Skip to navigation Skip to main content

Free Grow sales & stop fraud — Smart Cycle Discounts + TrustLens, free on WordPress.org Two free WooCommerce plugins

Explore both

Free Grow sales & stop fraud — Smart Cycle Discounts + TrustLens, free on WordPress.org Two free WooCommerce plugins

Explore both
  • WordPress
    WordPress Plugins
    View all
    Smart Cycle Discounts logo

    Smart Cycle Discounts

    Automate discount campaigns with scheduling, analytics, and smart product targeting.

    7 Discount Types Cycle AI
    Free Pro from $59
    TrustLens logo

    TrustLens

    Customer trust intelligence for WooCommerce. Score customers, spot abuse, protect revenue.

    Trust Scores Abuse Detection
    Free Pro from $79

    New Plugin

    Coming Soon

    Something exciting is in the works. Join the waitlist to be first to know.

    Get Notified
    Notify Me
    Secure Checkout
    WordPress.org
    14-Day Refund
    Resources
    Documentation Guides & tutorials
    Discount Calculator Plan your strategy
    Support Get help
    SCD Changelog Discount plugin updates
    TrustLens Changelog Trust intelligence updates
    Get notified on new releases
  • Affiliate
    Program
    Overview How the program works
    How It Works 4 steps from apply to earn
    Commission Details 30% · 60-day cookie · recurring
    Get Started
    Apply Now Open
    Takes ~2 minutes
    Earnings Calculator Estimate your monthly income
    FAQ Payouts, cookies, renewals
    Resources
    Brand Kit Logos, banners, copy, social
    Playbook Tactics that actually convert
    FTC Disclosure How to disclose properly
    Affiliate Terms Full program agreement
    Contact Team Open the contact form
    Earn 30% recurring on every sale Free to join · 60-day cookie · monthly PayPal payouts
    Apply Now
  • Blog
  • DOCS
    Docs & Resources

    Guides, references, and answers for every Webstepper plugin.

    Smart Cycle Discounts Automated WooCommerce discount campaigns
    Getting started › Discount types › Cycle AI ›
    TrustLens Customer trust & fraud intelligence
    Trust scoring › Detection modules › Card-testing defense ›
    Docs Home Guides FAQ Pricing Support
    WordPress tools that solve real problems
  • Contact Us
  • About
    Company

    Our Story

    Founded 2020

    Built by store owners, for store owners. We create WordPress tools that solve real problems.

    Learn more
    Built from Experience Real solutions we use ourselves
    Time is Precious Simple, intuitive tools
    Real Support Talk to the founders
    Legal & Contact
    Contact Us Privacy Policy Terms of Service Refund Policy
    14-Day Money-Back Guarantee No questions asked
Popular requests
  • smart cycle discounts
  • trustlens
  • chargeback protection
GET STARTED

Glossary

1
  • TrustLens Glossary

Detection Modules

9
  • Card Testing Defense
  • Chargeback Tracking
  • Shipping Anomalies
  • Linked Accounts Detection
  • Category Aware Risk
  • Coupon Abuse Detection
  • Order Pattern Analysis
  • Return Abuse Detection
  • Modules Overview

Card Testing Defense

9
  • Attack History
  • Allowlists
  • Geo Diversity
  • Auto Escalation
  • Fingerprinting
  • VIP Bypass
  • Panic Button
  • Velocity Thresholds
  • Overview

Chargeback Monitor

7
  • Ratio Email Alerts
  • Dispute Evidence Report
  • Chargeback Monitor
  • Manual Dispute Entry
  • Stripe WooPayments Ingestion
  • Card Network Thresholds
  • Chargeback Ratio Speedometer

Customer Management

7
  • Admin Notes
  • Checkout Enforcement
  • Order Trust Column
  • Bulk Actions
  • Blocking and Allowlisting
  • Customer Detail Profile
  • Customer List

Automation

7
  • Async Dispatch Retries
  • Webhooks and HMAC
  • Rule Inspector
  • Actions Reference
  • Conditions Reference
  • Triggers Reference
  • Automation Overview

