Skip to main content

BankingCard fraud7 of 28

Card testing

Running many small or zero-value authorizations against stolen card details to find which cards are live before using them for larger fraud.

EVENTS OVER TIMEDozens of attempts in minutesNormal cadenceBurst window
Illustrative patternA run of small authorizations on many different cards hits one merchant within minutes.

How it works

Card details stolen in bulk, through data breaches, skimming, phishing or underground marketplaces, are of uncertain quality. Fraudsters test them with small purchases, zero-value account-verification checks or donation payments through a merchant with weak controls. Cards that are approved are used or resold at a higher price, and declined cards are discarded.

Testing is usually automated. A script submits a large number of attempts through one merchant's checkout, often from rotating IP addresses and with randomized amounts so the traffic looks less uniform.

For an issuer, testing shows up as small authorizations or declines on many cards at the same merchant, followed later by larger fraudulent spending on the cards that passed. For a merchant or acquirer, it shows up as a spike in low-value attempts with a high decline rate. Catching the test stage gives the issuer a chance to block cards before the main losses.

Red flags

  • Many low-value or zero-value authorizations at one merchant across unrelated cards in a short window
  • A high decline rate, especially for invalid CVV, expiry date or address-verification mismatches
  • Small charges at unfamiliar online merchants, charities or digital-goods sites on a card that does not normally use them
  • Cards that pass a small test and then show larger card-not-present spending shortly after
  • Attempts across many cards from the same IP range or device

Signals the engine evaluates

  • Authorization attempts per merchant and per terminal across unrelated cards within short rolling windows
  • Decline rate and decline reason codes per merchant compared with the merchant's own baseline
  • Distribution of transaction amounts, flagging concentrations of very low or zero-value authorizations
  • Later spending on cards that recently had a small approved authorization at a merchant under suspicion

Investigation and response

  1. 01Identify the common testing point, usually a merchant or terminal, and the full set of cards that touched it during the window.
  2. 02Block or reissue cards that were approved during testing, and tighten authorization controls on the rest of the set.
  3. 03Notify the acquirer or card scheme through the usual fraud-reporting channels so the merchant can be secured.
  4. 04Track the tested cards in one case so that later fraudulent spending is linked back to the test event.
Get started

Catch card testing before the loss

See how FinCrimes scores this pattern against your own historical data in a backtest, before anything goes live.

Browse the library