In late August 2026, the donation page of Free Republic LLC became a target of card testing — attackers ran stolen card numbers through the form in bulk, checking which ones were still valid. The result: the payment processor cut off card donations, and the organization had to figure out how to get them back. The story matters to anyone who pays online — and especially to anyone who accepts payments.
What card testing is and why it gets accounts shut down
Card testing is when fraudsters take a database of stolen card data and probe it through a real payment form: small amounts, dozens or hundreds of attempts in minutes. To the site owner, it looks like a spike in declines and suspicious activity; to issuing banks, it looks like a red flag. Processors and anti-fraud systems react harshly: first they block suspicious transactions, then they may close the merchant's entire account to avoid chargeback risks and penalties from payment networks.
That's what happened to Free Republic: according to the incident description, a critical vulnerability on the donation page let attackers use it as a testing ground for cards. Until the vulnerability is fixed and protection is in place, the processor won't restore card payments.
What this means for everyday virtual card users
For those who pay for overseas services with virtual cards, there are two practical takeaways.
- Risk of false declines. If you make a series of small payments in a row or test a new card on an unfamiliar site, anti-fraud may flag the transaction as suspicious — especially if the card is new or the seller's region doesn't match your usual profile.
- Risk of card freezes. Banks and issuers see the pattern of "many small charges in a short time" and may temporarily freeze the card pending review. One-off purchases at trusted services don't trigger this, but attempts to "test" a card on shady platforms certainly can.
If you pay with a virtual card, it helps to keep a separate card for specific services and avoid mixing subscriptions, tests, and large purchases on one card. That way it's easier to pinpoint what caused a decline and restore access faster.
3DS, limits, and regions: what most often breaks a payment
Most online payment declines aren't about a "bad card" but about settings and payment context.
- 3DS. If the seller requires 3-D Secure confirmation and the card or service doesn't support the needed flow, the payment simply won't go through. For virtual cards, it's important that a confirmation code is available — via SMS, in an app, or by push.
- Limits. Many declines are caused by exceeding a daily or per-transaction limit. Before buying, check the card terms: virtual cards often have lower limits than classic bank cards.
- Region. A service may reject cards issued in certain countries or block payments from a specific region. Sometimes changing the region in your account settings helps, sometimes it doesn't: the seller's policy matters more.
- Mismatched details. The name, address, and country in the payment form must match what's linked to the card. Discrepancies are a common cause of declines with no clear explanation.
What to do if a payment fails
The practical order of steps is simple: check limits and card expiry, make sure 3DS is enabled, verify the region and payer details, try again on another day or with another card. If the decline repeats on one specific service while the card works elsewhere, the problem is likely on the seller's or its anti-fraud side, not with the card.
For those who accept payments, the lesson from the Free Republic story is clear: without protection against card testing and monitoring of suspicious activity, a merchant account can be closed at any moment. And restoring card acceptance takes far longer than setting up basic anti-fraud protection.
This material is for informational purposes only and is not financial advice.
A virtual card in 2 minutes
Pay for subscriptions, AI tools, travel, and international stores. Top up via USDT-TRC20 with no acquiring fees.