Store Owner Tips

Subscribe to our newsletter

Weekly ecommerce tips, deals & news.

Thank You, we'll be in touch soon.

Latest News

Card Testing Fraud

Card testing fraud is when criminals use your checkout to find out which stolen card numbers still work. A script fires hundreds of tiny payment attempts at your store, and the approvals tell them which cards are live. They then spend those cards somewhere else, or sell them on.


Key Takeaways

  • Your store is the test bench: the real theft usually happens on another site, after your checkout confirms the card.
  • Failed orders are the loudest sign: a sudden pile of small failed or pending orders almost always means an attack.
  • You pay even when you block it: declines, fees and disputes land on your account, not the fraudster’s.
  • Layers beat single fixes: rate limits, a CAPTCHA and gateway screening work far better together than alone.

How Does Card Testing Fraud Work?

Card testing fraud works by turning your checkout into a free card checker. Fraudsters buy lists of stolen or guessed card details in bulk. In practice, most of those cards are dead, cancelled or wrong. Your payment form tells them which ones are not.

Think of it like a thief with a huge ring of keys. He doesn’t break into your shop. Instead, he just tries every key in your front door, because your lock is the one that answers.

How the bots run the test

A script submits card after card through your checkout, often dozens a minute. Plus, each attempt is small, usually the cheapest item you sell. That’s deliberate, because small charges are less likely to be noticed by the real cardholder.

The bot then reads your gateway’s answer. An approval means the card is live. A decline means it moves on to the next number.

However, some attacks never take a payment at all. Instead, they save cards to new accounts, because a saved card rarely shows on a statement.

On WooCommerce, attackers often skip your checkout page entirely. They send requests straight to the checkout endpoint that powers the block-based checkout. That’s why a CAPTCHA that only guards the visible form can miss the attack completely.

Why your store gets picked

In fact, card testers look for the easiest door, not the richest store. A few traits make a checkout attractive to them:

  • Cheap products: a low price keeps each test charge small and quiet.
  • Open guest checkout: no login means every attempt can come from a fresh identity.
  • No attempt limits: nothing stops one visitor trying 500 cards in an hour.
  • Weak screening: a gateway that receives little customer data has less to judge risk with.

What it costs when it lands

Card testing costs you money even though the stolen goods leave from someone else’s store. First, a flood of declines damages your standing with card issuers. As a result, your real customers can start getting declined too, even after the attack stops.

Next, some test charges succeed, and real cardholders report them. That turns into a chargeback with a fee attached. Some gateway plans also bill per authorization, so thousands of attempts can arrive as a bill. Finally, the fake orders pollute your sales data, so real growth becomes harder to read.

Those costs add up faster than the fraud itself. The LexisNexis True Cost of Fraud study puts the multiplier in plain numbers. US merchants spend $4.61 for every $1 of fraud, once fees and other losses are counted.

How to stop an attack in progress

Stopping card testing fraud takes several small barriers, not one big wall. Card testers rotate IP addresses and fake identities, so a single rule based on IP alone rarely holds. Instead, stack controls that make each attempt slower and more expensive:

  • Rate limits on checkout: cap how many orders one visitor or device can place in an hour.
  • A CAPTCHA on every payment route: that includes the checkout endpoint, not just the page.
  • Limits on saved cards: restrict how many cards one account can add in a day.
  • Richer data for your gateway: passing email, name and billing address gives its fraud checks more to judge.
  • Refunds for anything that slipped through: refund successful test charges before they become disputes.

One warning applies to subscription stores. Aggressive payment retries can look like card testing to issuers, because they create bursts of declines. So never keep retrying cards that were saved during an attack.

What Do The Numbers Say About Card Testing Fraud?

Visa tracks card testing under the name enumeration. Its Payment Ecosystem Risk and Control team ranks it among the top threats to payments. The team’s Spring 2025 Biannual Threats Report ties enumeration to around US$1.1B in follow-on fraud in a one-year period. The same report counted a 22% rise in enumerated transactions over six months.

