Weekly ecommerce tips, deals & news.
Card testing fraud is when criminals use your checkout to find out which stolen card numbers still work. A script fires hundreds of tiny payment attempts at your store, and the approvals tell them which cards are live. They then spend those cards somewhere else, or sell them on.
Card testing fraud works by turning your checkout into a free card checker. Fraudsters buy lists of stolen or guessed card details in bulk. In practice, most of those cards are dead, cancelled or wrong. Your payment form tells them which ones are not.
Think of it like a thief with a huge ring of keys. He doesn’t break into your shop. Instead, he just tries every key in your front door, because your lock is the one that answers.
A script submits card after card through your checkout, often dozens a minute. Plus, each attempt is small, usually the cheapest item you sell. That’s deliberate, because small charges are less likely to be noticed by the real cardholder.
The bot then reads your gateway’s answer. An approval means the card is live. A decline means it moves on to the next number.
However, some attacks never take a payment at all. Instead, they save cards to new accounts, because a saved card rarely shows on a statement.
On WooCommerce, attackers often skip your checkout page entirely. They send requests straight to the checkout endpoint that powers the block-based checkout. That’s why a CAPTCHA that only guards the visible form can miss the attack completely.
In fact, card testers look for the easiest door, not the richest store. A few traits make a checkout attractive to them:
Card testing costs you money even though the stolen goods leave from someone else’s store. First, a flood of declines damages your standing with card issuers. As a result, your real customers can start getting declined too, even after the attack stops.
Next, some test charges succeed, and real cardholders report them. That turns into a chargeback with a fee attached. Some gateway plans also bill per authorization, so thousands of attempts can arrive as a bill. Finally, the fake orders pollute your sales data, so real growth becomes harder to read.
Those costs add up faster than the fraud itself. The LexisNexis True Cost of Fraud study puts the multiplier in plain numbers. US merchants spend $4.61 for every $1 of fraud, once fees and other losses are counted.
Stopping card testing fraud takes several small barriers, not one big wall. Card testers rotate IP addresses and fake identities, so a single rule based on IP alone rarely holds. Instead, stack controls that make each attempt slower and more expensive:
One warning applies to subscription stores. Aggressive payment retries can look like card testing to issuers, because they create bursts of declines. So never keep retrying cards that were saved during an attack.
Visa tracks card testing under the name enumeration. Its Payment Ecosystem Risk and Control team ranks it among the top threats to payments. The team’s Spring 2025 Biannual Threats Report ties enumeration to around US$1.1B in follow-on fraud in a one-year period. The same report counted a 22% rise in enumerated transactions over six months.
Visa now monitors merchants for it directly, through its Acquirer Monitoring Program. A merchant is flagged when enumerated attempts reach 20% of authorizations and 300,000 in a month. Most small WooCommerce stores will never reach that volume. Still, it shows the card networks treat testing as the merchant’s problem to control, not just the bank’s.
Card testing fraud in practice usually looks like a quiet night that fills your order list by morning. Here’s a hypothetical example. Imagine a small marketplace called Pinwheel Paper, where a dozen vendors sell stationery through one shared checkout.
Pinwheel’s cheapest listing is a $2 sticker sheet from one vendor. Guest checkout is on, and there’s no limit on attempts. Overnight, a bot hits the checkout endpoint 1,800 times with different cards.
Around 95% of the cards decline. The other 90 or so go through as $2 orders. The owner wakes up to a vendor asking why she suddenly has 90 sales and 1,700 failed orders.
At first, it looks like a good night for that vendor. However, the orders share the same $2 item, random names and throwaway email addresses. Every one arrived within a few seconds of the last.
In short, the 90 successful charges are the dangerous part. Over the next weeks, cardholders spot them and dispute them. If even a third turn into disputes at a $15 fee each, that’s $450 in fees on $180 of sales.
Meanwhile, the decline spike sits on the marketplace’s single payment gateway account. Every vendor shares that account. So a genuine customer buying a $60 planner from a different vendor gets declined the next day.
The owner refunds all 90 successful orders at once, before most can become disputes. Next, she turns on checkout rate limiting and adds a CAPTCHA that also protects the checkout endpoint. She also asks vendors to raise the price floor on tiny listings.
As a result, a second attack two weeks later stalls after 40 attempts. The refunds cost $180 in returned sales, far less than the dispute fees they prevented. Most importantly, the vendors’ real customers stop getting declined.
| What you’re comparing | Card Testing Fraud | Credential Stuffing |
|---|---|---|
| What is being checked | Stolen card numbers | Stolen email and password pairs |
| Where it hits | Checkout and saved-card forms | Your login page |
| What success gives them | A confirmed card to spend elsewhere | A working customer account |
| Loudest warning sign | A spike of small failed orders | A spike of failed logins |
Card testing fraud checks payment cards, while credential stuffing checks passwords. Both are bulk, automated guessing, so the same defenses (rate limits and CAPTCHAs) help with each. Credential stuffing is common too: Verizon found it made up 19% of all authentication attempts on a median day. A stuffed login often leads to an account takeover, so watch your login page as closely as your checkout.
A sudden wave of small failed orders is the classic sign of card testing. For example, look for the same cheap product, odd customer names and junk email addresses. Check whether the orders arrived seconds apart. If they did, treat it as an active attack and add limits right away.
Yes, refund them quickly and don’t ship anything. The real cardholders will likely dispute those charges once they notice. A refund before the dispute avoids the fee and keeps your dispute rate down. Cancel the failed orders too, so they stop cluttering your reports.
A CAPTCHA helps, but only if it guards every route to payment. Many attacks skip the checkout page and call the checkout endpoint directly. Confirm your CAPTCHA also protects that endpoint. Pair it with rate limiting, because rotating IP addresses can slip past either one alone.
Card testing fraud matters because the bill arrives at your door, even when the theft happens elsewhere. It raises your declines, fees and disputes, and it can block real customers from paying. A few layered fraud prevention controls keep your checkout from becoming someone else’s testing tool.
Copyright © StoreOwnerTips.com. All Rights Reserved.