Trust Scoring

5
  • Account Age Loyalty Bonus
  • Signals Explained
  • Six Customer Segments
  • The 0–100 Score
  • How Trust Scoring Works
View Categories
  • Home
  • Docs
  • Trustlens
  • Use Cases
  • Surviving Card Testing Attack

Surviving Card Testing Attack

5 min read

Card-testing attacks are loud, fast, and damaging. A bot can run thousands of authorization attempts against your gateway in minutes — costing you fees, polluting your conversion metrics, and seeding chargebacks that arrive weeks later. This walkthrough is the playbook for surviving an active attack with TrustLens, both Free and Pro tiers.


Recognizing You’re Under Attack #

Common indicators:

  • Spike in declined transactions in your gateway dashboard
  • Multiple decline notifications from your processor
  • Decline rate suddenly 10× normal
  • Unfamiliar fingerprints producing many attempts in TrustLens’s Card Testing event log
  • Decline codes heavily skewed toward “insufficient funds” or “invalid expiry”

If you’re seeing this, you’re being card-tested.


Immediate Response (Free) #

Step 1: Hit Panic Freeze #

Don’t troubleshoot first. Stop the bleeding.

  1. Go to TrustLens → Card Testing
  2. Click the red Panic Freeze button
  3. Confirm

All checkouts halt for 15 minutes. Your VIPs can still check out (bypass on by default). No further damage accumulates while you investigate.

Step 2: Identify the Attack #

On the same page:

  • Look at recent decline events — what fingerprints?
  • Check the velocity counters — single fingerprint hammering, or distributed?
  • If distributed, the per-fingerprint lockouts aren’t catching it — that’s why you needed Panic Freeze

Step 3: Tighten Velocity Thresholds (Optional) #

If the attack used a slow pace, the defaults may not have caught it in time. Temporarily tighten:

  • Settings → Modules → Card Testing
  • Lower the 60-second decline threshold to 2
  • Lower the 60-second submission threshold to 6
  • Save

Step 4: Cancel Panic Freeze When Ready #

After the attack pattern stops and you’ve tightened thresholds, cancel the freeze. The next few minutes are critical — if the attack resumes, refreeze and consider further hardening (Pro features described below).


Immediate Response (Pro) #

Pro adds tools that often prevent the attack from requiring Panic Freeze in the first place:

Auto-Escalation #

If Auto-Escalation was on, Panic Freeze likely activated automatically when the attack spread across multiple fingerprints. Your job is to verify the freeze fired and decide whether to keep it active longer than the default 15 minutes.

Attack History Tab #

Open the Attack History tab for forensic data:

  • 24-hour decline count
  • Decline-code breakdown
  • Top-10 attacking fingerprints
  • Geographic distribution

This tells you the shape of the attack — bursty or sustained, single botnet or distributed.

Alerts #

If you’ve configured Slack alerts, the attack_detected, auto_escalated, and panic_button_activated notifications should already be in your channel. Make sure the right people are looking.


Mid-Attack Tactics (Both Tiers) #

If a Single Fingerprint Is Dominating #

Sometimes one fingerprint is responsible for the majority of attempts. The velocity lockout should be catching it, but if it’s evading somehow:

  • (Pro) Add the fingerprint to the per-fingerprint override with a tight custom threshold
  • (Free) Tighten the global velocity thresholds to catch it on fewer attempts

If Many Fingerprints Are Attacking #

Distributed attack. Per-fingerprint defenses alone aren’t enough.

  • (Pro) Confirm Auto-Escalation is enabled and configured to trigger Panic Freeze on this scale
  • (Free) Use manual Panic Freeze repeatedly as the attack continues
  • Consider raising the firewall — if you can identify a country or IP range producing most of the traffic, block at the web-server or CDN level

If Attack Is Geographically Diverse #

Pro’s geo-diversity safeguard may have blocked Auto-Escalation, treating the pattern as legitimate viral traffic. Verify whether this is actually viral traffic (check your marketing — did something just go live?) or whether the safeguard misfired.

