Skip to main content

Serra: The Beast of Small Bites

Card testing attacks start under the radar: tiny repeated transactions, low-value attempts, and rapid retries until a valid payment method is found.

You've captured Serra. Your next trail clue is unlocked at the bottom of this page.

The Serra, or sawfish, hunts prey with small, repeated strikes of its blade-like fin. Card testers bombard your checkout the same way, sending small transactions to test their fraud attempts.

How to prevent Serra's attack

Card testing is how fraudsters validate stolen card numbers. Automated scripts push many small, low-value transactions through your checkout, usually from bots rotating IPs and browser fingerprints, and every approval confirms a live card that can be resold or used for larger fraud. Because each attempt looks like a harmless failed payment, the attack often runs for days before anyone notices.

The damage goes beyond the test transactions themselves: authorization fees per attempt, chargebacks, and a declining approval rate with your payment processor. Defenses that only count requests miss it. Effective prevention looks beyond simple rate limits and inspects browser behavior, automation signals, session patterns, and payment flow anomalies.

Serra bestiary card: the sawfish creature representing card testing attacks

Prevention checklist

  • Watch failed authorization rates per session, card, and IP. Spikes in low-value declines are the earliest signal.
  • Inspect browser behavior and automation signals, not just request counts. Card-testing bots rotate IPs faster than rate limits can follow.
  • Detect headless browsers and automation frameworks before traffic reaches the payment step.
  • Challenge or throttle suspicious sessions selectively instead of adding friction for every customer.
  • Review the scripts running on your checkout. Compromised third-party code can leak card data alongside the testing traffic.

Risk signals and how to respond

Many low-value payment attempts

What it may indicate Automated card testing
Response Challenge, block, or throttle suspicious sessions

Repeated failures across cards

What it may indicate Credential and payment enumeration
Response Detect repeated behavioral patterns

Similar browser fingerprints

What it may indicate Bot-driven attempts
Response Use client-side and server-side signals together

Sudden checkout spikes

What it may indicate Coordinated abuse
Response Alert, segment, and review traffic sources

What it looks like in cside

cside AI Agent Detection dashboard showing traffic breakdown, automation sources, and suspicious sessions

Automated traffic and session signals

cside surfaces cloud agents, headless browsers, and suspicious sessions: the automated traffic behind card testing.

cside PCI DSS dashboard showing weekly script and security header changes on payment pages

Checkout script and header monitoring

Continuous monitoring of the scripts and security headers on your payment pages, with weekly change tracking.

Next Trail Clue

The next creature is still hidden. This clue will point players toward the next cache once the final location is confirmed.

CLUE PLACEHOLDER: [Insert next location riddle here]

Keep this page bookmarked. The riddle appears here when the trail opens.

Book a demo