Critical ResourceVisa CEDP: Major Payments Disruption
Back to Glossary

Payment Enumeration Attack

A cyberattack where criminals systematically test large volumes of stolen or randomly generated payment card data against a merchant's payment system to identify valid card numbers, expiration dates, and security codes for fraudulent use.

Payment enumeration attacks (also called "card testing" or "carding") exploit payment gateways and checkout pages that provide real-time authorization responses. Attackers use automated bots to submit hundreds or thousands of small-value transaction attempts in rapid succession, using stolen or algorithmically generated card data with varying expiration dates and CVV codes. Approved transactions confirm valid card details, which criminals then sell on dark web marketplaces or use for larger fraudulent purchases. Declined transactions help attackers refine their data sets by eliminating invalid combinations.

These attacks create multiple problems for merchants beyond the direct fraud risk. Each authorization attempt incurs an authorization fee (typically $0.02 to $0.10), meaning thousands of test transactions can cost hundreds or thousands of dollars in fees for transactions that never result in legitimate sales. High volumes of declined authorizations may trigger processor fraud monitoring or account reviews. If attackers successfully identify valid cards through the merchant's system and those cards are later used fraudulently elsewhere, the merchant may face regulatory scrutiny or penalties. Legitimate customers may experience checkout problems if attacks overwhelm payment systems or trigger aggressive fraud filters.

Merchants can defend against payment enumeration attacks through several technical controls including rate limiting that restricts transaction attempts per IP address or session, CAPTCHA challenges on checkout pages to prevent bot automation, velocity filters that flag multiple declined transactions in short timeframes, geolocation blocking for high-risk countries, behavioral analysis to identify automated versus human checkout patterns, and requiring strong customer authentication like 3D Secure for suspicious transactions. E-commerce platforms and payment gateways increasingly build anti-enumeration protections into their systems, but merchants should actively monitor for attack patterns and configure available security controls appropriately.

Related Content

Optimize Your Payment Processing

Let Verisave analyze your merchant statement to identify hidden fees and misconfigurations related to payment enumeration attack.

Get a Free Audit

Related Terms