Platform Setup: Understanding Card Testing & Fraud Prevention
Online fundraising platforms across the sector continue to experience increased levels of fraudulent payment activity, including stolen card testing, spam donations, and automated bot attacks.
These incidents can feel alarming, especially when your organization's name appears connected to fraudulent transactions. In most cases, however, the organization itself is not being specifically targeted. Instead, fraudsters are typically attempting to validate stolen credit card details by processing small transactions through public-facing payment forms.
Because charity donation forms are intentionally designed to provide a fast, low-friction experience for genuine supporters, they can become attractive targets for automated payment testing and spam activity.
The Funraisin platform includes several built-in security measures and integrations designed to help reduce this risk across donation forms and payment flows.
This article explains how card testing works, how Stripe Radar fits into fraud prevention, and the steps your organization can take to help reduce fraudulent activity across your platform.
What is card testing?
Card testing is a type of payment fraud where attackers use stolen credit card details to attempt small online transactions and confirm whether the card is still active.
Fraudsters will often:
- Process very small donations.
- Attempt multiple transactions in quick succession.
- Use automated bots or scripts.
- Target low-friction payment forms.
- Test cards before using them elsewhere for larger fraudulent purchases.
Online donation forms are a common target across the fundraising sector because they are designed to make payment processing as easy as possible for legitimate supporters.
What should you do if your platform has been targeted?
If your organization identifies suspicious or fraudulent donations, take the following actions immediately.
- Refund suspicious transactions immediately
Refunding fraudulent donations quickly helps:
-
- Prevent legitimate cardholders from seeing your organization's name attached to fraudulent activity.
- Reduce the likelihood of disputes or chargebacks.
- Minimize Stripe dispute fees, which can commonly range between approximately $20–$50 per dispute.
- Flag the activity with Funraisin
Notify the Funraisin Support team as soon as possible if card testing or other suspicious payment activity is identified. This helps the Funraisin Support team to:
-
- Review activity patterns.
- Monitor for broader platform-level attacks.
- Assist with preventative recommendations.
- Apply additional protections where appropriate.
When contacting the Funraisin Support team, include:
-
- Example transaction IDs.
- Dates and times of suspicious activity.
- Donation page URLs affected.
- Screenshots where possible.
- Mark fraudulent payments within Stripe
Stripe recommends marking suspicious payments as fraudulent within the Stripe Dashboard. This helps:
-
- Improve Stripe's fraud detection models.
- Increase future fraud monitoring accuracy.
- Assist Stripe in identifying broader fraudulent activity trends.
- Enable reCAPTCHA on all forms
Google reCAPTCHA is one of the most effective tools for reducing automated fraud activity across public-facing forms. reCAPTCHA helps reduce:
-
- Automated bot submissions.
- Card testing attacks.
- Spam registrations.
- Fraudulent donation attempts.
We recommend enabling reCAPTCHA across:
-
- Donation forms.
- Event registrations.
- DIY fundraising pages.
- Web forms.
Important: Enabling Google reCAPTCHA across all public-facing forms is currently the most effective protection against automated card testing, spam submissions, and bot-driven fraud activity.
What is Stripe Radar?
Stripe Radar is Stripe's fraud prevention system designed to help identify suspicious transactions before they are processed by the issuing bank.
According to Stripe, Radar analyzes hundreds of signals and attributes for every transaction, including device behavior, card patterns, IP data, geographic indicators, transaction history, and network-wide fraud trends.
Each payment is assigned a fraud risk score. Based on this score and the rules configured for the Stripe account, transactions may be:
- Allowed
- Flagged for review
- Blocked automatically
For more information, refer to the following Stripe resources:
Important: Funraisin does not manage your Stripe fraud settings
While Funraisin can provide general platform guidance and introduce additional platform-level protections, your Stripe account, fraud rules, and Radar configuration remain the responsibility of your organization.
Because every organization has different risk tolerances, donor audiences, and fundraising requirements, we strongly recommend reviewing Stripe's official documentation and speaking directly with Stripe if you require advice on configuring Radar rules or fraud thresholds.
Funraisin is unable to advise on:
- Specific Radar rule configurations
- Fraud score thresholds
- Custom blocking logic
- Stripe account-level security strategies
- Financial or chargeback risk decisions
For assistance configuring Stripe Radar, reviewing fraud settings, or investigating suspicious transactions, contact Stripe Support directly.
Does Stripe Radar stop fraudulent donations automatically?
Not always.
Standard Radar may:
- Flag suspicious transactions
- Increase review visibility
- Assist with fraud monitoring
However, depending on the Stripe plan and configured settings, some transactions may still proceed successfully unless additional blocking rules are in place.
Stripe also offers enhanced fraud tools, such as Radar for Teams. These are managed directly within the Stripe account and may involve additional costs.
Learn more about Stripe Radar pricing and features.
Using the Funraisin blocklist to reduce human-based fraud activity
While reCAPTCHA is highly effective at slowing automated bots and card testing attacks, some fraudulent activity may still come from real people manually submitting forms. In these cases, the Funraisin blocklist can be used as an additional layer of protection.
The blocklist can be used to proactively block suspicious users, IP addresses, email patterns, or other identifiable behavior directly within the platform.
Common signs of suspicious human-driven activity include:
- Repeated low-value donations from the same IP address.
- Multiple failed payment attempts in a short period.
- Similar donor names or email address patterns.
- High volumes of activity occurring outside normal supporter behavior.
- Repeated use of disposable or suspicious email domains.
If you identify a clear pattern, you can add the relevant information to the blocklist to prevent further submissions from those users.
Additional platform protections
To continue improving platform security, Funraisin may implement additional platform-level preventative measures from time to time, including:
- Country-based transaction blocking
- Spam prevention improvements
- Additional form validation
- Enhanced bot protection measures
These protections are designed to help reduce fraudulent activity across the platform while balancing legitimate donor access.
If your organization requires access from a blocked region or has custom fraud handling requirements, contact the Funraisin Support team.
Still need help? Check out our other support articles or reach out to the Funraisin Support team by logging a ticket through the Support Module in your platform.
Last updated: 2 Oct 2026


