
Card Testing Indicators
Card testing is the practice of running small, low-risk charges against stolen card numbers to find out which ones still work. The attempts are cheap and quick, and a single one looks almost harmless on your order list โ but they leave a trail across your gateway logs. This guide collects the card testing indicators that matter most, so you can catch a run early instead of discovering it weeks later through chargebacks.
Key Features
- Indicators organized by channel: web checkout, mobile app, phone orders, and in-store terminals.
- Velocity patterns, including bursts of authorizations from one IP, device fingerprint, or card BIN.
- Decline-then-approve sequences that reveal a fraudster cycling through numbers until one clears.
- Digital fingerprint clues such as disposable email domains, proxy exits, and mismatched billing data.
- Order-value clustering just below your low-value fraud threshold.
- Geography and BIN anomalies, including sudden spikes from regions you do not ship to.
- Post-attack signals: refund requests, disputes, and cardholder complaints that arrive days later.
- A one-page triage checklist for risk, support, and fulfillment teams.
Format and Contents
The guide ships as an instant-download PDF with a plain-text checklist you can paste into a ticketing system. It runs 58 pages across nine tables and two printable worksheets, and every indicator explains what it looks like in raw authorization data and why it appears. Nothing depends on a specific processor, so the same signals apply whether you run on Stripe, Adyen, Shopify Payments, or a direct acquirer connection.
Delivery and Returns
Because this is a digital product, the download link arrives within minutes of checkout and there is nothing to wait for in the mail. If the guide does not fit how your team works, request a refund within 30 days and keep the checklist โ no forms, no phone calls.
What is card testing?
Card testing is a fraud technique where someone submits many small transactions to learn which stolen card numbers are still active. The working numbers are then used for larger purchases or resold.
How many failed attempts should worry me?
There is no universal number, but a sudden jump in declines from one IP, device, or BIN range โ even a few dozen in an hour โ deserves immediate investigation. Compare the spike against your normal decline rate before writing it off as noise.
What should I do first when I see these indicators?
Block or rate-limit the offending IPs and device fingerprints, require CVV and AVS on the affected BINs, and notify your acquirer. Documenting the run also helps if disputes arrive weeks later.