Skip to content
Will your site survive Black Friday? Free peak-readiness audit →
SECURITY

How to stop card-testing attacks on your checkout

How fraudsters use your checkout to test stolen cards, the warning signs, and the controls that stop card testing before your payment account is at risk.

By VISIBI Security team·Reviewed by Saeed Ak, Co-founder & CTO·Updated 29 September 2026·7 min read
QUICK ANSWER

How fraudsters use your checkout to test stolen cards, the warning signs, and the controls that stop card testing before your payment account is at risk.

KEY TAKEAWAYS
✓Card testing uses your checkout to validate stolen cards with small transactions.
✓It can lead to fees, chargebacks and payment account suspension.
✓Combine edge protection, checkout controls and gateway fraud tools.
INTERACTIVE CHECKLIST
Card-testing defence checklist
0 of 7 done0%

Warning signs

  • Spikes in failed or tiny payments
  • Many different cards from similar IPs
  • Orders with random names and emails
  • Payment provider alerts
RELATED GUIDEHow to stop spam and bot attacks on Adobe Commerce Cloud → Stop bots and card testingEdge and platform protection without annoying customers.Get a free bot audit →

How to stop it

  • Rate-limit payment and order endpoints
  • Invisible reCAPTCHA or Turnstile on checkout
  • Enable gateway fraud tools (Radar, RevenueProtect)
  • Block data-centre and high-risk IP ranges
  • Require minimum order values during attacks

Common mistakes to avoid

✕Waiting until after a breach to act
✕Restoring a backup without fixing the entry point
✕Leaving old plugins, extensions and admin users in place
✕Relying on a single tool instead of layered defences
HOW VISIBI CAN HELP

How we help with security

01ScanFree scan for malware, vulnerabilities and blocklisting.
02Clean & patchEngineers remove threats and close the entry point.
03HardenWAF, 2FA, least privilege and platform hardening.
04MonitorContinuous scanning with unlimited cleanups on our plans.
Get a free bot audit →Free · No obligation · Reply within 24 hours

Frequently asked questions

Will this block real customers?

Invisible checks and rate limits rarely affect genuine shoppers.

How fast can you help?

We can usually stop an active attack the same day.

Which platforms?

Magento, Adobe Commerce, WooCommerce, Shopify and custom checkouts.

SA
Reviewed by Saeed Ak · Co-founder & CTO25 years engineering high-traffic ecommerce, cloud and security platforms. Written by the VISIBI Security team.Meet the team →
Was this guide helpful?
Share:LinkedInXEmail
RELATED SERVICES

Keep reading

SECURITY · 9 MINHow to stop spam and bot attacks on Adobe Commerce CloudRead →SECURITY · 9 MINWordPress security checklist: 15 steps to protect your site in 2026Read →SECURITY · 8 MINMagecart and card skimming: how to protect your checkoutRead →
FREE · NO OBLIGATION

Stop bots and card testing

Edge and platform protection without annoying customers.

Get a free bot audit →Talk to a specialist
✓ Senior specialist, not a bot✓ Reply within 24 hours✓ Clients in 18 countries
SECURITY SCAN PREVIEWEXAMPLE
What attackers can see right now
Unpatched vulnerabilities6
Unknown checkout scripts2
Blocklist statusClean
Your free review shows your real numbers.