How it works
Card details stolen in bulk, through data breaches, skimming, phishing or underground marketplaces, are of uncertain quality. Fraudsters test them with small purchases, zero-value account-verification checks or donation payments through a merchant with weak controls. Cards that are approved are used or resold at a higher price, and declined cards are discarded.
Testing is usually automated. A script submits a large number of attempts through one merchant's checkout, often from rotating IP addresses and with randomized amounts so the traffic looks less uniform.
For an issuer, testing shows up as small authorizations or declines on many cards at the same merchant, followed later by larger fraudulent spending on the cards that passed. For a merchant or acquirer, it shows up as a spike in low-value attempts with a high decline rate. Catching the test stage gives the issuer a chance to block cards before the main losses.
Red flags
- Many low-value or zero-value authorizations at one merchant across unrelated cards in a short window
- A high decline rate, especially for invalid CVV, expiry date or address-verification mismatches
- Small charges at unfamiliar online merchants, charities or digital-goods sites on a card that does not normally use them
- Cards that pass a small test and then show larger card-not-present spending shortly after
- Attempts across many cards from the same IP range or device
Signals the engine evaluates
- Authorization attempts per merchant and per terminal across unrelated cards within short rolling windows
- Decline rate and decline reason codes per merchant compared with the merchant's own baseline
- Distribution of transaction amounts, flagging concentrations of very low or zero-value authorizations
- Later spending on cards that recently had a small approved authorization at a merchant under suspicion
Investigation and response
- 01Identify the common testing point, usually a merchant or terminal, and the full set of cards that touched it during the window.
- 02Block or reissue cards that were approved during testing, and tighten authorization controls on the rest of the set.
- 03Notify the acquirer or card scheme through the usual fraud-reporting channels so the merchant can be secured.
- 04Track the tested cards in one case so that later fraudulent spending is linked back to the test event.