1 / 2
One thief in an afternoon
Toby shipped a rule that bans anyone who tries the same card nine times, then tested checkout with his own card. It has caught exactly one thief.
The mistake
The fraud rule flags and bans any account that submits the same card number a set number of times (here, nine), treating repeated attempts as card-testing fraud. It has no allowlist or exemption for internal test traffic, so when Toby manually retests checkout with his own real card that afternoon, his own account trips the exact threshold the rule was built to catch. The rule works as designed; it just can't distinguish a developer's manual QA from an actual attacker probing stolen card numbers.
- fraud-rules
- checkout
- testing
- ecommerce
- release