Card-Testing (Carding) Scams on Online Checkouts
Fraudsters aim automated bots at online checkout and payment forms, pushing floods of stolen card numbers through as tiny charges or zero-value authorizations to sort the live cards from the dead ones.
Part of: Card-Testing (Carding) Scams
Last reviewed: 24 July 2026
The online checkout is where card testing actually happens. A stolen card number is just data until a real payment form confirms it still works, and a public checkout does exactly that on demand: enter a number, get an approve-or-decline answer in seconds, for free or a few cents. Fraudsters point automated scripts at any checkout that accepts cards with little friction, then read the yes/no responses to build a list of live cards to resell or spend later.\n\nTwo victims share the same page. Cardholders see a tiny mystery charge they never made; the merchant, nonprofit, or platform hosting the checkout absorbs a flood of attempts, fees, and later chargebacks.
How this scam works on online checkouts
Bots target the specific weak points of a checkout: guest checkout with no login, no address (AVS) or security-code (CVV) requirement, no rate limit, and a form that reveals exactly why a card declined. The classic pattern is a BIN attack — the script takes one valid card prefix and machine-guesses thousands of card numbers, expiries, and CVVs, firing each through the checkout as a low-value order, a token donation, a gift-card top-up, or a zero-dollar authorization that asks the bank \"is this card good?\" without capturing money.\n\nApprovals get logged as live cards; declines are discarded. To stay under thresholds, attempts are spread across many IPs, rotating email addresses, and headless browsers, often burst overnight. Donation forms, subscription sign-ups, and \"add store credit\" endpoints are favored because they accept any amount from any stranger. Merchants often first notice it as an unexplained spike in authorizations paired with a soaring decline rate from a single page.
Common red flags
- A small, unfamiliar charge or a zero-dollar authorization on your statement that matches no purchase you made at any online store
- A larger unauthorized charge appearing days after a tiny mystery one from an unknown merchant
- For merchants: a sudden surge in authorization attempts on one checkout or donation page paired with an abnormally high decline rate
- Many attempts using sequential or same-BIN card numbers, or the same amount repeated hundreds of times
- Traffic concentrated on a guest checkout, donation form, or gift-card endpoint from few devices but many rotating card numbers
- A wave of chargebacks arriving shortly after an unusual burst of tiny transactions
- Payment attempts clustered at odd hours from headless browsers or mismatched billing and shipping details
How to protect yourself
- As a cardholder, treat any small unexplained charge or authorization as a possible live-card test and ask your bank to cancel and reissue the number, not just refund the charge
- For merchants, require AVS and CVV to pass before a payment is accepted, so a bare stolen number alone cannot get an approval
- Add rate limiting, bot detection, and CAPTCHA or a challenge to checkout, donation, and account-creation forms to break automated bursts
- Set a minimum purchase or donation amount and disable or gate low-value and zero-dollar authorization paths bots exploit
- Monitor your payment processor's dashboard for authorization spikes and decline-rate surges, which the storefront alone hides
- Turn on real-time card alerts and use virtual or single-merchant card numbers for online purchases where your bank offers them
How to report it
- Contact your bank or card issuer the moment you spot an unrecognized charge, however tiny, and request the card be cancelled and reissued
- For merchants, report suspected card testing to your payment processor or gateway and ask about velocity rules, blocking, and fee relief
- File a complaint with the FTC at reportfraud.ftc.gov, or your country's consumer protection or cybercrime agency
- Report card fraud crossing borders to IC3.gov if you are in the US
- Preserve statements, alerts, and (for merchants) gateway logs of attempt volumes, decline rates, IPs, and timestamps as evidence
Frequently asked questions
A store I've never used shows a tiny charge or a $0 authorization — why?
Your card number was almost certainly run through that store's online checkout to test whether it still works. The amount is kept trivial, or zero, precisely so you shrug it off. A checkout returns an instant approve-or-decline answer, which is all a fraudster needs to confirm the card is live before reselling it or making a bigger purchase. Contact your bank and have the card reissued with a new number — replacing the number is what actually stops it.
My checkout or donation page is suddenly flooded with tiny failed payments. What's happening?
That is the signature of a card-testing bot attack running against your checkout. A script is machine-guessing card numbers and firing each through your form as a low-value order or donation, keeping the approvals. You'll see an authorization spike, a high decline rate, and later chargebacks. Require AVS and CVV, add rate limiting and bot detection, set a minimum amount, and contact your payment processor, which can help block the traffic.
Why do fraudsters use my checkout instead of testing cards some other way?
A public online checkout is the cheapest, fastest verification tool available: it accepts card details from anyone, needs no account, and returns a real bank approve-or-decline response in seconds. Checkouts built for easy conversion — guest checkout, no address or security-code check, no rate limit — hand bots exactly the frictionless yes/no they need. Every verification step a merchant removes to speed up buying is a door a card tester walks through.