Community
Recent reports by acquiring banks have identified a surge in card testing attacks detected on merchant sites during this pandemic year. As ecommerce volumes increase and new businesses move online, it is crucial to be aware of card testing fraud, and learn how to identify and prevent it.
What is Card Testing?
Payment Card Testing is an advanced operation, employed by fraudsters to determine whether stolen or computer-generated card numbers are valid. Card testers exploit targeted organisations or sites, particularly those that accept donations or deal with small value transactions. Still, small and medium sized businesses are often vulnerable to card testing attacks because they tend to lack the resources and tools to detect or prevent these attacks.
Since these cards may have been stolen some time ago, fraudsters developed card testing as a method to verify whether cards have expired or have been reported and blocked by banks, – or as they hope, are still effective to use. The initial “testing” of cards is intended to confirm the validity of the card, and not for the purpose of purchasing the product or service – before larger transactions or purchases are made. If card numbers are valid, automated payment responses will be approved, giving the greenlight for card testers to rake in the big purchase or resell these verified numbers on the dark web; and if declined, these card numbers are filtered out.
Card Testing Techniques
Firstly, Card Testing numbers are obtained generally through one or two ways: by illegal purchasing of stolen card numbers via the dark web, or computer-generated random card numbers. Nevertheless, both methods require ‘testing’ of the card numbers to determine its validity before making larger purchases or online transactions. Transactions of low amount are then tested (e.g., making a small donation), with the intention to avoid alerting the cardholder who may in turn, immediately block the card or report card fraud when aware. Fraudsters inventively exploit payment authorization to verify card numbers and is a preferred method as it provides real time authentication and will not be visible in card statements until weeks later.
Because manual card testing is tedious, and can be extremely time consuming when testing large batches of card numbers, fraudsters utilise bots or a system of computers to automate card testing on a large scale. These bots attempt small transactions on websites, automated at high volumes.
Impact of Card testing
Card testing can be detrimental to ecommerce, especially small to medium sized businesses. Due to the large scale of transactions processed as a result of card testing, unfortunate businesses targeted by card testing attacks suffer:
How to Identify Card Testing
Card Testing attacks on websites can be identified by a number of signs:
Preventing Card Testing
Preventing card testing attacks is crucial to every online business or website. By eliminating unrestricted access and adding security measures, this can significantly reduce the risk of card testing attacks on websites.
Here are a several strategies that can help to prevent card testing attacks:
To avoid further financial and reputational repercussions, merchants should make effort to refund fraudulent transactions when possible, to maintain customer satisfaction and reduce opportunities for disputes. Merchants should also proactively re-evaluate and develop their detection parameters or payment security procedures to minimise website vulnerability and protect their businesses from card testing fraud.
The Next Steps
Payment Card Testing on websites is becoming more prevalent today, as fraudsters are moving online and continuously developing their schemes. To protect your online business or your merchants from card testing attacks, it is crucial to employ fraud tools and utilise comprehensive payment service providers that cover detection and prevention of card testing attacks. Using advanced online payment and fraud solutions help protect you and your business not only from card testing attacks, but also the many types of fraud that exist today.
This content is provided by an external author without editing by Finextra. It expresses the views and opinions of the author.
David Smith Information Analyst at ManpowerGroup
20 November
Konstantin Rabin Head of Marketing at Kontomatik
19 November
Ruoyu Xie Marketing Manager at Grand Compliance
Seth Perlman Global Head of Product at i2c Inc.
18 November
Welcome to Finextra. We use cookies to help us to deliver our services. You may change your preferences at our Cookie Centre.
Please read our Privacy Policy.