HomeBlog

Card-Testing Attacks on Shopify: How to Spot and Stop Them

Card-testing attacks run stolen cards through your Shopify checkout in bulk. Learn the warning signs and the bot and IP rules that stop carding for good.

Card-Testing Attacks on Shopify: How to Spot and Stop Them

A card-testing attack is a fraud scheme where criminals push stolen card numbers through your Shopify checkout in rapid, low-value transactions to learn which cards still work. You spot it by a sudden spike in tiny orders and declines from a handful of sources, and you stop it by blocking the bots and networks running the probes before they reach checkout.

Card testing is one of the most common threats Shopify stores face. The Merchant Risk Council found that 33% of merchants experienced card testing in 2025, and at peak, payment processor Stripe has reported blocking more than 20 million card-testing attempts every single day. The damage outlasts the attack itself-even fully declined attempts quietly erode your standing with card networks.

Fraud detection network diagram showing automated card-testing bots probing a Shopify checkout from masked IP addresses

Card testing-also called carding, card cracking, or card validation-is a payment-fraud technique where an attacker submits many stolen or partially guessed card details through a checkout to confirm which ones are still active and have available funds, before spending the working cards on bigger purchases elsewhere.

On this page

What is a card-testing attack on Shopify?

A card-testing attack is an automated fraud run that uses your checkout as a free validation tool. Attackers buy batches of stolen card numbers-around $5 for a single set of card details on the dark web, per Experian data cited by Chargebacks911-but many of those numbers are already canceled, expired, or incomplete. To sort the live cards from the dead ones, they run each through a real merchant’s checkout as a small charge or a zero-dollar authorization. An approval means the card works and is worth using or reselling; a decline means discard it.

The attack is almost always run by bots, not people. A single script can cycle through hundreds or thousands of card numbers in minutes, often distributing the attempts across residential proxies and rotating IP addresses so the automated traffic looks like ordinary shoppers. Your store gets chosen not because you were targeted personally, but because your checkout accepted card entry without enough friction-card testers hunt for the path of least resistance and hammer it.

Shopify stores are attractive targets for a few structural reasons:

  • Guest checkout accepts cards from anyone, with no account or purchase history required.
  • Low-value or donation-style products (tip jars, digital downloads, gift cards) let attackers test with charges small enough to slip notice.
  • Public storefronts are easy to script against, and a successful run on one Shopify store often gets repeated across many.

Want to see what automated traffic is already hitting your store? Explore what Kedra Shield blocks at the storefront front door-bots, data-center IPs, proxies, and known-bad networks-before they ever reach your checkout.

How do I spot a card-testing attack?

You spot a card-testing attack by watching for a cluster of signals at once: a burst of small or zero-dollar orders, an abnormal spike in declines, and many different card numbers tied to a few IP addresses or devices. No single signal is proof, but several together-especially in a short window-almost always mean automated card validation is underway.

Here are the warning signs to watch for in your Shopify admin and payment reports:

SignalWhat it looks likeWhy it points to card testing
Micro or $0 transactionsA run of $0.50–$5 charges or zero-dollar authorizations in minutesTesters use the smallest possible amount to validate a card unnoticed
Decline spikeA sudden surge of declines for invalid number, expired card, AVS, or CVV mismatchAttackers test large batches of mostly dead credentials, so declines outpace approvals
Authorizations outrunning salesFar more attempted transactions than completed ordersThe goal is validation, not purchase-most attempts are never meant to convert
Velocity from few sourcesDozens of attempts per minute from one IP, device fingerprint, or browserHuman shoppers don’t submit cards in rapid succession
Repeated near-identical attemptsSame card cycling through different CVV or expiry valuesScripts brute-force the missing digits of partial card data
Disposable emails and mismatched addressesThrowaway email domains, billing that doesn’t match shipping or geographyBots generate synthetic customer data at scale

Inside Shopify, the fastest place to catch this is your payments and orders view: watch for a wall of orders with tiny amounts and identical timestamps, and check whether your order risk / fraud analysis flags a cluster of high-risk transactions from the same source. If you use Shopify Payments, a spike in your declined-authorization rate is often the first visible symptom. For a broader view of what a risky order looks like beyond card testing, see our guide to high-risk order indicators to spot before fulfillment.

