Card Testing: How to Spot an Attack in the First Hour and Stop It Before Your Processor Does
The short answer
A card testing attack is when fraudsters use bots to run stolen card numbers through your checkout in small amounts to learn which cards work, then use the good ones for bigger fraud elsewhere. You pay in fees, disputes and a falling approval rate. Spot it early by watching for a burst of small, mostly declined authorizations, then add checkout friction and void approved test charges.
How does a card testing attack work?
Card testing (also called carding or enumeration) is the use of automated scripts to check whether stolen card details are valid before using them for larger fraud.
A fraudster buys a batch of stolen card numbers, often thousands at a time. Many are dead: expired, cancelled or already blocked. To find the live ones, the fraudster points a bot at a checkout with weak defenses and submits small charges, one card after another. A $1 donation page, a low-price digital product or a free trial with a card on file all make easy targets. Some attackers skip the charge entirely and use "save card" or card setup flows, because those checks rarely show up on a cardholder's statement.
Some attacks go further. In an enumeration attack, the bot guesses missing details, cycling through expiry dates and security codes until an authorization goes through. Either way, the pattern is the same: a burst of small authorizations, most of them declined, from a rotating set of devices and IP addresses.
The problem is growing in targeted industries. HUMAN Security's 2026 guide to cyberthreats in travel and hospitality found that at the most heavily attacked travel businesses (the 90th percentile of its customers), attempted carding reached 17.6 percent of checkout traffic in 2025, up from 3.1 percent in 2022. Those figures measure attempts, not successful fraud, and come from HUMAN's own customer base.
What does card testing cost a merchant?
Card testing costs you in four ways: fees, disputes, network monitoring and your relationship with your processor.
- Fees. Depending on your pricing, you may pay an authorization fee on every attempt, approved or declined, plus a dispute fee on every test charge that turns into a chargeback.
- Fraud reports and disputes. Approved test charges turn into fraud reports and disputes once real cardholders spot them. Both count toward Visa's Visa Acquirer Monitoring Program (VAMP) ratio. For US merchants, Visa's "Excessive" threshold dropped from 2.2 percent to 1.5 percent on April 1, 2026. Our guide to Visa VAMP thresholds for 2026 covers the math.
- Lower approval rates. A wave of declines tied to your merchant account makes issuers see your traffic as riskier, which can push down approvals for real customers even after the attack stops.
- Processor action. When your processor sees the spike in declines and fraud reports, it can add a rolling reserve or close your account to protect itself.
Visa also measures enumeration on its own. The VAMP enumeration ratio counts enumerated authorizations, approved and declined, against all authorizations. A merchant is flagged at 20 percent or higher once it has at least 300,000 enumerated transactions in a month. Visa reports that, globally, enumerated accounts carry fraud rates 22 times higher than regular accounts.
Most merchants miss card testing until approval rates drop or the processor places a reserve hold.
What are the warning signs of card testing?
Card testing leaves a clear trail in your data, if you look in the right place at the right time.
- Attempt spikes: a sudden jump in authorization attempts with no matching jump in traffic or marketing.
- Small, repeated amounts: many transactions at the same low amount, often your lowest price point.
- Decline code patterns: a wave of generic, incorrect security code, expired card and do-not-honor declines.
- Many cards, one source: different cards tried from one device, IP address or email.
- Junk customer data: nonsensical names and email addresses on new orders or saved cards.
- Odd hours: spikes at times when your real customers sleep.
Decline rate and authorization velocity belong on your daily fraud dashboard. Our fraud detection metrics plan shows which numbers to track and how often.
How do you stop a card testing attack in progress?
Act fast. Every hour of an active attack adds fees, fraud reports and processor attention.
- Add friction at checkout. Turn on bot detection or a CAPTCHA on the payment page and on any save-card endpoint, and limit how many attempts one device, IP address or session gets.
- Tighten card checks. Require the security code on every card-not-present payment and use address verification where it is available.
- Protect your soft spots. Raise the minimum on donation pages, require login or session validation before payment, and lock down free trials.
- Clean up approved test charges. Void them before they settle. If they have already settled, refund them, so they are less likely to become disputes.
- Stop retrying. Do not keep retrying cards saved during the attack, since that repeats the attack in your own traffic.
Finally, call your processor and tell them what happened and what you fixed. A processor who hears it from you first treats you differently than one who finds it in a report.
Why do most merchants find out late?
Most merchants run payments, fraud screening and disputes on separate tools. Your shopping cart sees the traffic. Your gateway sees the declines. Your fraud tool sees its own scores. Your chargeback tool sees disputes weeks later. No single tool sees the full attack while it happens, so the pattern stays hidden until approval rates drop or the processor places a reserve hold.
How pmtbox catches card testing early
pmtbox sees your full transaction lifecycle in one place: shopping cart, payments, fraud attempts, disputes and chargebacks. Because we see the whole picture, we can spot the burst of small authorizations and the decline-code pattern while the attack is under way, instead of weeks later in a dispute report.
We flag the attack, show you what is happening, and act before your approval rates drop or a processor places a reserve hold. With Fraud Ownership, we cover the full cost of fraudulent transactions our system approves. And when you call, a real person answers.
Talk to the pmtbox team about protecting your checkout from card testing.
Frequently asked questions
What is card testing?
Card testing is when fraudsters run stolen card numbers through a checkout in small amounts to find out which cards work. It is also called carding, account testing or enumeration. The valid cards are then used for larger purchases or resold.
What is an enumeration attack?
An enumeration attack is a type of card testing where bots guess missing card details, such as expiry dates and security codes, until an authorization goes through. Visa tracks it separately through the VAMP enumeration ratio.
Can card testing get my merchant account closed?
It puts your account at risk. Approved test charges become fraud reports and disputes, and a spike in both can trigger processor reserves, card network monitoring programs and account closure.
Should I refund card testing charges?
Void approved test charges before they settle, so they never post as completed charges. If a charge has already settled, refund it. Either step makes it less likely the cardholder files a dispute.
How do I know if I'm being card tested?
Look for a burst of small transactions, a sharp rise in declines (especially generic, security code and expired card declines), and many cards tried from one device or IP address. Junk names and email addresses on new orders are another sign.
Sources
- Most targeted travel sites face stolen card tests at 17.6% rate, HUMAN finds, PPC Land (reporting HUMAN Security, "The 2026 Guide to AI, Agentic Traffic, and Cyberthreats for Travel and Hospitality")
- Visa Account Attack Intelligence, Visa
- Introducing the Visa Acquirer Monitoring Program, Visa
- Visa monitoring programs (VAMP thresholds and enumeration ratio), Solidgate
- Protect yourself from card testing, Stripe


