Guides
Last updated
July 24, 2026

Card Testing Fraud: How It Works and How to Stop It

Nicolas Rios
Nicolas Rios

Table of Contents:

Get your free
IP Geolocation
 API key now
stars rating
4.8 from 1,863 votes
See why the best developers build on Abstract
START FOR FREE
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
No credit card required

Overnight, your payment logs fill with hundreds of one-dollar authorizations from emails you have never seen, most declined, a few approved. Nobody bought anything real. Your checkout was just used as a testing rig for stolen card numbers, and the fees are yours. This guide covers how card testing fraud works, the pattern it leaves, and the defenses that stop it without hurting real customers.

What is card testing fraud?

Card testing fraud is the use of a merchant's checkout to find out which stolen card numbers are still live. Criminals buy card data in bulk, then run small, automated authorizations, donations, digital goods, one-dollar orders, against a real payment form. Approved numbers get resold or used for real purchases elsewhere; you keep the authorization fees and the flood of declines.

Related names: card cracking (guessing missing CVV or expiry values by brute force) and BIN attacks (testing generated numbers across one bank identification range). The mechanics and the defenses are the same.

What a card testing attack looks like

The pattern is loud once you know it: a burst of low-value authorizations in minutes, a decline rate far above your baseline, sequential or same-BIN card numbers, throwaway email addresses, and traffic from datacenter or VPN IPs rather than the residential networks real buyers use. Attacks favor endpoints without friction: donation forms, gift cards, one-click digital goods.

Enter an IP address to start
Need inspiration? Try
73.162.0.1
LOCATE
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Checking
5
Results for
ip address
Country:
TEST
Region:
TEST
City:
TEST
Coordinates:
TEST
Zip code:
TEST
Connection:
TEST
Get free credits, more data, and faster results

Why card testing hurts even when every charge is small

Three costs stack. Fees: every authorization attempt, approved or declined, costs you money at the processor. Standing: a decline rate spike marks your account at the acquirer, and testers who succeed leave charges that mature into chargebacks on your ratio. And infrastructure: a heavy attack is effectively load testing you never asked for. Processors can and do suspend merchants who stay easy to test on.

How to stop card testing

Defense means making automation expensive at the point where it is still cheap for you.

  • Screen the network first. Card testing runs from infrastructure, not living rooms. Check every checkout attempt's IP for datacenter, VPN, proxy, and Tor flags and block or challenge before the authorization is attempted; each request you stop is a fee you do not pay. The free proxy detector classifies any single IP, and Abstract's IP Intelligence API returns the same flags in one request per attempt; that screen also runs in the payment fraud detection solution.
  • Rate-limit by IP, device, and card BIN. No real customer tries eight cards in five minutes.
  • Require CVV and AVS, and reject mismatches. Testers often hold numbers without the rest.
  • Add friction only under attack: a challenge on the payment form when velocity spikes keeps normal checkout clean.
  • Validate identifiers: disposable email domains on payment attempts are a near-free signal; test one in the free disposable email checker.

These same signals, weighted together, are the score described in fraud risk scoring; card testing is the clearest case where the block band earns its keep. For where this attack sits in the wider landscape, see the payment fraud guide.

Frequently Asked Questions

What is card testing fraud?

The use of a merchant's payment form to validate stolen card numbers through small automated authorizations. Working numbers are then used or resold; the merchant absorbs the fees and the decline spike.

Why do fraudsters make small charges first?

A one-dollar authorization confirms a stolen number is live without attracting the cardholder's attention. Once validated, the card is used for larger purchases elsewhere or sold at a premium as "checked" stock.

How do I know if my site is being used for card testing?

Watch for bursts of low-value authorizations, decline rates far above your normal, many cards sharing a BIN, throwaway emails, and checkout traffic from datacenter or VPN IPs. Processor alerts often arrive after the fees are already yours.

Does card testing cost money if the charges are declined?

Yes. Most processors charge per authorization attempt regardless of outcome, and a thousand-attempt attack means a thousand fees plus a decline-rate spike your acquirer notices.

What is a BIN attack?

A card testing variant where attackers generate candidate numbers within one bank identification number range and test them in bulk, hunting for valid combinations rather than working from a stolen list.

Can rate limiting alone stop card testing?

It blunts single-IP attacks but not distributed ones that rotate through proxy networks. Pair velocity limits with network screening, datacenter, VPN, and proxy detection, so rotating infrastructure stays visible.

Nicolas Rios
Nicolas Rios

CEO at Abstract API

Get your free
IP Geolocation
key now
See why the best developers build on Abstract
get started for free

Related Articles

Get your free
IP Geolocation
key now
stars rating
4.8 from 1,863 votes
See why the best developers build on Abstract
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
No credit card required