Skip to main content
Back to the wiki
Fraud & Scams

What Is Card Cracking?

Last updated on July 20, 2026

Card cracking is the automated guessing of missing payment card details. An attacker holds partial data — often just a card number from a breach or a generated number that passes the checksum — and uses bots to test combinations of expiry date, CVV, and postal code against live payment forms until a full working set emerges. It is effectively a brute force attack against the payment system, and the guessing space is small: a three-digit CVV has a thousand possibilities, an expiry date a few dozen plausible values.

How Card Cracking Works

The operation distributes small authorization attempts across many merchants' checkout and donation forms, because any single issuer or merchant would flag hundreds of attempts on one card. Bots rotate through residential proxies and merchant targets so each site sees only a handful of tries, while the attacker's dashboard aggregates which combination was accepted. Small-donation forms and low-value digital checkouts are favored testing grounds: transactions are cheap, forms are simple, and declines draw little attention. Once a card validates, it moves to the same monetization paths as cards verified by carding — resale in card shops or direct fraudulent purchases.

The Difference Between Card Cracking and Carding

The two attacks are close cousins with an inverted starting point. Carding begins with complete stolen card records and verifies which are still alive; card cracking begins with incomplete data and manufactures the missing fields by exhaustion. In practice, fraud operations run both against the same merchant infrastructure, which is why defenses against one largely cover the other.

How Merchants Stop Cracking Attempts

Payment-side controls narrow the space: issuers throttle repeated declines on a card, and address and CVV verification raise the bar for each guess. The merchant-side lever is denying attackers the automated test bench, since cracking's economics collapse without free, high-volume attempts. Rate limits per card and per session catch naive runs; distributed campaigns that stay under those thresholds are the case for per-request bot verification — the invisible check services such as CaptchaFox perform at the payment form, confirming a real customer in a real browser before an authorization attempt is forwarded. Each blocked guess raises the attacker's cost per validated card, and merchants avoid the decline fees and scheme penalties that testing traffic accrues.

About CaptchaFox

CaptchaFox is a GDPR-compliant solution based in Germany that protects websites and applications from automated abuse, such as bots and spam. Its distinctive, multi-layered approach utilises risk signals and cryptographic challenges to facilitate a robust verification process. CaptchaFox enables customers to be onboarded in a matter of minutes, requires no ongoing management and provides enterprises with long-lasting protection.

To learn more about CaptchaFox, talk to us or start integrating our solution with a free trial.

Related terms

What Is Card-Not-Present (CNP) Fraud?

Card-not-present fraud is payment fraud where the physical card is never shown — online, by phone, or in-app — making stolen card data alone enough to pay.

Read more
What Is Carding?

Carding is the automated testing of stolen credit card data against payment forms to find cards that still work before selling or exploiting them.

Read more
What Is Chargeback Fraud?

Chargeback fraud is the abuse of the card dispute process to reverse legitimate charges — the merchant loses the goods, the revenue, and pays a fee on top.

Read more
What Is Click Fraud?

Click fraud is the automated or incentivized clicking of paid ads to drain an advertiser's budget or inflate a publisher's revenue — no buyer ever intended.

Read more

Fight bots and protect your users' data.

Don't give fraudsters and spammers a chance and protect your website with CaptchaFox today.

CaptchaFox protecting websites on desktop and mobile devices