• Developers
  • Reporting
  • Disputes
  • Contact us
  • Log in
Global Payments
Global Payments

Main Navigation

  • Account

      Account

        • Customer docs & pricing

          Find important documents such as our Terms of Service and Merchant Operating Instructions, as well as more information on things like Stored Credential Transactions and the Account Updater Service

        • Compliance & security

          For more information on Strong Customer Authentication, PCI Compliance, and fraud prevention best practices

        • Stationery ordering

          Order your tally rolls, card scheme logo stickers, and more

        • FAQs

          Our FAQs can help you with queries including pricing changes, cleaning and restarting your terminals, and Multi-Factor Authentication

  • Products

      Products

        • POS help
        • Ecommerce help
        • Bank Payment
  • Insights
  • Trending Articles
Sign up
Search
Global Payments

Main Navigation

  • Account
      Account

      Account

    • Customer docs & pricing
    • Compliance & security
    • Stationery ordering
    • FAQs
  • Products
      Products

      Products

    • POS help
    • Ecommerce help
    • Bank Payment
  • Insights
  • Trending Articles
    • Developers
    • Reporting
    • Disputes
    • Contact us
    • Log in
    Sign up /en-gb/sitecore/content/gpn/corporate/corporate/home/modals/signup-homepage

Sidebar Navigation

  • Account -
    • Carding attacks -
      • Carding FAQs -
    • FAQs +
      • Carding FAQs +
      • Are you ready for PCI DSS v4.0? +
      • PCI Frequently asked questions +
      • Pricing frequently asked questions +
      • Best practice for cleaning your POS device(s) +
      • Terminal restart guide +
      • CNP FAQs - resubmitting declined transactions +
      • Multi-Factor Authentication for Global Payments Ecommerce Portal +
      • Ecommerce FAQs +
      • Bank Payment FAQs +
      • How do I make a complaint +
      • Your invoice explained +
      • PSR FAQs +
    • Customer Docs & Pricing +
      • Terms of Service +
      • Merchant Operating Instructions +
      • Interchange fee update +
      • Recovered card form +
      • Mastercard and Visa Interchange rates +
      • Enhanced Authorisation Data Service merchant implementation guide +
      • Stored Credential Guide +
      • SCT Decision Tree +
      • SCT Technical Implementation Guide +
      • Account Updater Service +
      • Account Updater migration to UK Ensurebill +
      • Migrating your payments data securely +
    • Compliance & Security +
      • Are you ready for PCI DSS v4.0? +
      • PCI Frequently asked questions +
      • Ecommerce fraud management +
      • Know the risks +
      • Online Card Not Present Best Practices +
      • Fraud Hints and Tips Guide +
      • Reducing Risk of Fraud Guide +
      • Guide to Patching +
      • What To Do If You're Compromised +
      • SCA +
        • One-off payments without saving card details
        • One-click payments without saving card details
        • Card saved for recurring, automatic payments
        • Payment over the phone (MO/TO)
        • What Do I Need to Do to Be SCA Compliant?
        • PSD2 and SCA Technical Information Guide
        • Strong Customer Authentication Decision Tree
        • How to use the Strong Customer Authentication (SCA) Authentication Outage Indicator
    • Stationery ordering +
    • How do I understand my invoice? +
  • Products +
    • Point of Sale Help +
      • Ingenico guides +
        • Desk 5000 Quick Start Guide
        • Desk Series User Guide
        • Lane Series Quick Start Guide
        • Move Series Quick Start Guide
        • Move 3500 User Guide
        • Move 5000 User Guide
      • Mobile Pay guides +
        • Miura M10 Device user guide
        • Miura M20 Device user guide
    • Ecommerce Help +
      • Transaction management +
      • Customer management +
      • Fraud Management +
      • Resetting your password +
      • Virtual Terminal +
      • Ecommerce portal navigation +
      • User Management +
      • Transaction reporting +
      • Ecommerce FAQs +
    • Bank Payment +
      • Bank Payment FAQs +
      • Bank Payment sales sheet +
  1. Home
  2. Account
  3. Carding attacks
  4. Carding FAQs
Last updated 08/30/2024
2 Min Read Time

Carding FAQs

What is a carding attack? 

Carding is a type of payment fraud. The process starts with card thieves, or 'carders' who steal a large amount of credit/debit card details through scams, such as phishing, skimming or hacking. The cards are then tested in bulk against a payment processing system to check their validity. They will then try to make unauthorised online transactions, purchase gift or prepaid cards and generally misuse the card information for financial gain.