Visa now monitors merchants for it directly, through its Acquirer Monitoring Program. A merchant is flagged when enumerated attempts reach 20% of authorizations and 300,000 in a month. Most small WooCommerce stores will never reach that volume. Still, it shows the card networks treat testing as the merchant’s problem to control, not just the bank’s.


What Does Card Testing Fraud Look Like In Practice?

Card testing fraud in practice usually looks like a quiet night that fills your order list by morning. Here’s a hypothetical example. Imagine a small marketplace called Pinwheel Paper, where a dozen vendors sell stationery through one shared checkout.

The night of the attack

Pinwheel’s cheapest listing is a $2 sticker sheet from one vendor. Guest checkout is on, and there’s no limit on attempts. Overnight, a bot hits the checkout endpoint 1,800 times with different cards.

Around 95% of the cards decline. The other 90 or so go through as $2 orders. The owner wakes up to a vendor asking why she suddenly has 90 sales and 1,700 failed orders.

At first, it looks like a good night for that vendor. However, the orders share the same $2 item, random names and throwaway email addresses. Every one arrived within a few seconds of the last.

The fallout

In short, the 90 successful charges are the dangerous part. Over the next weeks, cardholders spot them and dispute them. If even a third turn into disputes at a $15 fee each, that’s $450 in fees on $180 of sales.

Meanwhile, the decline spike sits on the marketplace’s single payment gateway account. Every vendor shares that account. So a genuine customer buying a $60 planner from a different vendor gets declined the next day.

The fix

The owner refunds all 90 successful orders at once, before most can become disputes. Next, she turns on checkout rate limiting and adds a CAPTCHA that also protects the checkout endpoint. She also asks vendors to raise the price floor on tiny listings.

As a result, a second attack two weeks later stalls after 40 attempts. The refunds cost $180 in returned sales, far less than the dispute fees they prevented. Most importantly, the vendors’ real customers stop getting declined.


What’s The Difference Between Card Testing Fraud And Credential Stuffing?

What you’re comparingCard Testing FraudCredential Stuffing
What is being checkedStolen card numbersStolen email and password pairs
Where it hitsCheckout and saved-card formsYour login page
What success gives themA confirmed card to spend elsewhereA working customer account
Loudest warning signA spike of small failed ordersA spike of failed logins

Card testing fraud checks payment cards, while credential stuffing checks passwords. Both are bulk, automated guessing, so the same defenses (rate limits and CAPTCHAs) help with each. Credential stuffing is common too: Verizon found it made up 19% of all authentication attempts on a median day. A stuffed login often leads to an account takeover, so watch your login page as closely as your checkout.


Frequently Asked Questions

Why am I getting hundreds of failed orders overnight?

A sudden wave of small failed orders is the classic sign of card testing. For example, look for the same cheap product, odd customer names and junk email addresses. Check whether the orders arrived seconds apart. If they did, treat it as an active attack and add limits right away.

Should I refund card testing orders that went through?

Yes, refund them quickly and don’t ship anything. The real cardholders will likely dispute those charges once they notice. A refund before the dispute avoids the fee and keeps your dispute rate down. Cancel the failed orders too, so they stop cluttering your reports.

Will a CAPTCHA stop card testing on my store?

A CAPTCHA helps, but only if it guards every route to payment. Many attacks skip the checkout page and call the checkout endpoint directly. Confirm your CAPTCHA also protects that endpoint. Pair it with rate limiting, because rotating IP addresses can slip past either one alone.


Why Does Card Testing Fraud Matter?

Card testing fraud matters because the bill arrives at your door, even when the theft happens elsewhere. It raises your declines, fees and disputes, and it can block real customers from paying. A few layered fraud prevention controls keep your checkout from becoming someone else’s testing tool.

Share article

Subscribe to our newsletter

Weekly ecommerce tips, deals & news.

Nice – You're in!

Copyright © StoreOwnerTips.com. All Rights Reserved.