Card Testing Fraud

Card Testing Fraud

Card testing fraud, also known as carding (card networks call it enumeration), is a scheme where bad actors validate stolen credit card numbers by running small, low-risk transactions before attempting larger fraudulent purchases. A test charge that clears tells the fraudster the card is live, and the merchant who processed it becomes the proving ground for the fraud that follows.

How Card Testing Fraud Works

Fraudsters want to acquire as many stolen credit cards as possible to validate and assess their viability for fraudulent transactions. Here’s how a credit card testing scheme typically works.

  1. Acquisition of stolen credit card data. Cybercriminals obtain credit card information through various means, including:
    • Data breaches: Hackers breach the security of organizations and steal databases of credit card data.
    • Phishing: Fraudsters trick individuals into revealing their credit card details through deceptive emails or websites.
    • Card skimming: Criminals use skimming devices to capture card information from physical card readers, such as ATMs or point-of-sale terminals.
    • Dark web purchases: Criminals can purchase stolen credit card data from underground markets on the dark web.
  2. Compilation of card data. Once the criminals have collected significant credit card data, they compile it into a list or database. This data may include credit card numbers, expiration dates, cardholder names, and CVV (Card Verification Value) codes.
  3. Test transactions. To determine whether the stolen credit card data is valid and whether the cardholders or financial institutions are likely to detect unauthorized transactions, cybercriminals initiate small, low-risk transactions or “test” purchases. These test transactions typically involve:
    • Online purchases: Criminals use the stolen card details to make small online purchases, such as digital goods, gift cards, or low-value items.
    • Subscription services: They may sign up for subscription services, where the initial transaction is minimal.
    • Donations: Criminals may make small donations to charities or crowdfunding campaigns.
  4. Monitoring for flags or detection. After conducting test transactions, the fraudsters closely monitor the credit card accounts to see if any of the following events occur:
    • Immediate account block: The test fails if the financial institution or cardholder detects the unauthorized transaction and blocks the card.
    • Flags for suspicious activity: Multiple small transactions or unusual purchase patterns may trigger fraud detection systems or alerts, leading to further investigation.
    • No detection: If the test transactions go unnoticed, the cybercriminals gain confidence that the stolen card data is valid, usable, and valuable.
  5. Monetization of validated data. Once they have successfully validated the stolen card data through testing, cybercriminals can:
    • Sell the validated credit card information on the dark web, where other criminals can purchase it.
    • Use the stolen data for more significant fraudulent transactions, such as purchasing high-value items, using the card to commit subscription fraud, making cash withdrawals, and other illegal activities.

Impact on Commerce Brands

Credit card fraud is a prominent problem in the United States. Consumers reported losing a record of about $16 billion to fraud in 2025, according to the Federal Trade Commission, and credit cards remain one of the most commonly reported payment methods in those cases. Even that number doesn’t give a complete picture of the issue.

According to the Nilson Report, which monitors the payments industry, global card fraud losses reached $33.41 billion in 2024, and the US accounted for 41.87% of those losses on just 26.31% of worldwide card volume. Nilson projects more than $407 billion in cumulative card fraud losses over the next decade, and card-not-present fraud, the kind card testing enables, drives an outsized share of it.

The costs start before any big fraudulent purchase lands. Every test attempt carries authorization and decline fees, large botnet-driven runs can generate thousands of attempts in hours, and a flood of declines degrades a merchant’s standing with issuers and processors. The tests that succeed turn into chargebacks once the cardholder spots the charge, and the validated cards fuel larger card-not-present fraud across the ecosystem. Merchants with instant, low-price checkouts, such as digital goods, subscriptions, and donation forms, are the favorite testing grounds.

How to Prevent Card Testing Fraud

To combat card testing fraud, merchants must employ sophisticated fraud detection systems and monitoring mechanisms to identify unusual patterns, monitor transaction velocity, and promptly block or investigate suspicious transactions. Cardholders are encouraged to monitor their account statements for unauthorized activity and promptly report any suspicious charges to their card issuer. Additionally, strong authentication measures, such as multi-factor authentication (MFA) and CVV requirements, are used to enhance security during online transactions. However, each single method cannot stand on its own, and a robust fraud detection and prevention solution is required to combat unauthorized credit card use effectively.

Visa publishes dedicated anti-enumeration and account testing best practices for merchants, and the measures below cover the same ground: make automated testing expensive, and catch the pattern early.

