Enumeration Attacks: Why Declines Count Against You
Visa's enumeration ratio counts declined transactions on both sides, so blocking a card testing attack does not remove you from the numbers.
By Jeffrey Anderson

- Visa defines an enumeration attack as the systematic or routine submission of card-absent transactions to fraudulently obtain or validate payment information. Most people call it card testing.
- The VAMP enumeration ratio counts enumerated authorization transactions, approved and declined, over total authorization transactions, approved and declined. Nothing has to settle to be counted.
- That makes it the opposite of the main VAMP ratio, which uses settled transactions. Blocking an attack protects your money but does not protect this ratio.
- The thresholds are an enumeration ratio at or above 2,000 basis points, which is 20% of authorization attempts, or an enumeration transaction count at or above 300,000.
- A small merchant crosses the ratio easily because the denominator is small. A large merchant is more likely to hit the absolute count. The two thresholds catch different businesses.
- The fact sheet requires acquirers to take proactive steps to prevent merchants exceeding these thresholds, which is why an acquirer may raise card testing before you have noticed it.
- Only controls that act before authorization help: velocity limits on IP, device and BIN, friction on the payment form, and removing exposed zero-dollar or tiny-amount endpoints.
Enumeration attacks are the reason a merchant can have a clean dispute record, settle almost nothing unusual, and still get a call from their acquirer. Visa measures them with a metric that counts declined transactions, so blocking the attack doesn't remove you from the numbers.
That's the part worth sitting with. Every other ratio in this area is built on settled transactions. This one isn't.
What Visa Means By Enumeration
The glossary is precise. An enumeration attack is "the systematic or routine submission of Card-Absent Environment Transactions into the Visa system to fraudulently obtain or validate payment information" (ID# 0030894, Visa Core Rules and Visa Product and Service Rules, 18 April 2026).
Most people call this card testing. Someone with a list of card numbers, often bought and of unknown quality, runs small transactions through a checkout to find out which ones work. Your site isn't the target. It's the instrument.
Low-value, high-volume checkouts get chosen for this because a $5 charge attracts less attention than a $500 one. That's why it lands so often on web hosting and similar low-ticket billing.
The Metric Counts Declines On Both Sides
Here is the formula, from Visa's Acquirer Monitoring Program fact sheet.
The VAMP Enumeration Ratio is the count of enumerated authorization transactions, approved and declined, divided by the count of authorization transactions, approved and declined.
Read that twice. Declines are in the numerator. Declines are also in the denominator. Nothing has to settle for any of it to count.
Compare it to the main VAMP ratio, which divides fraud and non-fraud disputes by the count of settled transactions. That one only notices transactions that completed. The enumeration metric notices attempts.
So the intuition most merchants carry, that a blocked attack cost them nothing because no money moved, is wrong in the one place it matters. Your fraud tool declining ten thousand card-testing attempts is a good outcome for your losses and a neutral-to-bad one for this ratio.
The Two Thresholds
The fact sheet sets two, and they work independently.
| Measure | Threshold |
|---|---|
| VAMP Enumeration Ratio | 2,000 basis points, meaning 20% of authorization attempts |
| VAMP Enumeration Transaction Count | 300,000 enumerated transactions |
The ratio looks generous until you think about what an attack does to a small denominator. A merchant running 2,000 legitimate authorizations a month needs only 500 enumerated attempts to cross 20%. A sustained attack produces that in an afternoon.
The count threshold works the other way. It's absolute, so it bites large merchants whose ratio stays low because their legitimate volume is enormous.
Your Acquirer Is Required To Act On This
The fact sheet doesn't frame these as informational. It says VAMP "requires acquirers to take proactive steps to prevent merchants from exceeding enumeration thresholds."
That's an obligation on your acquirer, which means it becomes pressure on you. It's also why an acquirer may raise card testing with you before you've noticed a problem yourself, and why "we blocked it all" is not the reassurance merchants expect it to be.
If you want the wider context on how these programs fit together, we've covered the monitoring programs and how the ratios are calculated separately.
What Actually Reduces Exposure
Since declining doesn't help the metric, the goal has to be stopping the attempts from reaching authorization at all.
Rate limiting before authorization. Velocity controls at the application layer, on IP, device and card BIN, keep the traffic from becoming authorization attempts in the first place. That's the single highest-leverage change, because it acts before the transaction enters the system where it gets counted.
Friction that costs an attacker more than it costs you. A CAPTCHA or a proof-of-work step on the payment form is invisible to most real customers and expensive at scale for an automated tester.
Kill the zero-dollar and tiny-amount paths. Account verification endpoints and $1 authorizations are the cheapest enumeration surface you can offer. If you expose one publicly, it will be found.
Tune screening for attempts, not just losses. Most fraud screening is measured on approved fraud caught. Ask your provider what it does with attempt volume, and whether it can drop traffic before authorization rather than declining at it.
3-D Secure on suspicious traffic. Risk-based authentication moves the decision upstream and gives an attacker a much less useful signal than a clean approve or decline.
The theme is consistent. Anything that turns an attack into a decline protects your money. Only the things that stop it becoming an authorization protect your ratio.
Frequently Asked Questions
What is an enumeration attack?
Visa defines it as the systematic or routine submission of card-absent transactions to fraudulently obtain or validate payment information. Most people call it card testing.
Do declined transactions count against me?
Yes. The VAMP enumeration ratio counts enumerated authorization transactions, approved and declined, over total authorization transactions, approved and declined. Nothing needs to settle.
What are the thresholds?
An enumeration ratio at or above 2,000 basis points, which is 20% of authorization attempts, or an enumeration transaction count at or above 300,000.
Why is my acquirer raising this when I blocked the attack?
Because the fact sheet requires acquirers to take proactive steps to prevent merchants exceeding the enumeration thresholds, and blocking at authorization doesn't remove the attempts from the ratio.
Is this the same as my chargeback ratio?
No. The main VAMP ratio divides fraud and non-fraud disputes by settled transactions. The enumeration ratio divides attempts by attempts, which is why the two can move in opposite directions.
What stops it?
Controls that act before authorization: velocity limits on IP, device and BIN, friction on the payment form, and removing exposed zero-dollar or tiny-amount verification endpoints.
Seeing card testing traffic and unsure whether it's showing up in your acquirer's numbers? Apply free or talk to a specialist and we'll look at where your attempts are being counted.
Jeffrey Anderson, Merchant Placement Specialist
Merchant placement specialist at Gray Merchants. Jeffrey works directly with acquiring-bank underwriting teams across the firm’s 70+ banking relationships to place high-risk and hard-to-place businesses, structure multi-MID accounts, and keep flagged merchants processing. His writing draws on the placement files he works every week: what underwriters ask for, why accounts get declined, and what keeps an approved account open.