What it means
Carding describes the whole process of buying stolen card details in bulk, testing them, and turning the working ones into money or goods. The testing step is the part businesses feel, because the criminal needs a live payment page that will accept a small amount and answer yes or no instantly.
A merchant caught up in a card testing attack is being used as a free validation service rather than being robbed directly. The cost arrives as thousands of low-value attempts, a collapse in the authorisation approval rate, a gateway fee on every attempt and, if the ratio gets bad enough, penalties and monitoring by the card schemes.
Attackers favour donation forms, mobile top-ups, subscription sign-ups and any checkout that allows an open amount with no minimum. Scripts cycle through card numbers, expiry dates and billing addresses at speed, usually from many different internet addresses so no single source looks busy.
Defences are about friction and limits rather than detection after the event. A minimum transaction value, caps on attempts per card, per device and per address, a bot challenge on the payment form and address verification on the card all raise the cost of testing enough to send the attacker elsewhere.
Watching the approval rate hour by hour is the cheapest early warning most finance teams have. A normal consumer checkout approves the large majority of attempts, so a sudden drop to a small fraction approved, with average transaction values far below normal, is a testing attack in progress.
The nuance that catches people out is that the tested merchant may lose very little in fraud yet still pay heavily. Processing fees on worthless attempts, chargeback administration, staff time and the risk of being placed in a scheme monitoring programme are usually the larger numbers.
In practice
Real-world examples.
Example
A charity's donation page allows any amount from $1 upward with no limit on attempts. Over two nights it processes 40,000 attempts from scripts testing stolen cards, and the payment fees alone come to several thousand dollars. Setting a $5 minimum donation and adding a bot check ends the attack.
Example
A mobile airtime reseller sees its approval rate fall from 92% to 23% in an afternoon while transaction counts triple. Its acquirer warns that the chargeback ratio is approaching the level that triggers a scheme monitoring programme. The reseller caps attempts at three per card and five per device each hour, and the approval rate recovers the same day.
Example
An online electronics retailer finds that cards tested a week earlier on another company's donation page are now being used to buy high-value laptops for delivery to a single block of flats. It adds address verification and a manual review step on orders above $1,000, and the pattern stops.
Formula
Calculation
Cost of a card testing attack = (attempts x authorisation fee per attempt) + (chargebacks x chargeback fee) + value of fraudulent sales not recovered
A subscription business is hit with 60,000 authorisation attempts over one weekend. Its gateway charges $0.08 per attempt, so the processing cost is 60,000 x 0.08 = $4,800. Of those attempts, 300 cards were approved for $1 test charges that later came back as chargebacks with a $15 fee each, which is 300 x 15 = $4,500, plus the $300 of charges refunded. The weekend therefore cost 4,800 + 4,500 + 300 = $9,600, against almost no genuine revenue.Case study
Seen in the real world.
Brightpath Learning is an illustrative, fictional online course provider selling a $19 trial product through its own checkout page.
The trial was ideal for card testers: a small fixed amount, an instant approval or decline, and no limit on how many times a visitor could try. Over three weeks Brightpath's attempts rose from about 3,000 a day to 55,000 a day while genuine sign-ups barely moved, and its approval rate fell below 20%. The finance team first assumed a pricing problem, because revenue per visit had collapsed.
The fix cost very little: a bot challenge on the payment form, a cap of three attempts per card and ten per device each day, and address verification required on every transaction. Attempts returned to normal within two days. The illustrative lesson is that the attack never targeted Brightpath's money at all, only the yes or no answer its checkout gave away for free.
Watch out
Common mistakes.
- Assuming an attack has failed because almost every attempt was declined, when the declines themselves are the product the attacker came for.
- Measuring fraud only by chargeback value, which ignores the per-attempt processing fees that make up most of the cost of card testing.
- Allowing unlimited retries on a payment form in the name of customer convenience, which is the single feature testers look for.
Questions
People also ask.
How would a finance team spot carding in its own numbers?
A sharp fall in the authorisation approval rate, a jump in attempt volume and an average transaction value far below normal, all in the same period, is the classic signature.
Is carding the same as card-not-present fraud?
Carding is the activity of testing and exploiting stolen details, while card-not-present fraud is the category of loss that results, so the two overlap without being identical.
Can an acquirer penalise a merchant that was only used for testing?
Yes, because scheme monitoring looks at the merchant's own decline and chargeback ratios regardless of who was targeted, which is why attempt limits matter.
From the founder's library

Take it further with the book.
Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.
25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.
View the book and save 25%Related
