Fraud and Abuse
Card Testing
Quick Definition
Patterned authorization attempts used to determine whether stolen or generated payment credentials are valid.
Also Known As Account testing, Carding, Payment-card testing, Enumeration attack
What Card Testing Means
Card testing is a fraud technique in which an attacker runs many authorization attempts to find out which payment credentials are valid. The card numbers may have been stolen in a breach or generated through enumeration, and the goal is to quietly confirm which ones are live before using them for larger fraudulent purchases or reselling them.
The activity usually shows up as a pattern rather than a single event: bursts of small-dollar authorizations, repeated attempts across many card numbers, or an unusual spike in declines over a short window. Because each attempt passes through the merchant's checkout and payment stack, card testing raises processing costs, skews approval and decline metrics, and can contribute to fraud activity that affects a merchant's standing in network monitoring programs.
Defending against card testing relies on recognizing the pattern early. Velocity limits, device and behavior signals, screening tools, and alerting on abnormal authorization volume all help merchants shut down a testing campaign before it scales. Because a successful test often precedes a later unauthorized purchase, treating card testing as an early-warning signal — and monitoring for it continuously — is an important part of protecting both revenue and payment metrics.
Why Card Testing Matters
Card testing can flood a merchant's checkout with authorization attempts, driving up declines, processing costs, and fraud exposure. Left unchecked, it can distort approval metrics and contribute to fraud reporting that affects program standing.
Detecting and blocking these patterns early helps merchants safeguard revenue and keep their payment metrics clean.
How Card Testing Is Used in Payments
Attackers submit many low-value or rapid authorization attempts to learn which stolen or algorithmically generated card numbers are active. Valid credentials are then used for larger fraudulent purchases or sold.
Merchants counter card testing with velocity controls, screening signals, and monitoring that flags abnormal authorization behavior.
Important Distinctions
Card testing is an attack pattern, not a single fraudulent purchase. It often appears as a surge of small authorizations or declines rather than one large charge, so merchants should watch for velocity and pattern anomalies rather than only reviewing completed transactions. A successful test may later lead to an unauthorized transaction, but the testing activity itself is a distinct, earlier stage.
Payment Defender Products
Fraud Signal™
Fraud Signal™ detects the rapid, patterned authorization attempts that indicate card testing before they scale.
Explore Fraud Signal™Threshold Defense™
Threshold Defense™ watches authorization and decline patterns so card-testing spikes do not push a merchant toward monitoring-program thresholds.
Explore Threshold Defense™
Sources and Review Information
Last reviewed July 17, 2026
