An online shop explicitly invites strangers to enter card details - and that is exactly what fraudsters exploit. In card testing, automated bots fire stolen or guessed card numbers at the checkout in rapid succession, using tiny amounts to find out which card is still valid. The numbers for this attack type jumped in 2026: card-testing attacks rose 175 percent (Signifyd State of Fraud 2026) year over year, and account-takeover attacks 78 percent (Signifyd State of Fraud 2026). For shop operators this is not an abstract security topic but a direct assault on the till, the invoice and the reputation - every test transaction costs fees, worsens the fraud ratio at the payment provider and can ultimately lead to payments being blocked. This guide shows how managed checkout monitoring together with rate limiting stops the wave before chargebacks and provider penalties arise.
Key takeaways
- Card testing is automated fraud: bots use many tiny charges to check which stolen card details still work. 175 percent (Signifyd State of Fraud 2026) more such attacks were measured in 2026 year over year.
- The damage does not come from the test amounts themselves but from the knock-on costs: chargeback fees from 20 US dollars (Chargeflow) per case, rising decline rates and a growing fraud-and-dispute ratio at the payment provider.
- The card networks have tightened up: the Visa VAMP threshold for the fraud-and-dispute ratio dropped from 2.2 to 1.5 percent (Chargebacks911) on 1 April 2026, and a separate enumeration monitor kicks in at 20 percent (Visa) of flagged authorisations.
- Typical warning signs are a sudden spike in declined payments, many orders with tiny amounts, recurring IP addresses and unusual times of day - visible only if the checkout is monitored.
- Effective protection is layered: rate limiting and velocity checks slow the source, bot detection and CAPTCHA stop automation, 3D Secure 2 secures risky payments - embedded in ongoing maintenance and monitoring.
What Card Testing Is and Why It Hits Every Shop
Card testing - also called card enumeration - is an automated form of fraud. Criminals hold long lists of stolen or algorithmically generated card numbers and need to find out which of them are still active and have available funds. Instead of typing in each card by hand, they point bots at a freely accessible checkout and let them fire hundreds or thousands of payment attempts with tiny amounts in seconds. When a payment is confirmed, the card counts as verified and moves onto a list for a later, high-value fraudulent purchase. The attack on your shop is therefore only the preliminary stage - the expensive part comes afterwards.
It is not the biggest shop that gets hit, but the most reachable one. Attackers deliberately look for checkouts that allow many payment attempts without a brake, return error messages openly and have no bot defence. The economic lever is large: fraud pressure in retail rose 33 percent (Signifyd State of Fraud 2026) year over year in 2026, and a growing share of that runs fully automated. Signifyd evaluates a network of 950 million (Signifyd State of Fraud 2026) unique digital wallets for this - so the attacks are broad and measurable, not isolated cases. For small and mid-sized shops this means: visibility on the web is enough to become a target.
Card testing in brief
How an Attack Runs at the Checkout
A card-testing attack almost always follows the same pattern. It starts quietly, escalates within minutes and leaves a characteristic trail of declined payments. Anyone who knows the sequence spots the wave earlier - and can interrupt it at the right point instead of cleaning up chargebacks afterwards.
- Data sourcing: the perpetrators buy or generate card numbers in bulk, sometimes without a valid check digit or expiry date.
- Target selection: bots look for shops with an open checkout, donation or voucher forms and no visible brake.
- Test run: tiny amounts are authorised automatically - many cards, one source, a few seconds.
- Evaluation: confirmed cards are sorted out, declined ones are dropped from the list.
- Second strike: the verified cards are later used for high-value orders that come back as fraud.
- Aftermath: the shop carries fees, an elevated decline rate and the effort of investigation and refunds.
The Hidden Costs of a Card-Testing Wave
The amount of a single test transaction is almost meaningless - often less than one euro. The sum of the side effects is what gets expensive. For every disputed payment, a chargeback fee of 20 to 100 US dollars (Chargeflow) applies, regardless of the tiny order value. When thousands of attempts add up, that quickly becomes a noticeable loss. At the same time, every failed authorisation worsens the approval rate, and that stands out to the payment provider. The following six cost blocks hit every shop that lets a wave through unchecked.
Chargeback fees
Every disputed test transaction costs from 20 US dollars (Chargeflow) in processing fees - regardless of the tiny payment amount.
Decline rate
Thousands of failed authorisations push down the approval rate and stand out to the payment provider as an anomaly.
Provider penalties
If the fraud-and-dispute ratio rises above the threshold, penalty fees loom - up to a block on payment processing.
Server load
The flood of automated requests strains the checkout and database and can slow real customers during purchase.
Reputation
Cardholders see unfamiliar small charges and report fraud - which burdens the brand and customer service.
Real fraud purchases
Verified cards are then used for high-value orders that later come back as a chargeback.
Warning Signs of a Card-Testing Wave
Card testing is inconspicuous as long as no one is looking - but it leaves clear traces in logs and metrics. A watchful eye on payment attempts, declines and the origin of requests makes the attack visible, often within the first minutes. The following signals belong in every monitoring setup.
