Blogs

Card Testing Fraud: How to Detect and Stop It (SMB Guide)

author
SecureTrust by VikingCloud Team
Published
September 16, 2026

Card Testing Fraud for Small Businesses: How to Detect and Stop It

While accepting payments online helps small businesses reach broader audiences, those without dedicated fraud teams may be overlooking sophisticated threats. Card testing fraud, in particular, targets small businesses with weak controls and limited fraud detection.

Payment fraud affects more than three-quarters of US organizations, and the smallest companies often have the fewest resources to absorb the losses. In this guide, we explore what card testing fraud entails, how it harms businesses, and how you can protect against it.

What Card Testing Fraud Is and How It Works

Card testing fraud is the act of running small transactions with stolen card numbers through online checkout. Criminals do this to check if stolen card details are valid and active.

Once cards have “passed the test”, they are either resold on the dark web at a premium or used to commit larger fraudulent purchases.

Small businesses are at particular risk from this type of fraud because they don’t typically have the advanced detection capabilities to spot it. What’s more, would-be criminals don’t always have full card credentials and may rely on lax or weak payment controls to fill the gaps (and complete the “purchases”).

In some cases, card issuers and banks may spot this type of suspicious activity and raise flags such as a do not honor decline message.

The Role of Bots and Automation in Card Testing

The rise of bots and automation used in fraud attacks like card testing means that small-scale, manual card reviews are not enough to stop them. In fact, most modern card testing attacks are fully-automated. Fraudsters can deploy bots to perform hundreds of “purchases” in a matter of minutes.

To keep pushing fraud purchases at scale, criminals use rotating IP addresses, proxy services, and VPNs to hide their locations and distribute attempts across global servers. This also helps them to evade some anti-fraud measures, such as IP blacklisting.

Criminals take this type of fraud further by mimicking what appears to be legitimate customer behavior. For example, they may randomize and vary the times of day they attack, use separate devices, and add different products to their carts each time they “buy”.

By attacking “low and slow,” fraudsters deliberately avoid triggering fraud detection thresholds. A low, seemingly natural purchase velocity is unlikely to present red flags to typical fraud detectors, making this a highly deceptive attack. Avoiding high test volumes also reduces the chance of banks and issuers intervening.

The growing sophistication of card testing fraud means businesses must stay vigilant and use layered detection and prevention strategies to fight against these attacks.

How Card Testing Fraud Harms Small Businesses

Card testing fraud harms more than the cardholders whose details are stolen. It can also lead to serious financial and operational consequences for small businesses. For example, multiple low-value test purchases can lead to high processing fees, especially during large-scale attacks.

Moreover, cardholders who notice fraudulent transactions will usually file chargebacks to recoup costs, meaning a merchant’s chargeback ratio will suffer. This, in turn, can lead to payment processors applying penalties, increasing fees, or even suspending accounts.

A further compounding issue is that, in an attempt to thwart further fraud attempts, a small business might make verification rules too strict. This could risk completely innocent, legitimate transactions getting flagged and refused. In turn, this can affect customer trust and brand loyalty.

Card testing is one piece of a much larger drain on small businesses.

“(...) a first-of-its-kind national survey of more than 500 small business owners reveals that America’s small businesses are paying a staggering $131 billion annual “hidden tax” due to fraud, scams, and ransomware. The survey, conducted by Morning Consult for the Public Private Strategies Institute, also found that AI is increasing the risk(...)”

Public Private Strategies Institute

How to Spot a Card Testing Attack

It is possible to spot card testing attack signals even without sophisticated fraud detection measures. For example, a typical signal is a sudden, concentrated spike in low-value transactions declined across multiple card numbers. The key to identifying this signal is noticing both transaction size and time window.

In some cases, attackers may still use the same IP address or device to process multiple transactions. If there is a clear pattern of small, failed authorizations from identical IPs or device fingerprints, it’s a strong indicator of card testing fraud.

Card testing fraud is also identifiable through a concentrated creation of new accounts in rapid succession. If each new account then attempts a small transaction, it is wise to take action. Spotting fraud this way is easier when customers create accounts before checking out, though it’s important to weigh that against the friction it adds for legitimate buyers.

In other cases, you may be able to spot fraud if there are unusual traffic and login patterns (e.g., from VPNs and proxies).

Tools and Solutions for Stopping Card Testing Fraud

To help prevent card testing fraud, we recommend using solutions such as PCI-compliant gateways, CAPTCHA forms, velocity rules, device analysis, and real-time transaction monitoring.

Before choosing a payment processing or fraud mitigation tool, always check the PCI Security Standards Council’s (PCI SSC) listings of validated products and solutions. Listed solutions have been validated against PCI SSC standards, which means they’re built to protect cardholder data and support your own PCI Data Security Standard (PCI DSS) compliance efforts.

Here is a detailed breakdown of the solutions introduced above:

  • PCI-compliant payment gateways ensure that e-commerce transactions are treated with the utmost security in line with current threats. In particular, prioritize platforms that offer Address Verification Service (AVS) and Card Verification Value (CVV) enforcement, which block card testers working with incomplete card details.
  • CAPTCHA forms, widely used across the web, prevent bots from submitting purchase orders, and require human interaction for transactions to proceed.
  • Velocity rules, configured via your gateway, can block failed attempts from a specific IP range within a specific time window.
  • Solutions offering behavioral analysis and device fingerprinting can help you identify and analyze certain login and payment patterns. For example, this deeper analysis can help you identify bots that would otherwise avoid IP-based tracking.
  • Solutions providing real-time transaction monitoring, backed by adaptive risk scoring, support dynamic signal evaluation across multiple flagged transactions at once.

