Security · Payment Processing

Card testing is what happens when someone holding a list of stolen card numbers needs to know which ones still work. Rather than risk a large purchase, they run the numbers through a small online checkout, often thousands in an hour, usually for a dollar or two, and note which ones are approved. Stripe's documentation names the same activity "carding", "account testing", "enumeration" and "card checking". The store doing the checking is usually not the target. It is the tool.
For the merchant, the cost comes in three parts: fees on the declined attempts, refunds and disputes on the ones that were approved, and the attention of the card networks, which now count this activity against the business it happens to. How much of the first part you pay depends almost entirely on how your processor prices, and the processors do not all say.
Stripe's guide lists the symptoms: a spike in failed or blocked payments, a spike in API requests returning declines, and a run of small approved payments with nonsensical customer names and email addresses. WooCommerce's documentation describes the same thing from the store side: a wall of failed orders, often carrying several notes about cards being declined, because "it's common for card testers to attack a site with hundreds (or even thousands!) of stolen card numbers in a short period of time."
Testers favour two things: a guest checkout with no login, and any page that saves a card without charging it. Stripe notes that card setup is the method testers prefer, because a verification does not usually appear on the cardholder's statement, so the real owner is less likely to notice.
Every attempt, approved or declined, is an authorization request that travels from your processor through the card network to the issuing bank. The question is whether anyone bills you for the ones that fail.
On a flat-rate plan the fee is taken from a successful payment, so a decline has nothing to take it from. Stripe's US pricing page charges 2.9% + 30¢ "per successful transaction" for domestic cards online. Square's developer pricing page says the seller "pays only a single per-transaction percentage fee" covering interchange and everything else, with "no monthly charges or additional fees for payment processing". WooPayments, which runs on Stripe, says its fees "are deducted directly from each payment made via WooPayments". None of the three lists a charge for a declined card.
There is a caveat Stripe states itself: card testing "can result in additional fees, such as authorization fees for custom pricing plans". If you negotiated an interchange-plus or custom rate with Stripe, or with anyone else, the flat-rate answer no longer applies.
Authorize.net is the clearest case. Its Gateway only plan costs $25 a month plus 10¢ per transaction and a 10¢ daily batch fee, and its fee definitions say the per-transaction fee is charged on "charges, refunds, voids and declines". Ten thousand declined attempts are $1,000 in gateway fees before the processor behind the gateway charges anything. Its pricing page does not say whether the 30¢ in the All-in-one plan's 2.9% + 30¢ also applies to a decline, so ask before you assume either way.
Braintree publishes the same rule in a pricing article written for its Australian merchants: the per-transaction fee "is applied to all authorizations. This includes verifications, failed transactions, voids, and refunds." Its US fee schedule, which lists a 2.89% + 29¢ card rate for standard merchants, does not address declines at all. A US merchant on Braintree should get the answer in writing rather than rely on either document.
Under a flat rate the processor absorbs what the networks charge it. On an interchange-plus or pass-through plan those network fees are itemised on your statement, and some of them are charged per authorization, not per sale. Neither Visa nor Mastercard publishes its fee schedule. The most recent public copy we have found is Fiserv's spring 2023 pass-through schedule, which North Carolina's Office of the State Controller has posted publicly. It lists:
Those amounts are from 2023 and may have changed. On that Fiserv schedule they appeared as lines such as "VI Network Acq Proc Fee" and "MC Network Access Auth Fee". If lines like these jump in a month when your sales did not, card testing is a likely cause.
A tester only learns something when a card is approved, so some of the attempts will succeed. Each one is a real charge on a real person's card, and every guide on the subject says the same thing: refund them immediately, before the cardholder sees the charge and disputes it. WooCommerce calls this "critical to prevent disputes" and says WooPayments staff can issue bulk refunds when more than about 20 unauthorized orders went through. But a refund does not usually return the processing fee. WooPayments says plainly that transaction fees "are not refunded to you when you issue refunds", and most processors behave the same way, as our comparison of refund fees shows.
The ones you miss become disputes. Stripe charges a $15 dispute fee whatever the outcome, and Helcim, Braintree and WooPayments each charge about $15, as our chargeback fee comparison sets out. On a $1 test charge, that fee is fifteen times the sale.
Visa's Acquirer Monitoring Program, in the form that took effect in June 2025, tracks enumeration alongside fraud and disputes. Visa's fact sheet requires acquirers to take proactive steps to keep merchants below two enumeration thresholds: enumerated authorizations (approved and declined) making up 20% or more of all authorizations, and 300,000 or more enumerated transactions in a month. Few small merchants would reach 300,000. The bigger risk is the other side of the program. Approved test charges that cardholders report as fraud count in the VAMP ratio of fraud and disputes to settled sales, and the threshold for a US merchant was lowered to 1.5% on 1 April 2026. We explain the ratio in our guide to the chargeback monitoring programs.
There is a subtler cost as well. Stripe warns that a high decline rate can damage a business's reputation with issuers and networks, "which makes all of your transactions appear riskier", and that legitimate payments can see more declines even after the attack has stopped.
Visa and Mastercard also charge for retrying the same declined card too often. PayPal's May 2026 guide to the rules puts Visa's fee at $0.10 per domestic attempt ($0.25 cross-border) on any retry after a decline that means the issuer will never approve, and after 20 retries in 30 days on other declines. Fiserv's 2023 schedule gave the limit as 15. Mastercard charges $0.50 in the US for each retry beyond 10 in 24 hours or 35 in 30 days on the same card, merchant and amount. Visa, according to PayPal, matches retries on the same credential. Because testers usually cycle through many cards rather than hammering one, these fees mostly catch subscription businesses that retry failed renewals too aggressively. Stripe also warns against the reverse mistake: after an attack, do not keep retrying cards that the testers saved to fake customer accounts, "because this repeats the original attack".