Use Fraud Detection That Learns Patterns and Detects Anomalies

Utilize advanced fraud detection systems that can identify unusual patterns and behaviors associated with card testing and other fraudulent activities. A great fraud prevention solution will use advanced algorithms, machine learning and data analytics to identify suspicious and fraudulent transactions in real-time.

Be sure to customize your fraud detection rules and machine learning models within your fraud prevention solution to adapt to evolving fraud patterns and specific risk factors in your industry or business. And finally, set alert thresholds that trigger investigations or further actions when suspicious transactions or patterns are detected.

Find a fraud prevention solution with robust transaction monitoring that uses advanced algorithms to detect anomalies and deviations from established transaction norms. For card testing fraud prevention, they look for:

  • Rapid and repetitive small transactions from the same card
  • Transactions originating from unusual or unexpected locations
  • Large transaction volumes in a short period
  • Multiple failed transaction attempts within a short time frame
  • Transactions with suspicious merchants or merchant categories

Require Multi-Factor Authentication

Require MFA for online transactions to provide an additional layer of security, making it more difficult for fraudsters to use stolen card information. Choose the MFA methods that best fit your organization’s needs and user preferences. Common MFA methods include:

  • One-time passwords (OTP) sent via SMS, email, or mobile apps
  • Biometric authentication, such as fingerprint or facial recognition
  • Hardware tokens or smart cards
  • Knowledge-based authentication (KBA), involving security questions or personal information
  • Push notifications to mobile devices for approval

Consider implementing adaptive authentication, which assesses the risk associated with a transaction or login attempt and selects an appropriate level of MFA based on the perceived risk. Higher-risk transactions can trigger stronger authentication.

Set Up Velocity Rules

Velocity checks, also known as velocity limits or velocity rules, are an essential component of fraud prevention systems. They are designed to monitor the frequency and volume of certain activities, such as transactions or login attempts, within a specified time frame. Velocity checks are particularly effective in detecting and preventing card testing fraud, account takeover attempts, and other types of fraudulent activities characterized by rapid, repetitive actions.

Consider Pre-Gateway Fraud Prevention

Pre-gateway fraud prevention works to maximize approvals and reduce false declines by working in sync with a dynamic checkout before the customer gets to the payment gateway. It prompts shoppers to fix typos or incorrect information in real-time, rather than screening orders post-gateway when the opportunity to redeem a rejected order is lost.

How Wyllo Helps

Card testing is a pattern problem: each test charge looks harmless on its own, and only the sequence gives it away. Wyllo Payment Fraud Protection screens every transaction in real time, connecting device intelligence, behavioral signals, and network-level patterns to shut down a testing run at the first attempts instead of the thousandth. Because the screening reads intent rather than blunt rules, it blocks the bots without turning good shoppers into false declines.

Frequently Asked Questions

Why do fraudsters make small purchases with stolen cards?

Small charges validate that a stolen card is active without drawing attention. A $1 to $5 purchase is easy for a cardholder to miss on a statement and unlikely to trigger fraud alerts. Once a card tests as live, it gets used for larger purchases or resold on the dark web at a premium.

How do merchants detect card testing attacks?

The tells are volume and velocity: bursts of small transactions or failed attempts, many cards tried from one device or IP address, sequential card numbers, and activity at odd hours. Velocity rules catch the bursts, and anomaly detection catches slower runs distributed across botnets to stay under simple thresholds.

Why do card testers target donation forms and digital goods?

Both confirm a charge instantly, ship nothing, and accept low amounts, which is everything a tester wants. Donation forms are especially exposed because donors choose their own amount, so a $2 test looks like an ordinary gift. Any low-friction payment form can serve as a testing ground.

Does card testing cost merchants money even when the charges are declined?

Yes. Merchants pay authorization and processing fees on attempts whether they clear or not, and a testing run can generate thousands of attempts. A spike in declines also damages the merchant’s approval reputation with issuers, which can suppress approval rates for legitimate customers long after the attack ends.

Related Glossary Categories

Install Wyllo

Select your ecommerce platform to start your free two-week trial.​

See Wyllo in Action

Contact the Wyllo team and we’ll be in touch within one business day to schedule your personalized demo. 

Let's find those
bad actors.

Contact the Wyllo team and we’ll review your system together to identify the bad actors.