What can I do to protect my business from carding attacks? 

There are many ways you can protect your business from fraudulent carding activity including: 

3D Secure (3DS)

We’ve been working with our partners and other acquirers to launch 3DS to ensure all transactions are verified to the highest level–reducing the risk of fraud and chargebacks as a result of carding attacks. 

3DS is a customer authentication service introduced by Visa, Mastercard and American Express. The service is individually branded as Verified by Visa, Mastercard SecureCode and American Express SafeKey. It’s designed to protect you and the cardholder from fraudulent ecommerce transactions by adding an extra layer of security for online credit and debit card transactions. Cardholders are asked to key in a personal passcode after their card details have been entered.

CAPTCHA

Implementing a CAPTCHA on your website could also interrupt a fraudster’s carding attempt on your website. 

A CAPTCHA will help to distinguish human from machine input to reduce spam and automated insertion/extraction of data from websites. It presents a random sequence of distorted letters and/or numbers that is simple for humans to identify, but difficult for machines and bots. Speak to your web developer about adding a CAPTCHA to your website. 

Fraud Management

You can add fraud rules and checks to help validate transactions and decide whether to continue and fulfil your orders. These rules can be adapted to your personal risk preferences, helping to protect you against potential fraudulent activity.

Our Fraud Management product executes a series of rules configured by you, at the time the transaction is authorised, that can PASS, HOLD or BLOCK transactions automatically. It can help you identify suspected fraudulent transactions. Visit our Fraud Management page for more information on our service.

Will you notify me if you suspect a carding attack on my payment facility? 

Due to the nature of carding attacks, they are not always apparent until they are already underway. If we do identify a pattern of ongoing transactions that we suspect could be fraudulent, we may disable your account from processing further transactions. We’ll attempt to contact authorised people within your business to discuss this and suggest steps to remediate the security on your website. This can be via telephone or email, depending on the contact information we have available for you, so it’s important to ensure your contact details are up to date with us at all times.

We process millions of transactions every day for businesses all around the world - what may seem like fraud to one business may not be treated the same by another business. With this in mind, it’s solely the responsibility of the business to ensure you have the necessary control measures in place to prevent fraudulent activity on your payment facility.

Are there fees associated with a Carding Attack?

Yes. We charge for all transactions that interact with the card issuing banks, such as for authorisations and declines. The payment brands may also impose integrity fees. To avoid these, you must implement controls to ensure good data quality in authorisation requests. Any attacks will be subject to transaction charges.

Contact information

If you have any questions, or would like to discuss how we can help your business reduce the risks of carding, email us at  [email protected] or call IRE: +353 (1) 702 2000* or UK: +44 (0) 203 026 9659*.

 

*Lines are open from 8.30am to 6pm, Monday to Friday, except public holidays. If you have a speech or hearing impairment, you can call us using the Relay Service by dialling 18001 followed by the number you want to call. Calls may be recorded. To help us continually improve on our service and in the interests of security, we may monitor and/or record your telephone calls with us. Any recordings remain our sole property.

  • Account
  • Products
  • Customer Docs & Pricing
  • Compliance & Security
  • Insights
  • Trending articles
  • Notices and Policies
  • Sitemap

Already a customer?

Log in

Connect

  • LinkedIn Logo LinkedIn
  • X (Twitter)
  • Facebook Logo Facebook
  • YouTube Logo YouTube
 

Global Payments is a trading name of GPUK LLP. GPUK LLP is authorised by the Financial Conduct Authority under the Payment Services Regulations 2017 (504290) for the provision of payment services and under the Consumer Credit Act (714439) for the undertaking of terminal rental agreements. GPUK LLP is a limited liability partnership registered in England with company number OC337146. Registered Office: Granite House, Granite Way, Syston, Leicester, LE7 1PL. The members are Global Payments U.K. Limited and Global Payments U.K. 2 Limited. Service of any documents relating to the business will be effective if served at the Registered Office.

Global Payments is also a trading name of Pay and Shop Limited. Pay and Shop Limited is a limited company registered in Ireland with company number 324929. Registered Office: The Observatory, 7-11 Sir John Rogerson's Quay, Dublin 2, Ireland. Service of any documents relating to the business will be effective if served at the Registered Office.

© 2025 GPUK LLP. All rights reserved. Privacy Statement | Terms of Use  | Ethics Reporting Hotline | Gender Pay Report  | Anti Slavery StatementCookie Settings