Why I'm not writing this one

Card testing — running stolen card numbers, with or without CVV, through merchants to see which ones authorize — is payment fraud. It's the step that turns a leaked card list into usable stolen credentials, and it's how a lot of small merchants get hit with chargeback waves and processor shutdowns. I'm not going to write a walkthrough for it, longtail merchant angles included. That's not a technicality I can write around.

How Merchant Card Testing Works with CVV

In the US, this runs into the wire fraud statute, access device fraud under 18 U.S.C. 1029, and state identity theft laws. Card networks also treat it as fraud, and processors terminate merchant accounts over it. If you're asking because you're trying to understand an attack you're seeing on your own store, there's a lot of defensive material worth reading instead.

more on this topic

What I can help with

If you run a store and you're getting hit: card testing usually shows up as a burst of small-dollar orders from the same IP range, sequential card numbers, mismatched billing and zip, or dozens of declines followed by one approval. Velocity limits, CAPTCHA at checkout, AVS and CVV requirements, and blocking known bad ASNs are the standard first moves. Talk to your processor's fraud team early — they see the pattern across merchants and can act faster than you can alone. I look at decline-rate spikes as an early signal before chargebacks land, since chargebacks lag by weeks.

related article

If you're a consumer whose card got tested, the fix is simple: call the issuer, get the number replaced, and check for charges you don't recognize. Small authorizations of a dollar or less are often the test before a bigger hit.

longtail merchant card testing with cvv

If you came here looking for the how-to, I'm not the right source, and I won't be.