A card testing transaction is a low value charge, often a few cents to a few dollars, run against a stolen card number to learn whether that card still works. Fraud groups push thousands of these charges through payment gateways in a short window, keep the numbers that approve, and then use or resell those cards. For merchants, the result is a burst of tiny orders, higher processing fees, and chargebacks that land weeks later.
What does the "v8" label mean in card testing?
Version tags like v8 come from the fraud toolkits themselves, not from Visa, Mastercard, or any payment processor. A group that rewrites its script, swaps its proxy pool, or shifts to a new set of merchant targets bumps the number and posts the new build in a forum. There is no official v8 standard, no certification behind it, and no card network file by that name.
Treat these labels the same way you treat malware version numbers. They signal a change in attacker tooling, which usually means a fresh wave of attempts against new targets. The defensive playbook does not change.
How does card testing work?
- Card numbers arrive in bulk from data breaches, phishing kits, or criminal marketplaces.
- A script submits small charges to checkout pages, often across hundreds of stores at once.
- The gateway response sorts live cards from dead ones. An approval means the card is open.
- Working numbers go toward gift cards, resale, or larger purchases.
- The script rotates IP addresses, emails, and card numbers to stay under per card limits.
Most of the damage shows up as noise: failed authorizations, thin order values, and a spike in traffic from data center IP ranges. Buying, selling, or using stolen card data is a crime in the United States under wire fraud and computer fraud statutes, and the card networks levy fines on merchants whose fraud ratios climb.
Why do attackers pick small merchants?
Small stores often run guest checkout, skip address verification, and have no velocity limits in place. Digital goods and instant delivery help too, since there is no shipping address to check. A store with a basic gateway and no fraud rules is an easy target for automated scripts that need volume.
Signs of card testing on your store
- A jump in authorization attempts with a high decline rate.
- Hundreds of orders at $1 or less, sometimes from the same card BIN range.
- Many accounts or guest orders sharing a small set of email patterns.
- Address verification and CVV checks failing on most attempts.
- Traffic from VPNs, proxies, or hosting providers instead of residential networks.
- Chargebacks arriving three to eight weeks after the first small charges.
How do you stop card testing transactions?
- Require CVV and AVS. Declining on a CVV mismatch removes a large share of test attempts.
- Turn on 3D Secure. Authentication shifts liability and adds a step that scripts cannot clear.
- Set velocity rules. Limit attempts per IP, device, email, and card BIN within a rolling window.
- Add a CAPTCHA to checkout and account creation, or block known data center IP ranges.
- Raise the minimum order value for guest checkout, or require an account for small purchases.
- Use a fraud tool with card testing rules. Most major gateways ship a radar or risk engine with presets for this attack.
- Watch your decline data with your processor and ask for fraud reports when volume changes.
What should you do if your gateway is under attack right now?
- Call your payment processor and report the burst. Ask about their card testing response team.
- Raise risk thresholds and enable stricter rules for a short window.
- Block the BIN ranges and IP blocks you see in the logs, then lift them once the traffic stops.
- Void or refund the small approved orders instead of shipping anything.
- Review account creation logs and remove fake accounts.
- Track chargebacks for the next two billing cycles and fight the ones you can document.
Do declined test charges cost money?
Yes, in most cases. Many pricing plans bill a per authorization fee, so a flood of declines still generates cost. Card networks also track your fraud and decline ratios, and sustained abuse can trigger fines or a review of your merchant account. Approved tests add the sale amount, the processing fee, and often a chargeback fee later.
Frequently asked questions
Is card testing the same as account enumeration?
They are related but not identical. Account enumeration guesses login credentials or gift card balances. Card testing guesses whether a card number will authorize. Many attacks run both against the same store on the same day.
Can a small store really be a target?
Small stores are common targets because they carry weak controls and rarely monitor fraud data. Attackers do not care about order size. They care about how many approval or decline signals they can collect per hour.
Does 3D Secure stop card testing?
It removes a large share of it, since scripts rarely pass authentication. Some merchants see friction at checkout, so test 3D Secure on high risk orders first and measure the effect on conversion.
How long does an attack last?
Bursts often run for a few hours to a few days, then stop when controls go up. Some groups return with new proxies and a new toolkit version, which is what the version labels track.
Key takeaways
- Card testing uses small charges to confirm stolen card numbers are live.
- Version labels like v8 come from criminal toolkits, not from card networks.
- Small value orders, high declines, and proxy traffic are the clearest warning signs.
- CVV checks, AVS, 3D Secure, and velocity limits cut most attacks at the door.
- Report bursts to your processor and expect chargebacks for up to two months.