Merchant Fraud Guide Sections

Card Testing Attacks: Spot and Stop Them

Someone is running stolen card numbers through your checkout in bulk. Here is how to spot it and what you can do.

Your decline rate jumps. A run of small failed charges, none from a customer you know. You are probably being used to test stolen cards.

What a card testing attack is

A card testing attack is a type of fraud where someone checks whether stolen card information is valid. They use your checkout to do it. Other names for the same thing are carding, account testing, enumeration, and card checking. Stripe calls it an unavoidable part of online commerce. Our card testing guide covers the basics if you want a fuller picture.

How the attack works

Testers use scripts to try a large amount of card information at once. They do not go for big charges. They create small payments that cardholders are less likely to notice and report. Many prefer card setup, where the card is saved for later use. The cardholder's statement usually never shows the setup hold. So the cardholder may never see the test.

Why it hurts your store

The damage goes past the stolen money. Successful tests can be reported as fraud and turn into disputes. Customers who notice these payments report them, which can result in Early Fraud Warnings or fraudulent disputes. Testing also raises your decline rate and damages your reputation with card issuers and card networks. A flood of script traffic can overload your site. It can disrupt legitimate activity at your checkout.

How to spot it

You can spot most card testing by a big jump in failed authorizations and payments. That is the clearest sign. Watch for it with the Dashboard or webhooks. You can also use Stripe Sigma or Data Pipelines to track odd spikes in your traffic. One caution from Stripe. Too many retries of your own payments can look like card testing. This happens when they come in big spikes with few successes. If you retry failed charges, space them out.

How testers reach your checkout

There are two common doors. The first is your publishable key. Testers can use it to retry a large number of payments on your website. The second is worse. If your secret key is leaked or stolen, testers can use it to create payments and set up cards. Keep your keys safe and never publish your secret key publicly. Sites with free text fields, such as donation sites, are the main targets.

What Stripe's controls do

Stripe builds defenses against card testing into its Payment Element and Checkout. A few of them work without you doing anything. Some you turn on by hand. Its recommended setups include rate limiters, AI models, and CAPTCHA triggers. Payments stopped by these controls are marked as Blocked by Stripe, so you can see what was caught. You can also write custom rules in Radar to limit or prevent card testing activity. These controls are separate from Radar's protection against fraudulent disputes, though both draw on the same risk factors. And the more data your integration provides, the more successful prevention can be. None of this is a guarantee. Stripe says merchants, card networks, and Stripe share responsibility to prevent card testing, so part of the job is yours. For more on the fraud side, see card testing fraud.

What Shopify's bot protection does and does not do

Shopify's bot protection blocks known bots from checkout. It slows bot activity, so real customers can buy scarce products during flash sales. That is all it is for. Shopify says it only limits auto-checkout bots. It is not meant to fight fraud from bot activity. So Shopify does not offer it as a card testing defense, and it is available only for merchants on a Shopify Plus plan. Read more in our page on Shopify bot protection.

Steps you can take

Start with key hygiene. Keep the secret key secret. Then make the checkout harder for scripts. Require a login or an active session before anyone can pay. This cuts your exposure to card testers. CSRF tokens guard against cross-site request forgery. They also work against some types of card testing. Adding a delay or a CAPTCHA during checkout slows down someone testing cards on your website. Stripe recommends its own automated CAPTCHA protection. When attacks continue, trying a different CAPTCHA solution can help. You can also combine CAPTCHAs and rate limits. After that, any more requests from that same IP address have to clear a verification. Advanced fraud detection can filter out requests with certain user agents. If you want the wider picture of credit card testing, start with those same habits. No single step stops every attack, but together they make your checkout a poor place to work.

Sources

The rest of Card testing