Prevention Strategies for Small Businesses

Small businesses without in-house fraud management can fortify checkout against card testing with a few simple process adjustments.

For example:

  • Always require customers to provide CVV numbers and full, valid billing addresses when checking out. Doing so blocks fraudsters testing cards without full details available.
  • Use additional card verification steps, such as 3D Secure, so all payments undergo secondary authentication.
  • Raise the cost of testing for fraudsters on donation forms and via checkout rules. Set sensible minimum transaction amounts, and avoid open amount fields that let fraudsters submit very small test charges.
  • Regularly monitor payment decline rates and carefully consider false positives. Typically, short, sudden decline spikes indicate there may be fraud in play.
  • Always ensure checkout environments are PCI compliant. Regularly patch and update software in line with manufacturer guidelines and regulator expectations. Doing so reduces the chances of cardholder data being harvested through skimming attacks.

These strategies safeguard cardholders and strengthen e-commerce and retail PCI compliance. Auditors will see that you have taken measured steps to protect against fraud and to ensure cardholder information is locked down.

Balancing Fraud Protection and Customer Experience

While it may seem worthwhile to apply stringent e-commerce payment security with the most aggressive measures, doing so carries costs for businesses and their customers. For example, over-sensitive blocking and flagging may prevent legitimate purchases alongside fraud transactions.

The compounding effect is that customers become frustrated and don’t complete their orders, leading to lost revenue on top of fraud losses. Balance fraud protection carefully so that legitimate transactions can continue without unnecessary restriction.

We recommend using PCI SSC validated solutions that let you customize and configure rules based on customer histories and transaction values. Additionally, businesses should set rules that account for multiple risk signals to build clearer, more confident fraud profiles.

Used effectively, all of these strategies can reduce false positives while keeping cardholder data as safe as possible. The end goal is a layered, proactive defense that stops bots in their tracks while keeping shopping accessible to genuine customers.

Are you concerned about processor fines and data security? Learn more about how SecureTrust™  supports PCI compliance for small businesses, and in turn, helps you protect cardholders and customers with greater confidence.

Frequently Asked Questions

Q1. What is card testing fraud?

Card testing fraud is a criminal activity where fraudsters “test” stolen cards by making small purchases or transactions. Doing so confirms that a card is active, and can then be resold or used for larger fraudulent purchases.

Q2. Why do small businesses get targeted for card testing?

Smaller businesses are less likely than most to possess advanced fraud detection systems and security measures. That means fraudsters are more likely to see them as easy targets for seemingly innocuous “card testing.”

Q3. How do I know if my business is being targeted?

Your business may be experiencing card testing fraud if there are short, concentrated spikes or periods of declined transactions. These may appear as rapid-fire purchases split across different locations, and in some cases, from identical IP addresses.

Q4. Does CAPTCHA stop card testing?

CAPTCHA can stop card testing by preventing bots and automated tools from processing stolen card numbers at high volumes. CAPTCHA forms and puzzles require human users to complete them before further action, like making purchases, can continue.

Q5 Can card testing affect my merchant account?

Card testing can trigger payment processor fees, spike chargebacks, and potentially lead to processors freezing, penalizing, or even suspending accounts. This is because each test charge creates transaction costs and frequently leads to chargebacks from innocent cardholders.

Sources

The Association for Financial Professionals. (2026). 2026 AFP Payments Fraud and Control Survey Report. AFP, underwritten by Truist. Retrieved June 25, 2026, from https://www.financialprofessionals.org/training-resources/resources/survey-research-economic-data/details/payments-fraud

https://www.securetrust.com/blog/do-not-honor-decline

Ahmad, N. (2026, April 9). Press Release: New National Survey of Small Businesses: Fraud, Scams and Ransomware Impose a $131 Billion “Hidden Tax” on Main Street. Public Private Strategies Institute. Retrieved June 25, 2026, from https://www.ppsi.org/fraud-scams-ransomware-press-release

PCI Security Standards Council. (N.d.). Product & Solutions Listings Overview. PCI SSC. Retrieved June 25, 2026, from https://www.pcisecuritystandards.org/product-solutions-listings-overview/

SecureTrust . (N.d.). PCI Compliance for Small Retail Businesses. SecureTrust : Retail. Retrieved June 25, 2026, from https://www.securetrust.com/industries/retail

Hagdahl, J. (2025, June 30). Ecommerce Payment Security: Protect Every Transaction. SecureTrust  Blog. Retrieved June 25, 2026, from https://www.securetrust.com/blog/e-commerce-balancing-speed-to-market-and-payment-security

SecureTrust . (N.d.). PCI Compliance for Small Business. SecureTrust : Retail. Retrieved June 25, 2026, from https://www.securetrust.com/solutions/pci-compliance-for-small-business

author

SecureTrust

More Blogs

Stay up-to-date on the latest happenings in Cybersecurity and PCI Compliance.
View All Blogs
July 30, 2026
'Do Not Honor' Decline Code: What It Means and How to Handle It
July 20, 2026
AVS Mismatch: Why Your Customer's Card Got Declined and What to Do
July 16, 2026
PCI Compliance for Restaurants: POS, Online Ordering, and Delivery Apps