cardvera
Get started →
Sample assessment Illustrative data · fictional merchant
Threat analysis · Card-testing incident · Severity: high

Distributed card-testing attack on the Harbor & Pine Outfitters checkout.

A single operator used the store's guest checkout as a free validation service for stolen card numbers — and the campaign escalated 589% overnight.

Incident window · Day 1–Day 2  ·  Source · 2 gateway exports (1,420 authorizations)

Across two days, an automated script pushed 1,420 card-testing attempts through the checkout. It carried card numbers and expiry dates only — no security code, no billing address — and used the live authorization response to sort dead cards from live ones. It found roughly 38 live cards, and the gateway's velocity rule never fired.

Test attempts
1,420
Over two days, one endpoint.
Day-two jump
+589%
180 → 1,240 attempts.
Live cards harvested
~38
47 approved authorizations.
Median gap, day two
9s
Unattended, 01:00 – 06:50.

Read the full sample assessment

The timeline, the anatomy of the attack, what it cost, and why the existing controls missed it. Enter your work email to keep reading.

No spam. No drip campaigns.

01 — The escalation

A daytime probe, then a full automated run.

Day one looked like reconnaissance: 180 attempts spread across the afternoon. The operator came back the next night with 7× the volume, compressed into the early hours and fired 9 seconds apart. That's a script iterating, not a person.

MetricDay 1Day 2Change
Test attempts1801,240+589%
Active window13:00 – 19:0001:00 – 06:50overnight
Median gap between tries34s9s4× faster
Distinct BINs27fanned out
Approved (live cards found)641+583%
Attempts by hour — Day 1 afternoon burst · human-paced
00h 12h 23h
Attempts by hour — Day 2 early-hours ramp · machine-paced
00h 12h 23h

Shared y-axis · peak 268 attempts per hour.

02 — Anatomy of the attack

Every fingerprint points to scripted card validation.

Card number + expiry only

The security-code check fails or isn't processed, and address verification is unavailable on nearly every attempt. The operator has card numbers, not full stolen profiles.

Flat $4.99, every time

The store's cheapest item, bought as a guest. Small enough to pass unnoticed, large enough to confirm a real authorization.

One endpoint, guest checkout

Every attempt hit the same guest-checkout path with a fresh session, skipping the account flow entirely.

BIN concentration, then a pivot

Day one used 2 BINs. Day two fanned out to 7 — and the approvals clustered on two of them, so the operator found "good" ranges and leaned in.

03 — They are succeeding

3.3% of attempts approved. That's the attacker's yield, not noise.

Card testing isn't measured in dollars stolen from the store. It's measured in validated cards. Every approval is a live card the operator can now resell or use elsewhere.

Sample of confirmed live cards — Day 2 (masked)
03:41424242••••1881$4.99APPROVED
04:06400000••••3063$4.99APPROVED
04:52555555••••4444$4.99APPROVED
05:17222300••••7296$4.99APPROVED
What the two days cost in fees (Visa rails, $0.25 gateway fee)
Gateway + processor auth fees1,420 × $0.25$355
Visa APF1,420 × $0.0195$28
Visa Misuse of Auth47 × $0.15$7
Total$390

The fees are the smallest part. 1,373 declines in two days drag down the approval rate that the processor and the card networks watch, and every approved test that's later disputed adds a chargeback. The real victims are the ~38 cardholders whose cards are now validated for resale.

04 — The control that failed

A velocity rule was in place — and never fired.

The gateway blocked any IP making more than 25 attempts an hour. The attack spread across 312 IP addresses and never sent more than 6 from any one of them. A per-source threshold can't see a cross-source pattern: 1,240 attempts across 7 BINs in under six hours.

05 — Where Cardvera fits

Every signal here is detectable before the authorization hits the network.

Velocity across sources

Sub-10-second submissions sustained for hours, measured across the whole checkout rather than per IP.

BIN clustering

Dozens of cards sharing a handful of six-digit prefixes — the hallmark of a BIN attack.

Auth profile

Security code never matching, address never available, amount fixed at $4.99. No real customer base looks like this.

Session behavior

Fresh guest sessions that fill the form at machine speed and never browse — caught before the card is ever charged.

About this sample: the merchant and every figure on this page are fictional, and the masked cards come from public test ranges. Real assessments are built from your own gateway exports, with card numbers masked to BIN + last 4, and they're shared only with you.

Been hit? Get one of these for your attack — free.