Why card testing hurts even when the charges fail

The most dangerous myth about card testing is that a blocked or declined attempt is harmless. It isn’t. Even attempts that never complete cost you real money and can damage your ability to process legitimate payments for weeks afterward.

Here is where the damage actually lands:

  • Authorization-rate erosion. This is the hidden, lasting cost. Shopify’s own fraud team warns that card testing creates “failed transactions that degrade a merchant’s trust with banks,” producing “a lingering drop in authorization rates, meaning legitimate customer payments are unjustly declined long after the attack has stopped.” A flood of declines teaches the card networks to distrust your store-so your real customers start getting falsely declined.
  • Per-attempt processor fees. Many gateways charge a small fee for every authorization attempt. At roughly $0.05–$0.15 per decline, a 50,000-attempt attack can generate over $5,000 in fees before a single fraudulent order completes.
  • Chargebacks on the cards that do work. When a validated card is later used for a real purchase, the genuine cardholder disputes it-and you absorb a chargeback fee of $20 to $100 per transaction regardless of order value, plus the lost goods.
  • Merchant-account risk. A high ratio of declines and disputes can breach your processor’s thresholds and put your Shopify Payments account under review or reserve.
  • Polluted analytics and load. Thousands of bot sessions distort your conversion, traffic, and checkout metrics, the same way bot traffic quietly corrupts your Shopify reporting.

The scale of the broader problem keeps this from being a rare edge case. The Merchant Risk Council’s 2026 Global eCommerce Payments and Fraud Report, which surveyed 1,278 merchant professionals across 37 countries, found merchants faced an average of 3.7 distinct fraud attack types in 2025. As MRC’s Keith Briscoe put it, understanding “the latest developments in areas like agentic commerce, first-party misuse, payments optimization and fraud prevention is vitally important insight” for merchants trying to stay ahead.

Does Shopify already block card testing?

Yes-partly, and it’s worth crediting. Shopify runs a platform-level machine-learning model on guest credit-card checkouts that, by its own reporting, blocks approximately 90% of card-testing attacks and has boosted legitimate payment success rates by 13%. If you use Shopify Payments, that protection is real and working in the background.

But “approximately 90%” is not “all,” and there are gaps that matter:

  1. The remaining attempts still add up. At attack volumes measured in the thousands per hour, even a small percentage that slips through is a meaningful number of probes, fees, and declines against your account.
  2. Third-party gateways may not share the same model. If you process through a payment provider other than Shopify Payments, you can’t assume the same platform-level protection covers your checkout.
  3. The bots still reach you. Shopify’s model acts at the payment layer, after the automated traffic has already loaded your store, consumed resources, and skewed your analytics. Stopping the fraud attempt is not the same as stopping the bot.
  4. Testers adapt. Attackers deliberately spread low-volume attempts across many merchants and route through residential proxies to stay under detection thresholds.

The takeaway: Shopify’s payment-level defense is a strong last line, but the most effective posture also blocks the automated traffic at the front door-so the bots never get the chance to submit attempts in the first place. Payment-level filtering and front-door blocking solve different halves of the same problem.

How to stop card-testing attacks on Shopify

Kedra Shield is a Shopify security app that blocks the traffic behind card testing at the storefront entry point-before a bot ever reaches your product pages or checkout to submit an attempt. Instead of filtering charges after the fact, it removes the automation and known-bad networks that make bulk card testing possible in the first place. Here’s how a practical setup maps to the attack.

