Card Testing Shifts Its Tactics—And Radar Adapts
Stripe reports that while global fraud rates have climbed 11%, successful card testing attacks on its platform have fallen by 80%. That progress doesn't mean the attackers have given up. Stripe's fraud team recently observed a meaningful change in how card testing is being executed, and it required a new defensive approach.
Card testing has traditionally been identified by unusually low authorization rates. In an enumeration attack, fraudsters run automated trial-and-error attempts against card numbers to find which ones are active. Since most guesses are wrong, these attacks produce a telltale pattern of declined authorizations.
That pattern has shifted. Stripe noticed that authorization rates for card testing transactions were rising as attackers moved away from enumeration and toward verification attacks. Instead of guessing, they now work from data dumps of stolen payment details, often sourced from more sophisticated phishing operations. These dumps are higher quality than past leaks, meaning the stolen card details are accurate and more likely to authorize. The result is a double threat: risk to cardholders' personal information and increased disputes for businesses.
Three Layers of Defense
Radar's existing models already predict the likelihood of fraud or card testing, but the new wave of high-authorization-rate verification attacks required a different mechanism. Stripe built a three-tier strategy:
- Manual ingestion of data dumps. The first line of defense is straightforward: Stripe manually ingests known dumps of stolen card information and blocks any transaction attempting to use those cards.
- Automated internet monitoring. To complement the manual process, Stripe added features that automatically scan the internet for newly leaked card numbers.
- Probabilistic stolen card models. By analyzing the fraudulent use of compromised cards, Stripe identified characteristic patterns. This led to machine learning models that estimate whether a card is likely stolen even if the card number has not been discovered online.
These layers let Radar treat a card's compromised status as just another signal when evaluating a charge. The payoff so far: an additional 30 million high-risk transactions blocked, which helps lower dispute rates and keeps merchants out of card networks' fraud monitoring programs.
No Integration Changes Required
These compromised-card controls are one example of how Stripe continually improves Radar's underlying models. Merchants already using Radar get the benefit of these enhancements automatically, with no changes to their integration. Stripe points to its documentation for more details on how Radar protects businesses from fraud.



