Card Testing Attacks: How Subscription Sites Get Hit and What Stops It

Cardflo Editorial··8 min read

This article explains how card testing attacks uniquely impact subscription businesses, detailing the mechanisms of these fraudulent activities and their severe consequences for online merchants.

Apply for a Merchant Account with Cardflo

Merchant accounts, acquiring routes, and chargeback controls, matched to your risk profile.

Apply now
Card Testing Attacks: How Subscription Sites Get Hit and What Stops It editorial cover image

Card testing attacks are a persistent threat for any online merchant, but they pose a unique danger to subscription businesses. Fraudsters use automated scripts to test thousands of stolen card numbers on your payment page, often through small transactions like a £1 trial or a free sign-up that requires card validation. These attacks clog your payment gateway, trigger high decline rates that damage your acquirer relationships, and leave you with a mountain of chargebacks and scheme fines.

What is a card testing attack?

A card testing attack, also known as carding or card checking, is a type of payment fraud where criminals test the validity of stolen credit or debit card details. They use bots to submit a high volume of small transactions through a merchant's payment form. The goal is not to purchase goods but to identify which cards are "live" and can be used for larger fraudulent purchases elsewhere or sold on darknet marketplaces.

There are two primary forms of card testing:

  • Card number enumeration: Bots systematically generate and test sequential card numbers, often targeting a specific Bank Identification Number (BIN) range known to have lower security controls. This is also called a BIN attack.
  • Stolen card list testing: Fraudsters use lists of card details purchased from the dark web, which include the full card number, expiry date, and CVV. The bots cycle through this list on your site to see which ones are still active.

For each attempt, the bot analyses the response from the payment gateway. An approved transaction or a specific decline code (like "Insufficient Funds") confirms the card is valid. A "Do Not Honour" or "Invalid Card Number" response indicates the card is dead. The results are logged, and the list of live cards becomes a valuable asset for the fraudster.

Why subscription sites are prime targets

Subscription-based businesses are particularly attractive targets for card testing attacks for several reasons. Their business models often include features that, while great for legitimate customer acquisition, can be easily exploited by fraudsters.

Low-value initial transactions

Many subscription services, from SaaS platforms to creator content sites, offer free trials or low-cost introductory periods like a £1 first month. These require a card on file for validation and future billing. Fraudsters exploit these low-friction sign-ups because a small, £0 or £1 authorisation is less likely to be flagged by the cardholder or their issuing bank than a large purchase. This allows the card testing to fly under the radar.

Automated recurring billing

The core of the subscription model is automated billing. Once a card is on file and validated, it's stored for future payments. Fraudsters know that if they can get a stolen card successfully authorised once, it's vaulted in your system. This makes your site a perfect testing ground to validate cards for their own future use, without needing to complete a full, noticeable purchase.

Emphasis on conversion rate optimisation

Subscription businesses rightly focus on minimising friction at checkout to maximise conversions. This often means simplifying sign-up forms, removing CAPTCHAs, and not always enforcing 3D Secure on initial authorisations. While this helps genuine customers, it also removes the very barriers that could deter or block automated bot attacks. Fraudsters actively seek out these paths of least resistance.

The cascading costs of a card testing attack

The damage from a card testing attack extends far beyond the small transaction amounts. The true cost is a cascade of operational headaches, financial penalties, and reputational harm that can threaten your payment processing capabilities.

Authorisation and decline fees

Every transaction attempt, whether approved or declined, costs you money. Your payment processor and acquirer charge a small fixed fee for each authorisation request sent to the card schemes. During a bot attack involving tens of thousands of attempts, these fees accumulate rapidly. You end up paying for the privilege of being attacked.

Increased chargeback rates

Even if a £1 transaction is approved, the legitimate cardholder will eventually notice the unfamiliar charge and dispute it. This results in a chargeback. A sudden spike in chargebacks will increase your chargeback-to-transaction ratio, a key metric monitored by card schemes like Visa and Mastercard. This can lead to your business being placed in a monitoring programme.

Acquirer and scheme penalties

Acquirers and card schemes penalise merchants for excessive declines. High decline rates are a red flag for poor business practices or fraud, and they strain the network. If your decline rate spikes due to a card testing attack, your acquirer may impose hefty fines. In severe cases, they may place your merchant account under review or terminate it entirely, cutting off your ability to accept payments.

