Card-Testing (Carding) Scams
Fraudsters with lists of stolen card numbers run floods of tiny charges through online checkouts to find which cards still work, then sell or spend the live ones. Cardholders see small mystery charges; merchants absorb the flood.
Last reviewed: 24 July 2026
What this scam is
Card testing, also called carding, is the step fraudsters take between stealing card numbers and actually profiting from them. A stolen list — bought on a criminal marketplace, harvested by a skimmer, or lifted in a data breach — is worthless if the cards are cancelled or invalid, so the numbers have to be checked. Automated bots and cheap scripts push each card through a real online checkout as a tiny authorisation, a small purchase, or a token donation, watching only for which ones are approved. Approved cards are flagged as live and become the valuable inventory: they get resold at a higher price or used for larger fraud elsewhere. The scam has two sets of victims at once. Cardholders, who never lost the physical card, see unexplained small charges appear. Merchants and nonprofits — especially any site with a simple, guest-friendly checkout or donation form — become the unwitting testing ground, hit by waves of micro-transactions, wasted processing fees, and chargebacks. The distinction that matters most is that card testing is reconnaissance, not the payoff; the tiny charge is a signal that a number is live, and the real loss usually arrives later.
How it works
Fraudsters point automated software at a checkout or donation page that accepts cards with minimal friction — no address check, no security-code check, no rate limiting, guest checkout allowed. The bot submits card after card in rapid succession, each for a trivial amount: a cheap product, a small donation, or a zero-value authorisation that simply asks the bank whether the card is good without capturing money. Declines are discarded; approvals are recorded as verified live cards. Because each attempt is small and spread across many card numbers, no single charge looks alarming to the cardholder, while the merchant sees an abnormal spike in traffic, authorisations, and declines from one page.
On the cardholder side, the live card is then sold on or used for a bigger unauthorised purchase, and the small test charge is often the only early warning. On the merchant side, the flood brings processing and gateway fees on every attempt, penalties for a high decline rate, and a later wave of chargebacks once real cardholders dispute the charges — sometimes enough to threaten the account's standing with its payment provider. Nonprofit donation forms are favourite targets precisely because they accept any amount from anyone.
Why this scam works
Card testing thrives on scale and smallness. Individually the charges are too tiny to trigger a cardholder's alarm or a bank's fraud hold, yet run across thousands of numbers they efficiently sort the dead cards from the live ones. Automation makes the whole operation cheap, so fraudsters can afford enormous volumes of failed attempts to find a handful of winners. Frictionless checkout culture helps them: businesses remove verification steps to boost conversions, and every removed check is a door left open. Donation forms accept arbitrary amounts from strangers by design, which is exactly what a tester needs. And because the damage is split — a dollar here for the cardholder, fees and chargebacks there for the merchant — neither victim feels a single dramatic loss that would prompt immediate action, so the testing often runs for a while before anyone reacts.
Common red flags
- A small, unfamiliar charge or authorisation you cannot match to any purchase you made
- Several tiny charges from the same or similar merchants appearing close together
- A larger unauthorised charge following days after a small mystery one
- For merchants, a sudden surge in authorisations paired with an abnormally high decline rate
- Many payment attempts from a few IP addresses, devices, or in sequential card-number order
- A spike of very small or identical-amount orders, especially on a donation form
- A wave of chargebacks arriving after an unusual burst of small transactions
Sanitized example messages
Illustrative, sanitized examples. Personal details are replaced with placeholders such as [phone number] and [fake link].
Card alert: a payment of 1.00 to an online store was authorised on your card ending 1234. Reply STOP if this wasn't you.
Thank you for your 2.00 donation. — a receipt for a gift you never made, from a charity you have never heard of.
Merchant dashboard notice: authorisation volume is 12x your daily average and your decline rate has spiked in the last hour.
Your bank: we've spotted unusual activity on your card and have temporarily blocked it. Please review your recent transactions.
