🎓 CoursesRisk & complianceAdvanced⏱ 60 min

Managing a fraud crisis. 6 chapters and a final quiz.

An attack is underway: a card testing burst, mass account takeover, or a data breach. This course walks through a payments team’s full response. Detect within minutes, activate the war room, and deploy graduated emergency measures (risk rules, forced 3DS, BIN blocking). Then notify banks, schemes, the CNIL (France’s data protection authority), and customers on time, and turn the crisis into a tested resilience plan.

Chapter 1. Anatomy of an attack: card testing, ATO, data breach.

In fraud, the question is not whether your platform will be attacked but when, and above all how long it will take you to notice. Modern attacks are industrialized: botnets, card lists bought on criminal marketplaces, scripts that hit your APIs thousands of times an hour. Three scenarios cover most of the crises a payments team must be ready to handle.

Customeraccount, devicePayment pagethe merchant's DOMPSP / gatewayAuthorization APIAcquirerbatch, settlementIssuerACS, decisionnormal flowthe accountthe browserthe APIthe decisionAccount takeovercredential stuffing · phishingMagecart / e-skimmingcompromised third-party scriptCard testingenumeration with micro-amountsAuthorization fraudreplay, MOTO, unqualified MITMFA · device fingerprintCSP · SRI · integrity 11.6.1velocity · rate limit · 3DSqualified MIT · exemptionsoutside the payment chainRansomware · BECIT systems and people, outside the flowisolated backups · EDR · BCP/DRPnormal flowmodus operandicountermeasureOnly one of these five attacks can stop you without going through the payment chain: ransomware.
🃏
Card testing
The fraudster validates stolen or generated numbers (an enumeration attack on a BIN) by firing bursts of small authorizations at a poorly protected entry point: donation page, account creation, add card, payment API.
👤
Account takeover (ATO)
The fraudster replays username/password pairs from other breaches (credential stuffing), takes over legitimate customer accounts, then uses the stored payment methods or drains stored balances and store credit.
🗄️
Data breach
A compromise of your systems or a provider’s: exfiltration of PANs, tokens, and personal data. The damage often surfaces weeks later, when the stolen data is used elsewhere.
CriterionCard testingMass ATOData breach
Dominant signalBurst of low-value authorizations, decline rate soaringSpike in failed logins, password resets, email changesOften silent; detected through a common point of purchase (CPP) flagged by issuers
SpeedMinutes to hoursHours to daysWeeks to months before detection
Direct damageAuthorization fees, successful fraud on valid cardsFraudulent purchases, drained balances, customer disputesGDPR notification, forensic investigation, card reissuance
Indirect damageWorse scheme ratios (VAMP), merchant BIN reputationLoss of trust, churn, media exposureCNIL and scheme fines, possible MATCH listing, lawsuits
Signatures of the three scenarios compared

Card testing deserves special attention because it has become massive and automated. The attacker starts from a BIN, the first 8 digits of a card range, and uses a script to generate combinations of PAN, expiration date, and CVV. Each approved authorization “validates” a card that will be resold at a higher price or used immediately on other sites. Your platform becomes a free test bench, and you pay the fees.

⚠️
The hidden cost of card testing
Even if no fraud gets through, every attempt costs you. The acquirer and the schemes bill authorization fees: a few cents multiplied by tens of thousands of attempts. Your overall approval rate drops. Above all, your Visa and Mastercard monitoring ratios deteriorate. Since April 2025, Visa’s VAMP program has explicitly tracked an enumeration ratio. A merchant that lets testing bursts through becomes a compliance case.
€1.195B
Fraud on cashless payment methods in France in 2023
OSMP, 2024 annual report
0,053 %
Card payment fraud rate in France (2023)
OSMP, Banque de France
> $1.1B
Annual global losses attributed to enumeration attacks
Visa Payment Fraud Disruption, 2024
🎯 Quick question
What is the most typical signature of a card testing attack?