- A sudden, steep rise in declined payments with no explainable reason
- Many orders or payment attempts with conspicuously small amounts
- Numerous different card numbers from the same IP address or session
- Unusual times of day and a surge outside normal buying hours
- Recurring, similar email addresses or incomplete customer data
- A payment provider getting in touch about a risen fraud or decline ratio
If the provider calls first, it is late
Visa VAMP and Enumeration Monitoring in 2026
The card networks raised the pressure in 2026. On 1 April 2026, Visa lowered the threshold of its Acquirer Monitoring Program (VAMP) for the combined fraud-and-dispute ratio from 2.2 percent (Chargebacks911) to 1.5 percent (Chargebacks911) - a drop of roughly a third overnight. A fee of 8 US dollars (cside) applies per disputed transaction, and without any warning tier beforehand. In parallel, a dedicated enumeration monitor checks for automated card tests: if the share of flagged authorisations exceeds 20 percent (Visa) with a floor of 300,000 transactions, the data stream counts as an enumeration attack. For shops this means: card testing is no longer just an internal nuisance but a metric the network watches.
| What Visa changes in 2026 | Meaning | Consequence for the shop |
|---|---|---|
| VAMP threshold lowered from 2.2 to 1.5 percent | less room for fraud and disputes | card testing pushes the ratio over the line faster |
| Penalty fee per disputed transaction | eight US dollars per case, no warning tier | every test wave becomes immediately costly |
| Enumeration monitoring (VAAI) | flags automated card tests in the network | unusual authorisation patterns stand out at once |
| Monitoring floor at 1,500 cases per month | small shops below the formal threshold | protection still makes economic sense |
Small shops with fewer than 1,500 (cside) combined fraud-and-dispute cases per month do sit below the formal monitoring threshold - yet the fees, the server load and the reputational damage arise regardless. Economically, protection pays off whether or not a shop is large enough to fall into formal monitoring.
How Managed Monitoring Stops the Wave
There is no single switch against automated attacks, only a layered defence. Each layer makes the test run a little harder and renders it uneconomical for the perpetrators. Rate limiting and velocity checks form the front line: they cap how many payment attempts are allowed from one source within a time window, breaking the economics of a bot. Detection and alerting run around the clock in checkout monitoring, so a wave stands out before it gets expensive. The following six building blocks interlock.
Rate limiting
Caps payment attempts per IP, session and time window and thereby breaks the economics of a test run.
Velocity checks
Detect unusual frequencies: many cards from one source, many small amounts within seconds.
Bot detection
Distinguishes automation from humans via behaviour patterns and blocks script traffic before authorisation.
3D Secure 2
Moves risky payments into strong customer authentication and makes blind card testing unattractive.
Monitoring
Watches decline rates, tiny amounts and IP patterns around the clock and raises the alarm on anomalies.
Risk rules
Block suspicious countries, card ranges or amount patterns without locking out genuine customers.
Balance is key: rules that are too strict block real customers and depress conversion, while rules that are too loose let bots through. Managed monitoring tunes the thresholds against the shop's real traffic patterns and adjusts them when buying behaviour changes. This keeps the checkout smooth for customers and unattractive for automation - closely interlocked with ongoing security updates that secure the technical base.
The Playbook for an Emergency
When a wave is running, every minute counts. A clear procedure prevents panic and keeps the damage small. The following steps can be defined in advance in an SLA maintenance contract, so that in an emergency no one has to first work out who does what.
- Confirm the attack: cross-check decline rates, amount patterns and the origin of requests in monitoring.
- Slow the source: tighten rate limiting and throttle suspicious IP ranges or regions.
- Stop automation: activate bot detection and CAPTCHA at the payment step.
- Secure payments: enforce 3D Secure 2 for risky transactions.
- Involve the provider: inform the payment provider and clarify affected authorisations.
- Follow up: adjust rules permanently and record the incident in the maintenance report.
Speed beats perfection
Adding Card-Testing Protection to Ongoing Maintenance
Checkout security is not a project with an end date but a state that must be maintained. Attack patterns change, new card lists surface, and the card networks' thresholds are tightened - as in 2026. That is why protection against card testing belongs in the same rhythm as updates, backups and availability monitoring. In our maintenance packages, fraud defence at the checkout is a recurring building block: rules are monitored, adapted to new patterns and, in an emergency, tightened quickly via emergency support. Related building blocks such as protection against DDoS attacks during peak and the clean rotation of API keys and shop secrets belong in the same security strategy.
It starts with an inventory: how many payment attempts does the checkout allow unchecked, what patterns do the logs show, and where is visibility missing today? This analysis can be requested without obligation - as the basis for protection that fits the traffic and the risk of each individual shop.
Card testing does not cost where it is visible, but in fees, metrics and reputation. Whoever monitors the checkout and slows the source takes away the attack's economic value.