How to verify before you act
For cardholders, treat any small, unrecognised charge as a possible live-card test, not a rounding error — check the merchant name, and if you cannot place it, contact your bank or card provider rather than waiting to see if more follows. Genuine pending authorisations from businesses you actually used will match a purchase you remember. For merchants, watch for the signature pattern rather than any one order: a sudden surge of authorisations, an abnormal decline rate, many attempts from few IP addresses or devices, repeated tries with sequential card numbers, and a spike of very small or identical-amount orders. Confirm suspicions in your payment processor's dashboard, which shows attempt and decline rates the storefront alone hides. The reliable test on both sides is volume and pattern: card testing looks like machinery, not a customer.
Payment methods used
- Credit card
- Debit card
- Prepaid cards
Who is usually targeted
- Cardholders
- Online merchants
- Nonprofits and charities
- Small businesses
What to do immediately
- Contact your bank or card provider as soon as you spot a charge you don't recognise, even a tiny one, and ask them to review the account
- Ask for the card to be cancelled and reissued, since the number itself is what has been compromised
- Check your statement for any further or larger unauthorised charges and dispute every one of them
- For merchants, contact your payment processor to report suspected card testing and ask about blocking rules and fee relief
- Enable or tighten verification checks, rate limiting, and bot protection on your checkout or donation form right away
- Turn on real-time transaction alerts so any future charge is flagged to you the moment it happens
How to prevent it
- Treat every unexplained small charge as a warning sign and check it with your bank promptly, rather than ignoring it because it is minor
- For merchants, enable address verification and card security-code checks, and require them to pass before a payment is accepted
- Add rate limiting, bot detection, and CAPTCHA to checkout and donation forms to stop rapid automated attempts
- Set a minimum donation or purchase amount and monitor your processor's authorisation and decline rates for sudden spikes
- Use your card provider's transaction alerts so any charge, however small, notifies you instantly
- Keep card details out of reach by using virtual or single-merchant card numbers where your bank offers them
Evidence to preserve
- Statements or app screenshots showing the small charges, with dates, amounts, and merchant names
- Any bank or card-provider alert messages about the transactions
- For merchants, payment-gateway logs showing attempt volumes, decline rates, IP addresses, and timestamps
- Records of any resulting chargebacks and the disputed transaction references
Where to report it
- Action Fraud (UK) — UK national fraud & cybercrime reporting centre
- FTC ReportFraud (US) — US Federal Trade Commission fraud reports
- FBI IC3 (US) — US Internet Crime Complaint Center
- Scamwatch (Australia) — Australian competition & consumer reporting
- Your bank's fraud line — Use the number on the back of your card or in your banking app — never a number the caller gives you
Always verify reporting routes and emergency contacts on the official government or agency website for your country.
Frequently asked questions
I only see a tiny charge I don't recognise — is it worth worrying about a dollar?
Yes. A small unexplained charge is one of the clearest early signs that your card number has been stolen and is being tested to confirm it still works. The amount is kept trivial precisely so you will shrug it off. Once a card is confirmed live, it is often sold on or used for a much larger unauthorised purchase. Contact your bank, and ask them to cancel and reissue the card — replacing the number is what actually stops the fraud.
Why is my charity's donation page suddenly getting flooded with tiny donations?
That pattern is classic card testing. Donation forms accept any amount from anyone with no product to ship, which makes them an ideal place for a bot to check stolen card numbers a dollar or two at a time. You will typically see a surge of attempts, a high decline rate, and later a wave of chargebacks. Add rate limiting, bot detection, address and security-code checks, and a minimum donation amount, and contact your payment processor, which can help block the traffic.
The card was never out of my possession, so how was it tested?
Card testing almost never involves your physical card. Fraudsters work from lists of card numbers obtained through data breaches, skimming devices, phishing, or purchased on criminal marketplaces, then check them through online checkouts where only the number, expiry, and sometimes the security code are needed. Your card can be sitting safely in your wallet the entire time. Because the exposure is of the number itself, the fix is to have the card reissued with a new number rather than simply watching the account.