Skip to content
Proactive security updates
Security

Card-Testing Attacks: Protect Checkout From Bot Fraud

Automated bots test stolen card data at checkout. How to spot card testing early, stop it with monitoring and rate limiting, and avoid chargeback fees.

12 min read Card-TestingCheckout-SicherheitBetrugspräventionBot-FraudMonitoring

An online shop explicitly invites strangers to enter card details - and that is exactly what fraudsters exploit. In card testing, automated bots fire stolen or guessed card numbers at the checkout in rapid succession, using tiny amounts to find out which card is still valid. The numbers for this attack type jumped in 2026: card-testing attacks rose 175 percent (Signifyd State of Fraud 2026) year over year, and account-takeover attacks 78 percent (Signifyd State of Fraud 2026). For shop operators this is not an abstract security topic but a direct assault on the till, the invoice and the reputation - every test transaction costs fees, worsens the fraud ratio at the payment provider and can ultimately lead to payments being blocked. This guide shows how managed checkout monitoring together with rate limiting stops the wave before chargebacks and provider penalties arise.

Key takeaways

  • Card testing is automated fraud: bots use many tiny charges to check which stolen card details still work. 175 percent (Signifyd State of Fraud 2026) more such attacks were measured in 2026 year over year.
  • The damage does not come from the test amounts themselves but from the knock-on costs: chargeback fees from 20 US dollars (Chargeflow) per case, rising decline rates and a growing fraud-and-dispute ratio at the payment provider.
  • The card networks have tightened up: the Visa VAMP threshold for the fraud-and-dispute ratio dropped from 2.2 to 1.5 percent (Chargebacks911) on 1 April 2026, and a separate enumeration monitor kicks in at 20 percent (Visa) of flagged authorisations.
  • Typical warning signs are a sudden spike in declined payments, many orders with tiny amounts, recurring IP addresses and unusual times of day - visible only if the checkout is monitored.
  • Effective protection is layered: rate limiting and velocity checks slow the source, bot detection and CAPTCHA stop automation, 3D Secure 2 secures risky payments - embedded in ongoing maintenance and monitoring.

What Card Testing Is and Why It Hits Every Shop

Card testing - also called card enumeration - is an automated form of fraud. Criminals hold long lists of stolen or algorithmically generated card numbers and need to find out which of them are still active and have available funds. Instead of typing in each card by hand, they point bots at a freely accessible checkout and let them fire hundreds or thousands of payment attempts with tiny amounts in seconds. When a payment is confirmed, the card counts as verified and moves onto a list for a later, high-value fraudulent purchase. The attack on your shop is therefore only the preliminary stage - the expensive part comes afterwards.

It is not the biggest shop that gets hit, but the most reachable one. Attackers deliberately look for checkouts that allow many payment attempts without a brake, return error messages openly and have no bot defence. The economic lever is large: fraud pressure in retail rose 33 percent (Signifyd State of Fraud 2026) year over year in 2026, and a growing share of that runs fully automated. Signifyd evaluates a network of 950 million (Signifyd State of Fraud 2026) unique digital wallets for this - so the attacks are broad and measurable, not isolated cases. For small and mid-sized shops this means: visibility on the web is enough to become a target.

Card testing in brief

In card testing, fraudsters use many small payment attempts to check which stolen card details still work. The test amounts are tiny, often under one euro, and barely stand out individually. The danger lies in the volume: it causes fees, worsens your metrics at the payment provider and hands the perpetrators a verified card list for their next step.

How an Attack Runs at the Checkout

A card-testing attack almost always follows the same pattern. It starts quietly, escalates within minutes and leaves a characteristic trail of declined payments. Anyone who knows the sequence spots the wave earlier - and can interrupt it at the right point instead of cleaning up chargebacks afterwards.

  1. Data sourcing: the perpetrators buy or generate card numbers in bulk, sometimes without a valid check digit or expiry date.
  2. Target selection: bots look for shops with an open checkout, donation or voucher forms and no visible brake.
  3. Test run: tiny amounts are authorised automatically - many cards, one source, a few seconds.
  4. Evaluation: confirmed cards are sorted out, declined ones are dropped from the list.
  5. Second strike: the verified cards are later used for high-value orders that come back as fraud.
  6. Aftermath: the shop carries fees, an elevated decline rate and the effort of investigation and refunds.

The Hidden Costs of a Card-Testing Wave

The amount of a single test transaction is almost meaningless - often less than one euro. The sum of the side effects is what gets expensive. For every disputed payment, a chargeback fee of 20 to 100 US dollars (Chargeflow) applies, regardless of the tiny order value. When thousands of attempts add up, that quickly becomes a noticeable loss. At the same time, every failed authorisation worsens the approval rate, and that stands out to the payment provider. The following six cost blocks hit every shop that lets a wave through unchecked.

Chargeback fees

Every disputed test transaction costs from 20 US dollars (Chargeflow) in processing fees - regardless of the tiny payment amount.

Decline rate

Thousands of failed authorisations push down the approval rate and stand out to the payment provider as an anomaly.

Provider penalties

If the fraud-and-dispute ratio rises above the threshold, penalty fees loom - up to a block on payment processing.

Server load

The flood of automated requests strains the checkout and database and can slow real customers during purchase.

Reputation

Cardholders see unfamiliar small charges and report fraud - which burdens the brand and customer service.

Real fraud purchases

Verified cards are then used for high-value orders that later come back as a chargeback.

Warning Signs of a Card-Testing Wave

Card testing is inconspicuous as long as no one is looking - but it leaves clear traces in logs and metrics. A watchful eye on payment attempts, declines and the origin of requests makes the attack visible, often within the first minutes. The following signals belong in every monitoring setup.

