← RetryHub

My processor disabled my account for card testing. What now?

Short answer: Card testing is when fraudsters run many small or rapid transactions through your checkout to check stolen card numbers. Processors often pause or disable processing when they see it, to limit fraud and fees. First, stop the attack: add bot protection, velocity limits, and 3D Secure where available. Then document what happened and respond to your processor. If the account is closed for good, apply for a new merchant account with that remediation evidence in the file.

Query focus: payment processing disabled card testing / abnormal number of transactions / processor shut off after bot attack

The notice usually mentions an “abnormal number of recent transactions,” fraud protection, or fee protection. From your side, it looks like a sudden flood of tiny authorizations and declines, often overnight, followed by processing being switched off. It is stressful because you did nothing to invite it, yet the account is the one paying the price.

This page explains why processors react this way, what to do in the first hours, and how to present the incident if you need a new merchant account.

RetryHub helps with merchant-account placement and underwriting prep; PayFresco is a separate payments + CRM / orchestration product.

Why processors disable accounts during card testing

Every authorization attempt costs something, and a wave of stolen-card tests produces declines, fraud reports, and later disputes. Card networks watch fraud and decline patterns at the merchant level, so acquirers act quickly to contain exposure. Disabling processing is a blunt tool, but from the acquirer’s perspective it stops fees and fraud from piling up while the merchant fixes the hole.

First hours: contain the attack

  1. Confirm it is card testing. Look for many low-value attempts, repeated failures, unusual countries or IP ranges, and new customer accounts with random details.
  2. Close the entry point. Add bot protection (CAPTCHA or similar) to checkout and account creation, and rate-limit payment attempts per IP, device, and session.
  3. Turn on stronger authentication. Use 3D Secure where your gateway supports it, and require address and security-code checks.
  4. Remove easy targets. Test products at very low prices, open donation fields, and guest checkouts with no friction are common targets.
  5. Refund or void any successful fraudulent charges before they turn into disputes.
  6. Tell the processor what you changed, with specifics and screenshots, and ask what they need to review reactivation.

What to document

Whether the account comes back or you move to a new one, keep an incident file: when the attack started, how many attempts and how many succeeded (from your own logs), what controls you added and when, and every notice from the processor. A clear timeline tells the next underwriter this was an attack you handled, not a pattern in your business.

If the account is closed: the path to a new MID

  1. Apply with your business details, region, volume, and a note that processing was disabled after card testing.
  2. Attach documents: owner ID, formation papers, bank letter, recent statements, website policies, the processor notice, and your incident file. Our document checklist covers the rest.
  3. Underwriting review. Expect questions about fraud controls, checkout design, and whether any fraudulent charges became chargebacks.
  4. Terms. Some acquirers may add a reserve or processing limits after an incident; see how reserves work.
  5. Go-live with controls in place. Connect the new MID only after bot protection, velocity limits, and 3D Secure are working, then test.

What not to do

If disputes followed the attack, our chargebacks guide explains how underwriters read that history.

How RetryHub helps

RetryHub treats a processing shutdown as urgent. We help merchants organize the notice, incident timeline, and statements into an application file and look for acquiring paths that fit the business. RetryHub is a placement and onboarding partner, not the bank. We cannot reactivate an account at another processor or promise a timeline, and approval is subject to underwriting. Where hosted 3D Secure is available for card-not-present processing, it can be part of your setup.

FAQ

What is card testing?

Card testing is when fraudsters use your checkout to run many transactions, often small ones, to find out which stolen card numbers still work. It creates declines, fraud reports, and later disputes.

Why did my processor disable my account instead of blocking the fraud?

Processors limit exposure quickly when abnormal volume appears. Disabling processing stops fees and fraud from building while you add controls. Ask the processor what evidence they need to review reactivation.

How do I stop card testing on my checkout?

Common steps include bot protection on checkout and account creation, rate limits per IP and device, 3D Secure, address and security-code checks, and removing very low-priced or open-amount items.

Will card testing stop me from getting a new merchant account?

Not necessarily. Underwriters want to see that the attack was contained and that controls are in place. A clear incident file helps, but approval is never guaranteed.

Should I refund fraudulent charges that went through?

Generally yes. Refunding or voiding them promptly can prevent chargebacks, which would add to your dispute history.

Is this a fit?

Related: Document checklist · Merchant account terminated · High-risk chargebacks · FAQ

Apply: retryhub.com/apply · Site: retryhub.com · Services: retryhub.com/services · Email: help@retryhub.com