Answer
A card test number is a payment card number used to check how a payment system responds. The term covers two different things. In software work it means a sandbox number issued by a payment processor. In fraud it means a live card number that someone checks before using it.
Sandbox test numbers
Processors publish test card numbers for their test environments. Stripe lists numbers such as 4242 4242 4242 4242 for a successful charge. These numbers pass the Luhn check and route to a simulator, not a bank. They work only with test API keys. A test number sent to a live endpoint returns an error or a decline.
The Luhn check
Most card numbers carry a check digit. The Luhn algorithm sums the digits with a doubling rule and requires the total to end in zero. Software uses this to reject typos before it calls the network. The check confirms format only. It does not confirm that an account exists, that the account is open, or that it holds funds.
Card testing attacks
A card testing attack runs many low-value charges against one merchant. The attacker reads the response codes. An approval marks a number as active. A decline marks it as dead. Visa and Mastercard both publish material on this pattern. Attackers target small merchants, donation pages, and free trial signups because those flows answer fast.
Signs a merchant should watch
- A spike in authorization attempts from one IP range or one device fingerprint.
- Many cards used in sequence with the same billing address or email domain.
- Order values of a few cents or a few dollars.
- High decline rates mixed with a few approvals.
- Attempts on a card-not-present channel outside normal business hours.
Controls that reduce exposure
- Set velocity limits in the processor fraud tools for card, IP, email, and device.
- Require CVV and AVS checks, and decline on mismatch.
- Add a CAPTCHA or bot filter to checkout and trial signup pages.
- Block traffic from hosting providers and open proxies.
- Log each authorization request with its response code for later review.
- Send a chargeback alert to the processor when a pattern starts.
Legal position
Testing a card number that belongs to another person is unauthorized access to a payment account. In the US it falls under wire fraud statutes and state computer crime laws. Card networks can fine the merchant for the authorizations. Processors can freeze the account. Sandbox test numbers are the only numbers a developer should use outside a signed live agreement.
What is not public
No public source lists live, valid card numbers. A seller that claims to supply them is selling stolen data or fabricated data. Both carry risk for the buyer. The result of a purchase cannot be checked before payment, and the data may be reused, invalid, or traced.