Merchant Fraud Guide Sections

Card Testing: What It Is and How to Stop It

Someone is running stolen card numbers through your checkout in bulk. Here is how to spot the attack and slow it down.

Your sales look normal. Then your payment log fills with small failed charges from cards you have never seen. That is card testing at work on your store.

What card testing is

Card testing is a type of fraud where someone checks whether stolen card information is valid. Attackers feed card numbers into a checkout and watch which ones go through.

It goes by other names too. Carding, account testing, enumeration, and card checking all mean the same thing. If you see those words in a fraud report, this is the topic.

Card testing is an unavoidable part of online commerce. So expect it. Then make your checkout a hard place to run it.

How a card testing attack works

Card testers use scripts to test a large amount of card information at once. No human types card after card into your form. Software does it.

They often prefer card setup over a real purchase. Setup holds usually do not show up on the card owner's statement. That makes the test quieter. When they do create payments, they keep them small, because cardholders are less likely to notice and report a tiny charge.

A full card testing attack runs a large amount of card information through at once. The goal is not your product. The goal is a list of working card numbers.

Why your checkout is a target

Attackers pick checkouts that are easy to script against. Sites with free text fields, such as donation sites, are the main targets. A donation form with free text fields is a typical example.

Your keys matter too. Card testers can use your publishable key to retry a large number of payments on your website. That key is meant to be public, so it is on the front of your site where scripts can find it.

Your secret key is different. Card testers can create payments and set up cards with your secret key if your credentials are leaked or stolen. Keep your keys safe and never publish your secret key publicly. Check your code repository, your old server files and any public page for it.

How to spot it

Stripe says you can identify most card testing by a significant increase in failed authorizations and payments. Excessive retries can look like card testing when they come in extreme spikes with a low success rate.

Watch your traffic for anomalies. You can use the Dashboard, webhooks, or monitoring with Stripe Sigma or Data Pipelines to track them. Payments blocked during an attack are marked as Blocked by Stripe, which is another place to look.

What it costs you

The damage goes past the failed charges. Card testing can raise your decline rate. It can also hurt how card issuers and card networks see your business. It can also overload your site. Real buyers then get a slow or broken checkout.

And a successful test is not the end of it. Card owners who notice the small charges report them as fraud. That can lead to Early Fraud Warnings or fraudulent disputes. A fraudulent sale can later turn into a chargeback that lands on you.

How to prevent it

No single fix stops all of this, but layers help.

Start with friction. Add a CAPTCHA. Or limit how many charges can come in. Both help fight card testing. Card testers often use automated scripts that CAPTCHA can block. You can use both. Later tries from the same IP address then need to pass a CAPTCHA. If one CAPTCHA service is not catching the attack, trying a different CAPTCHA solution can help.

Add a delay or a CAPTCHA during checkout to slow down someone testing cards on your website. Ask buyers to log in or start a session before they pay. That cuts your risk too. Some guards against cross-site request forgery attacks also stop some kinds of card testing.

Stripe's Payment Element and Checkout tools come with controls that fight card testing. Some run on their own. You can turn others on by hand. You can also write your own rules in Radar to limit or stop card testing. These controls are separate from Radar's dispute protection. But they use the same risk data. The more data your integration provides, the more successful prevention can be.

You can go further. Some tools block requests that come from certain user agents. Fraudsters also work in groups.

Where it fits in card fraud

Card testing is one part of card not present fraud. The tester confirms a card works.

For you, the cost shows up as fraud reports and disputes on the payments that went through. Stripe says merchants, card networks, and Stripe share responsibility to prevent card testing. Your checkout is the part you control.

Read more on credit card testing and on card testing fraud for a deeper look at each part.

Sources

The rest of Card testing