SterlingRidge
FraudJuly 16, 2026 · 5 min read

Card Testing Attacks: Spot Them Before Your Processor Does

By Sterling Ridge Editorial

Fraudsters validate stolen card numbers by firing small transactions at unprotected checkouts — and the merchant pays for every attempt. Early detection is the difference between a bad hour and a terminated account.

What a card testing attack looks like

Card testing is industrialized trial and error: a bot armed with thousands of stolen card numbers hits your checkout or donation form with small transactions — $1, $5, sometimes $0 authorizations — to learn which numbers are still live. The validated cards are then resold or used for real fraud elsewhere. You are not the target; you are the free testing lab.

The damage is real anyway. You pay authorization and decline fees on every attempt, your decline rate spikes in ways issuers and processors notice, the few approved transactions come back as chargebacks weeks later, and if the attack runs long enough, your account gets flagged for the fraud pattern someone else created.

Detection and defense

The signature is unmistakable if you are watching: a burst of low-value attempts, high decline rates, sequential card numbers, many cards per IP address or device, and velocity no human shopper produces. Alerting on "declines per hour" alone catches most attacks in minutes rather than days.

Defense is layered: CAPTCHA or proof-of-work on checkout, velocity limits per IP and per device fingerprint, AVS and CVV enforcement, minimum transaction amounts on public forms, and rate limits on your payment API. Sterling Ridge monitors merchant traffic for testing patterns at the gateway level and alerts you before the pattern damages your standing with the acquiring bank — because catching it in hour one instead of week two is what keeps a fraud incident from becoming an account review.

Having trouble
getting approved?

Sterling Ridge approves 99% of applicants — including high-risk businesses and merchants dropped by other processors.

No long-term contracts · No setup fees

More from the blog