Card Testing
PCIComplianceHubLast updated
An attack in which stolen card numbers are validated in bulk by pushing large volumes of small or zero-value authorizations through a merchant payment form, to find out which cards still work before they are used elsewhere. The merchant is collateral damage rather than the target, but bears the authorization costs, the chargebacks and the risk to its acceptance. PCI DSS v4.x expects public-facing web applications to be protected against automated attacks of this kind.