  • A sudden, steep rise in declined payments with no explainable reason
  • Many orders or payment attempts with conspicuously small amounts
  • Numerous different card numbers from the same IP address or session
  • Unusual times of day and a surge outside normal buying hours
  • Recurring, similar email addresses or incomplete customer data
  • A payment provider getting in touch about a risen fraud or decline ratio

If the provider calls first, it is late

If a shop only learns of a wave through the payment provider's warning, the attack has usually been running for a while. By then fees have already been incurred and the metrics are burdened. Your own monitoring of decline rates and amount patterns provides the decisive head start to intervene earlier.

Visa VAMP and Enumeration Monitoring in 2026

The card networks raised the pressure in 2026. On 1 April 2026, Visa lowered the threshold of its Acquirer Monitoring Program (VAMP) for the combined fraud-and-dispute ratio from 2.2 percent (Chargebacks911) to 1.5 percent (Chargebacks911) - a drop of roughly a third overnight. A fee of 8 US dollars (cside) applies per disputed transaction, and without any warning tier beforehand. In parallel, a dedicated enumeration monitor checks for automated card tests: if the share of flagged authorisations exceeds 20 percent (Visa) with a floor of 300,000 transactions, the data stream counts as an enumeration attack. For shops this means: card testing is no longer just an internal nuisance but a metric the network watches.

What Visa changes in 2026MeaningConsequence for the shop
VAMP threshold lowered from 2.2 to 1.5 percentless room for fraud and disputescard testing pushes the ratio over the line faster
Penalty fee per disputed transactioneight US dollars per case, no warning tierevery test wave becomes immediately costly
Enumeration monitoring (VAAI)flags automated card tests in the networkunusual authorisation patterns stand out at once
Monitoring floor at 1,500 cases per monthsmall shops below the formal thresholdprotection still makes economic sense

Small shops with fewer than 1,500 (cside) combined fraud-and-dispute cases per month do sit below the formal monitoring threshold - yet the fees, the server load and the reputational damage arise regardless. Economically, protection pays off whether or not a shop is large enough to fall into formal monitoring.

How Managed Monitoring Stops the Wave

There is no single switch against automated attacks, only a layered defence. Each layer makes the test run a little harder and renders it uneconomical for the perpetrators. Rate limiting and velocity checks form the front line: they cap how many payment attempts are allowed from one source within a time window, breaking the economics of a bot. Detection and alerting run around the clock in checkout monitoring, so a wave stands out before it gets expensive. The following six building blocks interlock.

Rate limiting

Caps payment attempts per IP, session and time window and thereby breaks the economics of a test run.

Velocity checks

Detect unusual frequencies: many cards from one source, many small amounts within seconds.

Bot detection

Distinguishes automation from humans via behaviour patterns and blocks script traffic before authorisation.

3D Secure 2

Moves risky payments into strong customer authentication and makes blind card testing unattractive.

Monitoring

Watches decline rates, tiny amounts and IP patterns around the clock and raises the alarm on anomalies.

Risk rules

Block suspicious countries, card ranges or amount patterns without locking out genuine customers.

Balance is key: rules that are too strict block real customers and depress conversion, while rules that are too loose let bots through. Managed monitoring tunes the thresholds against the shop's real traffic patterns and adjusts them when buying behaviour changes. This keeps the checkout smooth for customers and unattractive for automation - closely interlocked with ongoing security updates that secure the technical base.

The Playbook for an Emergency

When a wave is running, every minute counts. A clear procedure prevents panic and keeps the damage small. The following steps can be defined in advance in an SLA maintenance contract, so that in an emergency no one has to first work out who does what.

  1. Confirm the attack: cross-check decline rates, amount patterns and the origin of requests in monitoring.
  2. Slow the source: tighten rate limiting and throttle suspicious IP ranges or regions.
  3. Stop automation: activate bot detection and CAPTCHA at the payment step.
  4. Secure payments: enforce 3D Secure 2 for risky transactions.
  5. Involve the provider: inform the payment provider and clarify affected authorisations.
  6. Follow up: adjust rules permanently and record the incident in the maintenance report.

Speed beats perfection

A card-testing wave is not stopped by the one perfect rule but by fast, layered intervention. Whoever throttles the source within minutes and locks out the automation takes away the attack's basis - and limits fees and metric damage before the payment provider has to react.

Adding Card-Testing Protection to Ongoing Maintenance

Checkout security is not a project with an end date but a state that must be maintained. Attack patterns change, new card lists surface, and the card networks' thresholds are tightened - as in 2026. That is why protection against card testing belongs in the same rhythm as updates, backups and availability monitoring. In our maintenance packages, fraud defence at the checkout is a recurring building block: rules are monitored, adapted to new patterns and, in an emergency, tightened quickly via emergency support. Related building blocks such as protection against DDoS attacks during peak and the clean rotation of API keys and shop secrets belong in the same security strategy.

It starts with an inventory: how many payment attempts does the checkout allow unchecked, what patterns do the logs show, and where is visibility missing today? This analysis can be requested without obligation - as the basis for protection that fits the traffic and the risk of each individual shop.

Card testing does not cost where it is visible, but in fees, metrics and reputation. Whoever monitors the checkout and slows the source takes away the attack's economic value.

Principle of checkout security
This article is based on data from: Signifyd State of Fraud Report 2026, Chargeflow (card-testing statistics 2026), Chargebacks911 (Visa Acquirer Monitoring Program 2026), cside (VAMP 2026 Merchant Playbook) and Visa (Account Attack Intelligence, enumeration monitoring). Security requirements and card-network thresholds can change.

Related Articles