Manage Card Testing Exposure
Last updated on Sep 1, 2026
Card testing occurs when fraudsters use automated scripts to validate stolen or algorithmically generated card numbers, typically through small-value or zero-dollar transactions on publicly accessible payment forms. Public Signup Pages, designed to reduce friction for new Customers, can also give automated testing scripts an easy entry point.
Recognize card testing activity
Watch for these signs that your account may be experiencing a card testing attack:
- A sudden spike in failed payments or authorization-only transactions
- A high volume of small-value charges ($0.01-$5.00) with no associated order or sale
- Multiple failed payment attempts from the same IP address or device
- Frequent use of international or high-risk card BINs
- Reversals or voids immediately following authorizations
- Unusual activity concentrated in off-hours or across time zones
Configure Maxio protections against card testing
Maxio provides several protections against automated card testing that you can enable or keep up to date on your own account.
Consider these options to reduce card testing exposure on Public Signup Pages:
- Enable CVV verification as a required field for your account. This affects Public Signup Pages and other payment forms, and can eliminate a significant portion of card testing attempts that use basic stolen card data.
- Upgrade to the latest version of Maxio.js (formerly Chargify.js). Maxio.js applies Google reCAPTCHA Enterprise protection automatically to help block automated bot traffic while remaining invisible to legitimate Customers. Sites on an outdated Maxio.js version don't receive this protection.
- If you have a custom checkout implementation, keep Maxio.js updated to the latest version to receive ongoing bot-detection and security token improvements.
Respond to a card testing attack
If you're using Maxio Payments, contact the support team immediately when you detect suspicious activity. The Maxio team can implement temporary protective measures while you work together on a longer-term solution.
If you're using an external payment gateway, contact your gateway provider immediately. Gateway providers offer their own tools for combating card testing that aren't available through the standard Maxio merchant interface.
Related information
If you collect card details through your own pages rather than a Maxio-hosted page, see Prevent Card Testing Abuse with Maxio.js for the protections available at the form itself.
Get help
If you need help reviewing your current payment setup or strengthening your card testing defenses, contact us:
- Email: support@maxio.com
- Phone: Contact your assigned Account Manager
Still need help?
Reach out and our support team will take it from here.
