Carding is the whole criminal business of buying, selling, and cashing out stolen card data, including the automated testing of small purchases to find live cards before they are resold or used. It is an organized supply chain, not a one-off theft, which is why the same cards surface at many different merchants.
What is carding, in plain English?
Carding is the term for the end-to-end economy around stolen payment cards. It is not a single act of fraud but a market: card data gets stolen, sold, tested, and cashed out by different specialists, each handling one stage. Thinking of it as a supply chain, rather than one criminal with one stolen card, is the key to understanding how it behaves.
At the front of the chain, stolen data flows through dark-web shops that sell card numbers, dumps of magnetic-stripe track data, and fullz, meaning full identity packages. Buyers run automated testing on small purchases to confirm which cards are live. The confirmed cards are then cashed out, often by buying resellable goods or gift cards, frequently at a different, higher-value merchant than the one used for testing.
Carding sits at the center of card fraud and connects to many neighbors: dumps, fullz, BIN attacks, and enumeration feed it, while mule networks and resale channels move the proceeds. On the merchant side, it shows up not as one bad order but as the recognizable footprint of an industrial process.
The carding supply chain
- Steal — Harvest card data. Breaches, phishing, skimming, and malware feed a steady supply of card numbers and track data.
- Sell — Trade on dark markets. Data is packaged as numbers, dumps, or fullz and sold in bulk through specialized shops.
- Test — Confirm live cards. Automated small or zero-dollar charges sort working cards from dead ones at a soft merchant.
- Cash out — Convert to value. Live cards buy resellable goods or gift cards, usually at a different, higher-value merchant.
Who is involved?
Who | Their role |
The data thief | Steals card data through breaches, skimming, phishing, or malware. |
The vendor or shop | Sells the stolen data as numbers, dumps, or fullz on dark-web marketplaces. |
The tester | Runs automated checks to confirm which purchased cards are still live. |
The cashout crew | Uses confirmed cards to buy resellable goods and convert them to money, often via mules. |
The merchants | The testing ground and, separately, the higher-value cashout target that takes the real loss. |
What it looks like in practice
In practice
A digital gift-card seller sees two waves. First, a flurry of small, fast, mostly declining transactions from throwaway email addresses and a handful of devices: automated testing sorting a fresh batch. The seller shrugs it off as noise because the amounts are tiny.
A few days later, the second wave hits: larger orders for high-value gift cards, placed with the cards that survived the first wave, shipping to disposable identities. These are the cashout. The chargebacks that follow trace straight back to cards confirmed live during the earlier testing burst. What looked like two unrelated events was one carding operation, testing at a soft merchant and cashing out at a valuable one.
Why it matters to operators
Seeing carding as a supply chain changes how you defend against it. The merchant that gets tested is rarely the one that takes the big loss, and the merchant that gets cashed out may never see the testing that preceded it. Fighting only your own visible losses misses that you are one node in a larger process, and that the signals you ignore may be enabling fraud downstream.
On the merchant side, carding leaves a distinctive footprint: testing bursts, high declines, and small orders from throwaway identities, followed elsewhere by higher-value cashout. Because tested cards move between merchants, cross-merchant and consortium signals are especially valuable. The practical defenses are the same tools that blunt any automated card abuse: velocity limits, device intelligence, and friction on the testing path.
What to watch in the data
- Testing bursts. Spikes of small or zero-dollar attempts with high decline rates, a hallmark of card confirmation runs.
- Throwaway identities. Orders from disposable emails, freshly created accounts, and minimal customer history.
- Device and IP concentration. High volume traced to a small set of devices, IP ranges, or automation signatures.
- Test-then-cashout link. Cards seen in a small-value burst reappearing days later in larger orders or as chargebacks.
- Cross-merchant reuse. The same cards or devices showing up at multiple merchants, which consortium data can surface.
Quick questions
Is carding the same as card testing?
No. Card testing is one stage within carding, the part where fraudsters confirm which cards are live. Carding is the whole business around stolen cards, from theft and sale through testing to cashout.
What are dumps and fullz?
Dumps are stolen magnetic-stripe track data used for cloning cards for in-person use. Fullz are complete identity packages, card plus personal details, used for richer fraud. Both are traded through carding shops.
Why do fraudsters test and cash out at different merchants?
Testing needs a cheap, soft endpoint that just returns approve or decline. Cashout needs a merchant selling resellable, high-value goods. Separating the two also spreads the footprint and makes each stage harder to link.
How organized is carding?
Highly. It is a specialized market with data thieves, shop operators, testers, cashout crews, and mule networks, each doing one job. That division of labor is why it behaves like a supply chain rather than isolated fraud.
What helps most against carding?
Velocity limits and bot defenses on the testing path, device fingerprinting, throwaway-identity detection, and cross-merchant or consortium intelligence to catch cards and devices reused across the chain.
Go deeper
- EMVCo ↗ — Maintains the EMV chip and 3-D Secure specifications for card payments.
- PCI Security Standards Council ↗ — Security standards for handling cardholder data, including PCI DSS.

