A greeting card or gift shop protects customer card data by keeping checkout on a PCI-compliant payment processor, switching on address verification and CVV checks, and watching for small test charges. Those three habits stop most card-testing attacks before a stolen number ever reaches a criminal marketplace.
Why card data rules matter for a small gift shop
Card networks fine merchants that store full card numbers in their own systems. A gift shop that writes numbers on paper order forms or leaves them in an email inbox carries that risk for no business gain.
Customers notice too. A single breach at a three-person shop can cost more in lost trust than the fraud itself, since greeting cards and gifts are repeat purchases bought for birthdays, weddings, and holidays.
What is a CVV shop, and why does it matter to you?
A CVV shop is an illegal online marketplace where stolen credit card numbers, including the three-digit security code on the back, are bought and sold. These sites run on card data taken from skimmers, phishing pages, and breached store databases.
Small gift shops get targeted because their checkout pages often run older software. Numbers stolen from a shop can appear on those sites within hours and get used to buy goods that are hard to trace.
Buying or selling card data is a crime in every market you ship to. The useful takeaway for a shop owner is defensive: keep your own checkout from becoming a source.
How do card-testing attacks hit gift shops?
Card testing works by running thousands of small purchases against a checkout to see which stolen numbers still work. A $1.00 greeting card order at 3 a.m. is usually a test, not a customer.
Attackers favor gift shops because digital gift cards arrive by email and resell fast. Physical items need shipping, which adds friction they avoid.
Warning signs to watch
- A burst of orders in a short window, all with different card numbers and similar email patterns.
- Many failed authorization attempts from one IP address.
- Orders where the billing address and shipping address sit in different countries.
- Gift card orders for round amounts, such as $50 or $100, placed back to back.
- Customer names with random strings or cardholder details that do not match the order.
Five steps to lock down your checkout
- Use a hosted checkout. Process payments on the processor's page, not yours. The card number never touches your server, which cuts your PCI scope to a short self-assessment.
- Turn on CVV and AVS checks. Decline orders that fail the security code or address match. This one setting stops most test charges.
- Set velocity limits. Cap the number of orders one IP address or card can place per hour. Most card-testing scripts break when a limit fires.
- Add a bot check at checkout. A CAPTCHA or a fraud-scoring service from your processor filters automated traffic before it reaches the payment step.
- Delay digital gift card delivery. Hold emailed gift cards for a few hours or until the order clears. Fraud rings resell codes within minutes.
How to pick a processor your shop can live with
Compare processors on PCI support, fraud tools, and chargeback fees rather than the headline swipe rate. A low rate means nothing if you spend your week fighting disputes.
- PCI Level 1 certification and a current attestation of compliance you can download.
- Tokenized card storage, so repeat gift buyers never re-enter full card details on your site.
- Built-in fraud scoring with rules you can edit, not a black box.
- Chargeback dispute help, including evidence templates for digital goods.
- No monthly minimum for seasonal shops that do most of their volume in November and December.
Ask each provider how they handle gift card orders specifically. Digital delivery is the one feature that decides how much fraud reaches your door.
What should you do if your shop gets hit?
Contact your payment processor first. They can reverse test charges, block the offending IP range, and walk you through the chargeback process.
Report the fraud to the FTC and to the FBI's Internet Crime Complaint Center. Both feed patterns into wider investigations, and the FTC report gives you a paper trail for your processor.
Reset admin passwords, check for user accounts you did not create, and install any plugin or theme updates you skipped. Attackers often leave a back door for a second run.
FAQ
Can a small gift shop accept cards without a full PCI audit?
Yes. When you use a hosted or tokenized checkout from a compliant processor, you usually qualify for the shortest PCI self-assessment questionnaire, SAQ A. You still confirm each year that your setup matches it.
Are paper order forms safe for card numbers?
No. Paper forms, email threads, and spreadsheets put you in PCI scope and create a record that is easy to lose or photograph. Take card details by phone only through a processor's keypad or virtual terminal.
How fast do stolen cards get used?
Often within hours. Stolen numbers have a short shelf life before the bank blocks them, so criminals test and spend fast. Quick detection matters more than a perfect prevention setup.
Does fraud protection slow down real customers?
Not much. Address checks and CVV prompts sit inside the normal checkout flow. Velocity limits and bot checks run in the background, and a real customer rarely notices.
Do I need to store card numbers to offer gift cards?
No. Store a token from your processor instead. The token handles refunds and repeat orders while the real number stays on the processor's systems, out of your reach and out of a thief's reach too.