not-present purchases, the merchant usually does. The cardholder disputes the charge, the issuer refunds them, and the amount is taken back from the merchant as a chargeback, plus a fee. The goods are gone. Liability can shift to the issuer when the payment was authenticated with 3-D Secure.

---
Kavra Lab: bot and fraud detection that explains every decision. Book a demo: https://kavralab.com/contact/
