Criminals use small online stores to find out which stolen cards still work. Every attempt goes through your payment account, and too many failed payments can get that account restricted or closed. We put protection in front of your checkout, so bots are stopped before they reach your payment provider.
Card testing, also called carding, is a type of fraud where criminals check stolen card details by making small payments on real websites. A script fills in your checkout again and again, each time with a different card. Most payments fail. The few that go through tell the criminals which cards are still active.
The cards were not stolen from your store. Your store is simply the tool used to check them, and you are the one who pays for it.
Card details stolen in data breaches, by phishing and by malware are sold in large lists. Many cards in a list are already blocked or expired, so buyers need to know which ones still work.
Scripts search for stores with guest checkout, cheap products or donation forms with a free amount, and no limits on payment attempts.
It adds the cheapest item to the cart and pays with one card after another, often from many IP addresses, so the orders look like they come from different shoppers.
Each attempt goes to Stripe, PayPal or your bank. Most are declined and a few are approved, and every result is recorded against your merchant account.
Cards that pass are used for large purchases elsewhere or sold again at a higher price as "checked" cards.
They do not want your products. They want a checkout that lets them try many cards quickly without being stopped.
Large stores have fraud teams and strict limits. Many small stores accept any number of payment attempts from anyone.
A small charge rarely makes a cardholder call the bank, so the card stays active for the real fraud later.
No account, no login, no limits. Donation forms and gift vouchers with a custom amount are especially popular.
Many shop platforms have background routes that accept orders without loading the checkout page. Bots use them to skip protection added to the page itself.
One script can try hundreds of cards an hour and change its IP address every few attempts. Others test slowly for weeks to stay unnoticed.
Attacks often start at night or at the weekend, when nobody checks new orders until the damage is done.
Especially stores with low-price products and guest checkout.
Forms where the donor chooses the amount are a favorite target.
A voucher page is often the only place on the site that takes card payments, and nobody watches it closely.
Sign-up forms that check a card for a free trial or a first payment.
Cheap tickets and many small orders make an attack easy to miss.
Forms that save a card for recurring billing let criminals check a card without charging it.
The cards are not yours, but the payment account is. This is what usually follows an attack.
Payment providers watch how many of your payments are declined or disputed. A sudden jump looks like fraud on your side. The provider can review your account, hold your payouts, limit payments or close the account, and a closure for fraud can make it harder to open a new merchant account.
Depending on your provider and plan, you can be charged for authorization attempts, including declined ones. Test payments that go through are often disputed by the real cardholder, and each dispute usually comes with a fee.
Successful test payments have to be found and refunded quickly. Those you miss turn into fraud reports and disputes that count against your account.
Banks start to see your store as risky. Even after the attack stops, more payments from genuine customers can be declined.
A long or large attack can put your account into the card networks' monitoring programs, with extra fees and stricter rules.
Hundreds of failed order emails, fake orders holding stock or bookings, a website slowed down by bot traffic, and hours spent cleaning up and talking to your payment provider.
Every attack is different, but most follow one of these patterns.
A small gift shop wakes up to hundreds of failed orders for its cheapest item, all placed between 2 and 5 a.m. A few payments went through. The payment provider holds the payouts while it reviews the account.
A local charity's donation form receives hundreds of tiny donations in an hour, each from a different card. Weeks later, the ones that went through come back as disputes, each with a fee.
An event ticket website gets a few payment attempts a week from the same visitor, each with a new card. Nobody notices until the payment provider asks about the rising number of declines.
Seeing this right now? Contact us and we will help you stop the attack.
Stripe, PayPal and other providers have their own fraud filters, but they see a payment only after it leaves your website. Our protection works on your website, before card details are sent to the provider. Several layers work together, because a single rule, such as blocking one IP address, is easy for bots to get around.
Every payment attempt has to pass a check that tells people and bots apart. Real customers do not solve puzzles. Scripts are stopped before the payment is sent.
Too many attempts or failed cards from one visitor in a short time trigger a pause. Limits are set for your store, so a real customer can still retry a mistyped card.
We protect the checkout page, the background routes that can create orders without it, the "add payment method" page in customer accounts, and your payment and donation forms.
Our website firewall blocks the IP addresses and networks taking part in an attack across your whole website.
If failed payments jump, you and our team get an alert, so you know about an attack while it is happening, not at the end of the month.
We install and configure the protection for your platform and payment provider, test it and keep it up to date. No code changes on your side.
We have ready solutions for all popular platforms and shop extensions. For anything else, we integrate the protection on request.
WooCommerce, Easy Digital Downloads, WP Simple Pay, GiveWP, MemberPress, Paid Memberships Pro, and payment forms in WPForms and Gravity Forms
VirtueMart, HikaShop, J2Commerce (formerly J2Store) and JoomShopping
Magento Open Source and Adobe Commerce
OpenCart 3 and 4
PrestaShop 1.7, 8 and 9
Drupal Commerce
Shopware, CS-Cart, WHMCS and custom-built stores: on request
Payment providers: Stripe, PayPal, WooPayments, Square, Braintree, Authorize.net, Mollie, Worldpay and others. The protection works on your website, so it does not depend on the provider.
Card Testing Protection is included in both plans, together with malware scanning, the website firewall and our other security features.
Let us know your platform and payment provider and send us access details. Already on Premium or Business? Just contact our support.
Our engineer installs and tests the protection and turns on alerts. Your checkout keeps working as usual for real customers.
Card Testing Protection is not sold on its own. It is included in our Premium and Business security plans, together with everything else that keeps your website safe.
Card testing is fraud where criminals check stolen card details by making small payments on real websites. They use the results to find the cards that still work, then use or sell those cards elsewhere.
Because it is small. Criminals look for checkouts with no limits and nobody watching. They do not need your products, only a place to try cards quickly.
Providers like Stripe and PayPal block many fraudulent payments, but they only see a payment after it leaves your website, and the attempts that reach the banks still affect your account. Stripe's own guide on card testing recommends adding protection on the website itself, such as a CAPTCHA and rate limits. That is what we do.
No. Real customers check out as usual and do not solve puzzles. Limits are set so that a customer who mistypes a card number can try again.
WordPress (WooCommerce, Easy Digital Downloads, payment and donation forms), Joomla (VirtueMart, HikaShop, J2Commerce, JoomShopping), Magento, OpenCart, PrestaShop and Drupal Commerce. For other platforms and custom-built stores, we integrate the protection on request.
Yes. The protection works on your website before the payment request is sent, so it works with Stripe, PayPal, WooPayments, Square, Braintree, Authorize.net, Mollie, Worldpay and other providers.
Yes. Providers measure your declines, fraud reports and disputes. A card testing attack raises declines at once, and fraud reports and disputes follow. The usual first steps are a review and held payouts, and if the problem continues, the provider can limit or close the account.
Contact us straight away and we will help you stop it. Refund any test payments that went through, so they do not turn into disputes, and let your payment provider know you are dealing with the attack.
Contact our support with your website address, platform and payment provider. Our engineer will set up the protection and let you know when it is active.
No. Card Testing Protection is included in Premium and Business only. You can upgrade your plan at any time.
No. The protection works on your website. On the Business plan, we review your provider's fraud settings together with you, and you stay in control of the account.
Card testing can start on any day and on any store. Premium and Business include Card Testing Protection, set up by our engineers.