Visa and Mastercard have specific programmes to address this. For example, if your authorisation attempts are deemed excessive, you can face significant financial penalties from the schemes, passed on to you through your acquirer.

Practical defences against card testing

Defending against card testing requires a multi-layered approach that combines front-end checks with back-end payment logic. Relying on a single tool is insufficient; you need a system that can identify and block suspicious behaviour at multiple points in the payment flow.

Implement velocity rules and device fingerprinting

Velocity rules are your first line of defence. These are rules that limit the number of transaction attempts from a single source in a given timeframe. Effective velocity rules monitor multiple data points:

  • IP address: Limit attempts per IP address (e.g., no more than 5 attempts in an hour).
  • Email address: Limit sign-ups per email address. Bots often use disposable or nonsensical emails.
  • Card number: Limit attempts per card number to prevent repeated testing of the same stolen card.
  • Device fingerprint: This is more sophisticated than IP tracking. It creates a unique identifier for a user's device, allowing you to block a single machine even if it cycles through different IP addresses using a VPN or proxy network.

Use CAPTCHA and bot detection tools

While some merchants resist adding friction, a well-implemented CAPTCHA is highly effective at stopping basic bots. Modern tools like Google's reCAPTCHA v3 can analyse user behaviour in the background and only present a challenge to suspicious traffic, minimising disruption for legitimate customers. Integrating a dedicated bot detection service can provide an even stronger layer of security by analysing hundreds of behavioural signals to distinguish humans from automated scripts before they even reach your payment form.

Enforce 3D Secure strategically

Forcing 3D Secure on every transaction can harm conversion rates. A smarter approach is to use it dynamically. A payment orchestration platform can help you build rules that trigger a 3D Secure challenge only for suspicious transactions. For example, you could enforce Strong Customer Authentication for transactions originating from a high-risk country, or if a user's IP address doesn't match their billing address country, or if they have failed multiple previous attempts. This provides targeted security without penalising all of your customers.

Leverage smart payment routing

If one of your merchant accounts comes under attack, you risk having it shut down. Using smart payment routing through a multi-acquirer setup provides resilience. If an attack targets one acquirer, you can automatically redirect traffic to another, isolating the issue and keeping your business online. This also allows you to route suspicious transactions to an acquirer with stricter fraud filters, while sending trusted traffic to an acquirer optimised for higher approval rates.

Frequently asked questions

What is a BIN attack?

A BIN attack is a specific type of card testing where fraudsters target a Bank Identification Number (BIN), which is the first 6 to 8 digits of a card number. They systematically generate and test card numbers within that specific BIN range, hoping to find a sequence of valid, active cards issued by that particular bank.

Will a CAPTCHA stop all card testing attacks?

A CAPTCHA can stop most unsophisticated bots, but determined fraudsters use advanced scripts and even human-powered "CAPTCHA farms" to bypass them. It should be used as one layer in a wider fraud prevention strategy, not as your only defence.

Why do I get charged for declined transactions during an attack?

Your acquirer and payment processor incur a small cost every time they send an authorisation request to the card schemes (Visa, Mastercard, etc.), regardless of the outcome. This fee is passed on to you. During a card testing attack involving thousands of attempts, these small fees add up quickly.

How do card testing attacks affect my acquirer relationship?

Acquirers monitor your transaction metrics closely, especially your decline rate and chargeback ratio. A card testing attack causes both to spike dramatically. This signals to the acquirer that your site is a target for fraud, making you a higher-risk merchant. They may respond with fines, increased scrutiny, or even termination of your merchant account.

Can 3D Secure prevent card testing?

Yes, 3D Secure is an effective tool against card testing because most bots cannot complete the authentication challenge (e.g., entering a one-time code sent to a phone). However, forcing it on all users can lower conversion. The best practice is to apply 3D Secure dynamically, triggering it only for transactions that meet certain risk criteria.

How does payment orchestration help fight card testing?

A payment orchestration platform provides a central control panel to manage multiple fraud tools and routing rules. You can set velocity rules, integrate device fingerprinting, and build dynamic 3D Secure triggers. It also enables you to route suspicious traffic to different acquirers, containing an attack and preventing any single merchant account from being suspended.

Apply with Cardflo

Ready to improve your payments setup?

Tell us about your business. We'll match you with the right acquiring partners and the right route, typically inside a week.