Card testing is a fraud pattern in which criminals fire small authorizations at a merchant’s checkout to learn which stolen card numbers are still live. Validated cards are then resold or spent elsewhere. Merchants with fast checkouts, low priced products and no friction are the preferred laboratory.
Why it matters
The damage lands in three places: authorization fees on thousands of junk attempts, a decline spike that wrecks issuer confidence in your MID, and the chargebacks that arrive when the few approved tests hit real statements. The signature is easy to spot once you look: bursts of small identical amounts, sequential BINs, one IP cycling many cards. Velocity limits, a CAPTCHA on the payment step and strict AVS and CVV rules stop most of it, and monitoring programs like VAMP now count fraud you fail to block.
