A card testing attack is when fraudsters use bots to run stolen card numbers through your checkout in small amounts to learn which cards work, then use the good ones for bigger fraud elsewhere. You pay in fees, disputes and a falling approval rate. Spot it early by watching for a burst of small, mostly declined authorizations, then add checkout friction and void approved test charges.
Card testing (also called carding or enumeration) is the use of automated scripts to check whether stolen card details are valid before using them for larger fraud.
A fraudster buys a batch of stolen card numbers, often thousands at a time. Many are dead: expired, cancelled or already blocked. To find the live ones, the fraudster points a bot at a checkout with weak defenses and submits small charges, one card after another. A $1 donation page, a low-price digital product or a free trial with a card on file all make easy targets. Some attackers skip the charge entirely and use "save card" or card setup flows, because those checks rarely show up on a cardholder's statement.
Some attacks go further. In an enumeration attack, the bot guesses missing details, cycling through expiry dates and security codes until an authorization goes through. Either way, the pattern is the same: a burst of small authorizations, most of them declined, from a rotating set of devices and IP addresses.
The problem is growing in targeted industries. HUMAN Security's 2026 guide to cyberthreats in travel and hospitality found that at the most heavily attacked travel businesses (the 90th percentile of its customers), attempted carding reached 17.6 percent of checkout traffic in 2025, up from 3.1 percent in 2022. Those figures measure attempts, not successful fraud, and come from HUMAN's own customer base.
Card testing costs you in four ways: fees, disputes, network monitoring and your relationship with your processor.
Visa also measures enumeration on its own. The VAMP enumeration ratio counts enumerated authorizations, approved and declined, against all authorizations. A merchant is flagged at 20 percent or higher once it has at least 300,000 enumerated transactions in a month. Visa reports that, globally, enumerated accounts carry fraud rates 22 times higher than regular accounts.
Most merchants miss card testing until approval rates drop or the processor places a reserve hold.
Card testing leaves a clear trail in your data, if you look in the right place at the right time.
Decline rate and authorization velocity belong on your daily fraud dashboard. Our fraud detection metrics plan shows which numbers to track and how often.
Act fast. Every hour of an active attack adds fees, fraud reports and processor attention.
Finally, call your processor and tell them what happened and what you fixed. A processor who hears it from you first treats you differently than one who finds it in a report.
Most merchants run payments, fraud screening and disputes on separate tools. Your shopping cart sees the traffic. Your gateway sees the declines. Your fraud tool sees its own scores. Your chargeback tool sees disputes weeks later. No single tool sees the full attack while it happens, so the pattern stays hidden until approval rates drop or the processor places a reserve hold.
pmtbox sees your full transaction lifecycle in one place: shopping cart, payments, fraud attempts, disputes and chargebacks. Because we see the whole picture, we can spot the burst of small authorizations and the decline-code pattern while the attack is under way, instead of weeks later in a dispute report.
We flag the attack, show you what is happening, and act before your approval rates drop or a processor places a reserve hold. With Fraud Ownership, we cover the full cost of fraudulent transactions our system approves. And when you call, a real person answers.
Talk to the pmtbox team about protecting your checkout from card testing.
Card testing is when fraudsters run stolen card numbers through a checkout in small amounts to find out which cards work. It is also called carding, account testing or enumeration. The valid cards are then used for larger purchases or resold.
An enumeration attack is a type of card testing where bots guess missing card details, such as expiry dates and security codes, until an authorization goes through. Visa tracks it separately through the VAMP enumeration ratio.
It puts your account at risk. Approved test charges become fraud reports and disputes, and a spike in both can trigger processor reserves, card network monitoring programs and account closure.
Void approved test charges before they settle, so they never post as completed charges. If a charge has already settled, refund it. Either step makes it less likely the cardholder files a dispute.
Look for a burst of small transactions, a sharp rise in declines (especially generic, security code and expired card declines), and many cards tried from one device or IP address. Junk names and email addresses on new orders are another sign.