If the safeguard misfired, temporarily disable it or lower its country threshold.


Post-Attack Cleanup #

Within 24 Hours #

  1. Confirm the attack has stopped — no more decline spikes
  2. Restore velocity thresholds to defaults if you tightened them
  3. Review which fingerprints completed orders during the attack — they could be successful card-testing tools that found live cards
  4. Flag those customer records for high scrutiny
  5. Generate a post-attack report (Pro Attack History → Export CSV)

Within 1 Week #

The dispute window is starting. Expect chargebacks 2–8 weeks later on any orders that completed during the attack with stolen cards.

  • Monitor incoming disputes
  • Generate Dispute Evidence Reports for orders that completed during attack windows
  • Cross-reference disputed orders against the Attack History — orders from attacking fingerprints have strong fraud evidence

Within 1 Month #

  • Review your chargeback ratio — has it spiked from attack disputes?
  • If yes, prepare for processor scrutiny; communicate proactively
  • Tune defenses based on lessons learned

Preventive Setup for Next Time #

The best response is no attack at all. Configure:

Setup Effect
Auto-Escalation enabled (Pro) Auto-freezes on distributed attacks
Geo-diversity safeguard enabled (Pro) Prevents auto-escalation false positives
Slack alerts configured (Pro) Realtime notification when attacks start
VIP allowlist populated Confirmed legitimate customers can’t be caught
Fingerprint allowlists for QA / partners (Pro) Reduce false-positive volume
Velocity thresholds tuned to your gateway behavior Right balance of sensitivity and noise

What to Communicate Externally #

During or after a significant attack:

  • Processor: Most appreciate proactive notification. They’ve seen the spike anyway; getting your context helps.
  • Customer service team: Some legitimate customers may have had failed checkouts during defensive measures. Brief CS so they can handle inquiries.
  • Marketing team: If the attack coincided with a campaign, conversion data is polluted. Note for analytics review.
  • Stakeholders / leadership: Document attack scale and protection effectiveness. This is the kind of incident that justifies the Pro license.

What Not to Do #

  • Don’t disable Card-Testing Defense. Even partially, even temporarily. The attack will resume immediately.
  • Don’t open up rate limits to “see what’s happening.” The bot doesn’t slow down because you’re watching.
  • Don’t email blocked attackers. They’re bots; emails go nowhere or to inboxes you don’t want to interact with.
  • Don’t assume the attack stopped after one wave. Many bots return after a cooldown.

Metrics to Track #

  • Time from attack start to first defensive action
  • Total declines blocked during the attack
  • Orders that completed during attack (potential fraud)
  • Chargebacks attributable to the attack (track 4–8 weeks out)
  • False-positive customer complaints in the week following
Updated on June 4, 2026

What are your Feelings

  • Happy
  • Normal
  • Sad

Share This Article :

  • Facebook
  • X
  • LinkedIn
  • Pinterest
Staying Below VDMP ThresholdDetecting Fraud Rings
Table of Contents
  • Recognizing You're Under Attack
  • Immediate Response (Free)
    • Step 1: Hit Panic Freeze
    • Step 2: Identify the Attack
    • Step 3: Tighten Velocity Thresholds (Optional)
    • Step 4: Cancel Panic Freeze When Ready
  • Immediate Response (Pro)
    • Auto-Escalation
    • Attack History Tab
    • Alerts
  • Mid-Attack Tactics (Both Tiers)
    • If a Single Fingerprint Is Dominating
    • If Many Fingerprints Are Attacking
    • If Attack Is Geographically Diverse
  • Post-Attack Cleanup
    • Within 24 Hours
    • Within 1 Week
    • Within 1 Month
  • Preventive Setup for Next Time
  • What to Communicate Externally
  • What Not to Do
  • Metrics to Track
Newsletter

Insights that grow your business

Join thousands of WooCommerce store owners who get actionable tips, plugin updates, and industry news every week.

