175% Increase in Card Testing Attacks: Why Retailers Must Prepare for Carding Fraud

October 2, 2026

Carding fraud is becoming faster and more automated, making it harder forCarding fraud is becoming faster and more automated, making it harder for retailers to separate legitimate shoppers from coordinated fraud attempts. retailers to separate legitimate shoppers from coordinated fraud attempts.

A few low-dollar transactions probably aren't enough to make a retailer hit the panic button. But when those transactions start showing up in large numbers, along with repeated payment declines and unusual checkout activity, they could be a sign of something bigger: card testing.

According to Signifyd's 2026 State of Fraud Report, card testing attacks increased 175% year over year during the first four months of 2026. Overall ecommerce fraud pressure also increased 33%, while account takeover attempts rose 78%.

For retailers, that makes it worth taking a closer look at what card testing actually looks like, how these attacks work, and what can be done to spot suspicious activity before it turns into a bigger fraud problem.

What Is Carding Fraud & Card Testing?

Let's start with the basics.

Carding fraud is when someone uses stolen payment card information to make unauthorized purchases or obtain something of value.

Card testing is often one of the first steps. Instead of immediately trying to make a large purchase, fraudsters test stolen card details with small or low-value transactions to see which ones work. These attempts can include $0 authorizations, small purchases, or other low-dollar transactions.

The idea is pretty simple: find the cards that work, then figure out how to use them.

Card testing can be done manually, but fraudsters increasingly use automated tools to submit large numbers of payment attempts quickly. That means what looks like a handful of insignificant transactions to a retailer could actually be part of a much larger operation.

What Happened: Card Testing Attacks Increased 175% in 2026

The 175% increase in card testing attacks comes from Signifyd's 2026 State of Fraud Report, which compared activity during the first four months of 2026 with the same period in 2025. The report also found that overall ecommerce fraud pressure increased 33% year over year, while account takeover attempts rose 78%.

The numbers point to a broader shift in the way online fraud is being carried out. Fraudsters aren't necessarily relying on one tactic at a time. They can combine stolen payment credentials, automated bots, account takeovers, and other methods at different points in the customer journey.

For retailers, that means looking at more than just whether an individual transaction went through. The patterns surrounding that transaction can matter just as much.

How Carding Fraud Works

So, what does a carding attack actually look like? While tactics can vary, the process often follows a few basic steps.

Step #1: Collect Cards & Card Details

First, fraudsters need payment credentials to test. Stolen card information can come from data breaches, phishing attacks, digital skimming, compromised accounts, or other sources.

Once fraudsters have enough card details, they can move on to testing them.

Step #2: Test the Cards

This is where card testing comes in.

Fraudsters submit transactions using large batches of stolen card details. They may use $0 authorizations, small purchases, or other low-value transactions to determine whether a card is active without immediately attempting a large transaction.

Automation makes this process much faster. Instead of testing a few cards at a time, fraudsters can potentially run large numbers of attempts in a short period.

Step #3: Identify the Working Cards

Next, fraudsters look at the results.

Declined cards can be set aside while successful authorizations may indicate which payment credentials are still usable. Those working cards can then become targets for additional fraudulent activity.

Step #4: Use or Monetize the Validated Cards

Once working card details have been identified, fraudsters can attempt larger purchases or potentially sell the validated credentials to other criminals.

In other words, the small test transaction isn't necessarily the end goal. It can be a way for fraudsters to figure out which stolen cards are worth pursuing.

How Carding Attacks Hit Retailers: Common Tactics

Carding attacks don't just create a problem for the person whose card was stolen. Retailers can feel the impact, too.

Increased Declined Transactions

A fraudster cycling through large numbers of stolen cards can create a noticeable spike in declined transactions. The mix may include active cards, inactive cards, canceled cards, or cards that have already been reported as stolen.

A sudden increase in payment failures can be an early warning sign that something unusual is happening.

Payment Processing Costs

Even unsuccessful attempts can create additional payment processing activity. When large numbers of authorization requests are submitted in a short period, those transactions can add costs and create extra work for retailers and their payment partners.

The exact impact will depend on the retailer's payment setup and processor.

Chargebacks

Sometimes a stolen card does make it through.

If the legitimate cardholder later notices and disputes the transaction, the retailer may face a chargeback. Beyond the financial impact, chargebacks can also mean additional time spent investigating transactions and resolving disputes.

Fraud-Monitoring Problems

Here's where things can get tricky.

A legitimate customer might make a small purchase, use a new device, or have an address that doesn't match their billing information. None of those things automatically mean fraud.

The challenge is separating those normal behaviors from the same signals appearing repeatedly or in unusual combinations.

Bot-Driven Micro-Transactions

Bots can submit large numbers of small transactions in a very short period. Because each individual transaction may be low value, the activity can be easy to overlook if retailers aren't watching for patterns across transactions.

Gift Card and Stored-Value Abuse

Gift cards and other stored-value products can also attract fraudsters because they can provide a relatively quick way to turn stolen payment credentials into something of value.

