Card testing: how stolen card numbers get checked

Card testing is the scripted run of small payments or card checks through a merchant's checkout to find out which stolen card numbers still work. Visa's rules call it an enumeration attack. The merchant pays for it in declined payments and dispute fees, and the valid cards are used or sold elsewhere. Dated events on payments and fraud are in the calendar below.

Repeated small declined card payments in an illustrative fraud-monitoring screen

How a card testing attack works

The Visa Core Rules define an enumeration attack as the systematic or routine submission of card-absent transactions into the Visa system to fraudulently obtain or validate payment information. Stripe's guide on card testing describes how it runs: scripts test many cards at once and read the 3-D Secure or issuer responses to see which ones are valid. Other names are carding, account testing and enumeration.

Most testers use card setup, where a card is saved for later, because a card validation does not show on the cardholder's statement. Others use small payments that a cardholder is less likely to notice. A BIN attack is the variant in which the fraudster holds no stolen numbers and generates them: the first digits of a card number identify the issuing bank, and the script tries the remaining digits until a payment goes through.

Costs for merchants and acquirers

Test payments that succeed come back as disputes and early fraud warnings. According to Stripe, a high share of declined payments harms the merchant's standing with issuers and card networks, so legitimate payments get declined more often even after the attack stops. Authorization and dispute fees add up, and a merchant with many fraud warnings can end up in a card network monitoring program.

Those programs reach the acquirer as well. The Visa Core Rules let Visa identify acquirers under the Visa Acquirer Monitoring Program (VAMP) and treat non-compliance with its requirements as a breach of the rules.

Controls that stop it, from CAPTCHA to AI models

Payment service providers fight card testing with automated controls. Stripe names rate limiters, AI models, CAPTCHA triggers and ongoing reviews in its own checkout, and adds that a rule built on one signal, such as the IP address, is rarely enough. The models work better when the merchant sends more data with each payment: IP address, customer email and name, billing address.

On its own site a merchant can require a CAPTCHA on every request that saves a card or makes a payment, ask for a login or a validated session before checkout, and limit how many cards one account may add or how many new customers one IP address may create in a day. Stripe also warns against aggressive payment retries, which look like card testing to issuers.

Upcoming events on payments and fraud in Germany

How do you recognize a card testing attack?

By a sudden rise in failed or blocked payments, many declines with a generic decline code, and a wave of low-value payments with nonsense customer names and email addresses. Stripe advises refunding test payments that got through before the cardholders dispute them.

Does 3-D Secure stop card testing?

Only in part. The testers read the 3-D Secure response as one of the signals that tell them whether a card is valid, so authentication alone does not end an attack. It does shift fraud liability for authenticated payments to the issuer, as the strong customer authentication page explains.

Card testing and Finance Loop

Finance Loop is the meeting place for the people who run checkouts, acquiring and fraud operations at payment service providers and merchants. Finance Loop announced KI Exchange 2026 in Hamburg, whose program included fraud detection with AI.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, digital payments, cloud and blockchain solutions. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.