Shopify merchant reviewing a security dashboard that flags and blocks automated card-testing traffic by network and country

  1. Install and open the dashboard. Add Kedra Shield from the Shopify App Store and open its protection settings. You’ll see live blocked-traffic reporting broken down by network type and country-the fastest way to confirm an attack in progress.
  2. Block bots and data-center networks. Card-testing scripts almost always run from cloud and hosting infrastructure. Turn on bot and data-center (ASN/hosting) blocking so automated traffic from AWS, OVH, and similar networks never loads your checkout. This alone removes a large share of card-testing volume.
  3. Enable VPN, proxy, and Tor detection. Attackers hide behind anonymized connections to rotate identities and dodge rate limits. Switch on anonymized-connection detection to identify and challenge or block that masked traffic. Our VPN and proxy blocking guide walks through the exact settings.
  4. Apply rate limiting and velocity rules. Cap how many requests a single visitor or IP can make in a short window, so a script trying to fire hundreds of checkout attempts per minute gets throttled and blocked instead of tested.
  5. Layer in country and city rules. If your card-testing traffic clusters in regions you don’t sell to, add geographic blocking to close that lane-while keeping your real markets fully open. See our country blocking strategy for how to do this without losing legitimate sales.
  6. Monitor and tune weekly. Review the blocked-traffic dashboard, watch your Shopify decline rate recover, and adjust each rule as your data accumulates. Because enforcement happens at the front door, blocked bots never test cards, never inflate your fees, and never slow the store for real shoppers.

Front-door blocking and Shopify’s payment-level model are complementary: one stops the bots from arriving, the other catches anything that gets through. Run together, they shrink both the volume of attempts and the fallout on your authorization rate.

Ready to cut off card testing at the source? Install Kedra Shield, turn on bot and data-center blocking, and watch your dashboard reveal how much automated traffic was reaching checkout unchecked.

Frequently asked questions

What is a card-testing attack in simple terms?

A card-testing attack is when fraudsters run stolen credit card numbers through an online checkout in small or zero-dollar transactions to find out which cards still work. It’s automated and high-volume-one bot can test thousands of cards in minutes. The working cards are then used or resold for larger fraud elsewhere.

How do I know if my Shopify store is being card-tested?

Look for a cluster of signals together: a burst of tiny or $0 orders in minutes, a sudden spike in declines for invalid card, AVS, or CVV mismatch, and many different card numbers coming from a few IP addresses or devices. A rising declined-authorization rate in Shopify Payments is often the first visible symptom.

Does card testing cost me money if the charges are declined?

Yes. Declined attempts still trigger per-authorization gateway fees, and a flood of declines degrades your standing with card networks-lowering approval rates for legitimate customers long after the attack ends. Cards that do validate later come back as chargebacks costing $20–$100 each, and high dispute ratios can put your merchant account at risk.

Doesn’t Shopify already stop card testing automatically?

Shopify’s machine-learning model blocks roughly 90% of card-testing attacks on guest credit-card checkouts using Shopify Payments, which is significant. But it operates at the payment layer, so bots still reach and load your store, third-party gateways may not share the same protection, and the remaining attempts add up at attack volumes. Front-door bot blocking closes those gaps.

Can I stop card testing without hurting real customers?

Yes. The traffic behind card testing-data-center IPs, bots, and rotating proxies-looks nothing like a genuine shopper, so blocking it at the storefront rarely touches real buyers. Tools like Kedra Shield let you block bot and hosting networks outright while applying softer friction to edge cases, keeping checkout fast for legitimate customers.

The bottom line

Card testing turns your Shopify checkout into a free validation service for stolen cards-and the cost lands whether or not the charges succeed. Declined attempts drain per-authorization fees, drag down the approval rates your real customers depend on, and set up the chargebacks that follow when a validated card is finally spent. With a third of merchants hit in 2025 and testing bots probing millions of times a day, it’s less a matter of if than when.

The strongest defense works in layers. Shopify’s payment-level model is a capable last line for Shopify Payments merchants, but it can’t stop the bots from arriving. Blocking that automated traffic at the storefront front door-data-center networks, proxies, and scripted velocity-removes the attack before it becomes attempts, protecting both your fees and your authorization rate.

Kedra Shield brings that front-door defense to your Shopify store in minutes, with maintained network intelligence and blocked-traffic reporting that shows exactly what it’s stopping. Turn on bot and data-center blocking first, then layer in proxy detection and rate limits-and watch how much quieter your checkout gets.