We respect your privacy. Unsubscribe at any time.

Weekly updates — Fresh content every Tuesday
Exclusive content — Tips you won't find on our blog
Early access — Be first to know about new plugins
Webstepper
Weekly WooCommerce Tips
Just now
This week: 5 proven strategies to boost your average order value using smart discount campaigns...
New issue!
Webstepper

Tools for store owners who'd rather grow than grind.

Simple, powerful plugins that help WooCommerce store owners sell more — without the learning curve.

500+ happy stores

Products

  • Smart Cycle Discounts
  • TrustLens
  • Discount Calculator
  • Sale Calendar

Company

  • About Us
  • Blog
  • Contact
  • Affiliates

Resources

  • Help Center
  • Guides
  • Affiliate Program
  • Become a Partner

Questions? We actually answer.

Real humans, real help. No bots, no runaround. Usually within a few hours.

Get in touch
Operated by Setmood LLC · 7901 4th St N, St Petersburg, FL 33702 · United States

© 2026 Webstepper. All rights reserved.

Privacy Terms Refunds
Visa Mastercard PayPal Apple Pay Google Pay & more
Limited Time Offer

Save 15% on
SCD, TrustLens & the Bundle

Smart Cycle Discounts and TrustLens — buy either plugin or grab both in the bundle. Use code at checkout.

WELCOME15
23 hours
:
59 minutes
:
59 seconds
Claim My Discount

Just want one? Smart Cycle Discounts · TrustLens

  • WordPress
    Back
    WordPress Plugins
    View all
    Smart Cycle Discounts logo

    Smart Cycle Discounts

    Automate discount campaigns with scheduling, analytics, and smart product targeting.

    7 Discount Types Cycle AI
    Free Pro from $59
    TrustLens logo

    TrustLens

    Customer trust intelligence for WooCommerce. Score customers, spot abuse, protect revenue.

    Trust Scores Abuse Detection
    Free Pro from $79

    New Plugin

    Coming Soon

    Something exciting is in the works. Join the waitlist to be first to know.

    Get Notified
    Notify Me
    Secure Checkout
    WordPress.org
    14-Day Refund
    Resources
    Documentation Guides & tutorials
    Discount Calculator Plan your strategy
    Support Get help
    SCD Changelog Discount plugin updates
    TrustLens Changelog Trust intelligence updates
    Get notified on new releases
  • Affiliate
    Back
    Program
    Overview How the program works
    How It Works 4 steps from apply to earn
    Commission Details 30% · 60-day cookie · recurring
    Get Started
    Apply Now Open
    Takes ~2 minutes
    Earnings Calculator Estimate your monthly income
    FAQ Payouts, cookies, renewals
    Resources
    Brand Kit Logos, banners, copy, social
    Playbook Tactics that actually convert
    FTC Disclosure How to disclose properly
    Affiliate Terms Full program agreement
    Contact Team Open the contact form
    Earn 30% recurring on every sale Free to join · 60-day cookie · monthly PayPal payouts
    Apply Now
  • Blog
  • DOCS
    Back
    Docs & Resources

    Guides, references, and answers for every Webstepper plugin.

    Smart Cycle Discounts Automated WooCommerce discount campaigns
    Getting started › Discount types › Cycle AI ›
    TrustLens Customer trust & fraud intelligence
    Trust scoring › Detection modules › Card-testing defense ›
    Docs Home Guides FAQ Pricing Support
    WordPress tools that solve real problems
  • Contact Us
  • About
    Back
    Company

    Our Story

    Founded 2020

    Built by store owners, for store owners. We create WordPress tools that solve real problems.

    Learn more
    Built from Experience Real solutions we use ourselves
    Time is Precious Simple, intuitive tools
    Real Support Talk to the founders
    Legal & Contact
    Contact Us Privacy Policy Terms of Service Refund Policy
    14-Day Money-Back Guarantee No questions asked
We use cookies to improve your experience on our website. By browsing this website, you agree to our use of cookies.
More info More info Accept