A fraudster may use a compromised card to purchase a gift card or other stored-value product and then use or resell it.

Who's Being Targeted?

Carding fraud can affect many businesses that accept card-not-present payments, but some are particularly exposed to this type of activity.

Ecommerce Stores

Online checkout gives fraudsters an easy environment for testing payment credentials, particularly when automated tools can submit large numbers of attempts quickly.

Gift Card Retailers

Gift cards and other stored-value products can be attractive targets because they can potentially be converted into value quickly.

Looking for more on gift card fraud? Explore common gift card scams and warning signs.

Digital Subscription Businesses

Subscription businesses can also face card testing attempts because their checkout and payment processes are often automated, giving fraudsters another opportunity to test stolen credentials.

Warning Signs of Carding Fraud for Retailers

One unusual transaction doesn't necessarily mean a retailer is dealing with fraud. It's the combination of signalsβ€”and how often they appearβ€”that can tell a bigger story.

Keep an eye out for:

  • Multiple low-value transactions within a short period
  • Numerous failed payment attempts
  • High transaction velocity from the same device or internet protocol (IP) address
  • Multiple cards being used with the same customer account
  • Different names, addresses, or email addresses connected to similar payment activity
  • Unusual or repetitive checkout behavior
  • Suspicious device or browser fingerprints

For example, one customer making a small purchase isn't particularly unusual. But dozens of small purchases using different cards from the same device in a matter of minutes? That's a very different pattern.

Carding is only one piece of the fraud puzzle. Explore other ecommerce fraud risks
and how they can affect your business.

How Retailers Can Prevent and Respond to Carding Fraud

There’s no single step that will stop every carding attack. Instead, retailers can use a combination of payment controls, transaction monitoring, and fraud detection tools to spot unusual activity and step in when something doesn't look right.

These fraud detection methods can help retailers take a closer look at the signals behind a transaction, not just the transaction itself.

Here are some ways retailers can strengthen their approach:

Monitor Unusual Payment Patterns

Start by paying attention to what's changing. A sudden jump in transaction volume, declined payments, low-dollar purchases, or unusual customer behavior could be worth a closer lookβ€”especially when several of these signs show up together.

Set Limits on Payment Attempts

If the same account, device, or source is making a large number of payment attempts in a short period, setting limits can help slow down automated testing and prevent an attack from continuing unchecked.

Implement CAPTCHA

CAPTCHA can add another layer of protection by helping distinguish real shoppers from automated bots. It can be especially useful when unusual activity is detected during checkout.

Use Fraud or Bot Detection Tools

Fraud and bot detection tools can look beyond the transaction itself. Depending on the solution, they may consider device information, customer behavior, network activity, and transaction patterns to help flag activity that looks unusual.

Use Velocity Analysis

Sometimes, how quickly something happens can be just as telling as what happens. Velocity analysis looks at the frequency and speed of transactions or other actions.

For example, a large number of payment attempts from the same device or account within a few minutes could signal that something deserves a closer look.

Use AVS and CVV Matching Enforcement

Address verification service (AVS) and card verification value (CVV) checks can provide additional signals when evaluating card-not-present transactions. Retailers can work with their payment partners to determine which verification rules make sense for their business and risk level.

Monitor Low-Value Transactions

A small purchase isn't automatically a red flag. But when a retailer suddenly sees a wave of low-dollar transactionsβ€”particularly alongside repeated declines or other unusual activityβ€”it may be time to take a closer look.

Report Suspicious Activity to Your Payment Processing Partner

Think you may be dealing with a card testing attack? Don't try to figure it out alone. Your payment processing partner may be able to help identify what's happening and provide additional guidance, monitoring, or controls.

Consider Age & ID Verification for High-Risk Categories

For retailers selling age-restricted products, age and ID verification can add another layer of protection by helping confirm that a customer meets the applicable age requirements.

It shouldn't replace payment fraud controls, but for higher-risk purchases, it can be another useful part of the verification process.

Payment fraud isn't the only risk retailers have to think about. See how identity verification fits in
when businesses are working to reduce fraud.

Staying Ahead of Carding Fraud

Carding attacks can start with transactions worth only a few dollarsβ€”or even less. But those small transactions may be an attempt to figure out which stolen payment credentials are still usable.

With card testing attacks up 175% during the first four months of 2026, it's worth looking beyond individual transactions and paying attention to the bigger picture.

Are payment attempts suddenly increasing?

Are multiple cards being used from the same device?

Are low-value transactions showing up alongside a high number of declines?

Those patterns can tell retailers much more than any one transaction on its own.

The goal isn't to make legitimate customers jump through extra hoops. It's about using the right signals and controls to catch suspicious activity while keeping checkout straightforward for the people who are actually there to shop.

As carding tactics continue to evolve, knowing what to watch forβ€”and having a plan for when something doesn't look rightβ€”can help retailers respond more confidently when an attack comes their way.

Help Us Track Scams and Fraud. Report to FTx Identity.

Submit scam or fraud details you’ve noticed so we can warn the retail community and their shoppers, supporting awareness and prevention efforts.