Skip to navigationSkip to loginSkip to content

Card testing: Why small, strange amounts suddenly appear on your bank statement

Keytrade Bank logo

Keytrade Bank

keytradebank.be

September 22, 2026 

3 minutes to read

While going through your expenses, you see a payment of €0.60 to an online shop you've never heard of before. It's a little strange, but the amount is so small you think no more of it. What you don't know: That tiny transaction may be a test by a scammer to find out whether your stolen card details still work. If the test succeeds, larger amounts will soon be debited from your account.

Card testing is one of the most underestimated types of card fraud, precisely because it starts in such an inconspicuous manner. The principle is quite straightforward – criminals who have obtained card details don't know which card numbers are still active and which ones have already been blocked, have expired or are simply wrong. Before debiting large amounts or selling the card details, they therefore carry out small test transactions, which are usually under €5 and often less than €1. If the small payments go through, the criminals have the proof they need that the card works and is ready to be misappropriated.

The scale on which the testing takes place is hard to believe. Payment processor Stripe often blocks millions of card testing attempts a day (source). The phenomenon is becoming increasingly widespread, too: Research based on a large network of online stores showed an 175% rise year on year (source). The reason behind this rise is the fact that AI and automated bots make testing thousands of card numbers at the same time a piece of cake.

Where do the stolen card details come from?

Card details can be leaked in a whole host of ways. Criminals loot the details through hacked online shops, data leaks, phishing and fake payment pages, or steal them using malware that spies on you while you're paying for something online. Fraudsters then trade the details in bulk on marketplaces.

Scammers also use another, remarkably brutal method known as a BIN attack. The first six to eight digits of each card number refer to the issuing bank, and fraudsters take a known sequence as a starting point and let software generate all potential combinations of the remaining numbers, expiry dates and CVC codes. Bots then attack payment pages with thousands of numbers until one works (source). This means your card details can be 'stolen' without a data leak ever having occurred, and simply due to brute computing power and bad luck.

When running the tests themselves, criminals deliberately choose websites where small amounts won't stand out, such as charitable donation pages, online shops selling cheap digital products or subscription services with trial plans. Sometimes they may even attempt transactions of €0, such as the card verification checks that some services carry out during registration.

From €1 to €1,000

Everything follows a fixed pattern once a test has been successful. The validated card is either used to make large purchases (such as electronics, gift cards and other products that can easily be sold on) straight away or sold on to other criminals at a premium. It goes without saying that card numbers that have been proven to work are worth much more on the black market than untested numbers.

There may only be a few minutes – or even several days or weeks – between the test being carried out and the actual misuse. This is why one small transaction is such a valuable sign, as it is often the only time you can see the fraud coming before you suffer any major consequences.

US research also shows how persistent the problem is, as more than half of consumers who fell victim to card fraud experienced it several times over (source). After all, card numbers in a leaked database continue to do the rounds, and replacing your card number is often the only real solution.

Why would a fraudster target me?

That's precisely the point: They are not targeting you specifically. Card testing is not a targeted attack, but an industrial process in which bots attempt millions of numbers at random. Your card may be present on that list because you made a payment at an online shop that was later hacked, because your details were stolen in aphishing attack, or simply because an algorithm generated your card number by accident.

How can you protect yourself?

1. Check your statements and look at small amounts

The most important lesson to learn from this blog is to take every unknown transaction seriously, no matter how small it may be. A €0.30 transaction that you can't remember deserves as much attention as one worth €300.

2. Enable notifications for each transaction

Set up your banking app to notify you of every payment. Doing so will allow you to see a suspicious test on your statement in seconds instead of weeks later.[LV1]

3. React to suspicious transactions immediately

Don't recognise a transaction? Contact your bank straight away to have your card blocked and replaced. Simply disputing the suspicious payment is not enough – if your card number has been validated by fraudsters, the misuse will return sooner or later. You can call Keytrade Bank on +32 (0)2 679 90 00 or block your payment cards by contacting Card Stop on +32 (0)78 170 170.

4. Be cautious when using your card details

Do not store your card number in online shops and never enter it on pages you ended up on by clicking on a link in an email or ad. The fewer online shops that have your details, the lower the chances of a data leak.

5. Make use of your card's security features

Lower your spending limits to what you actually need and turn off features such as payments outside Europe if you don't use them. Doing so will limit the damage if your card number falls into the wrong hands.

6. Look beyond the card itself

Card details are often stolen together with passwords. If you notice a suspicious transaction, change the passwords for your most important accounts, starting with your email account, and use apassword manager to make sure you have unique passwords for all your accounts.

TIP Not sure whether a message, phone call or email is actually from Keytrade Bank? Use the call function in the Keytrade Bank app when calling us so you can be 100% sure you are speaking to an official member of staff.

Stay safe online with Keytrade Bank

At Keytrade Bank, we make security a top priority. If your bank details have been listed on a suspicious website, your personal details have been shared with an unknown person over the phone or you have spotted an unknown payment that you didn't make, you can call us on +32 (0)2 679 90 00.