Skip to content
Risk & Compliance

Velocity Checking

Automated fraud detection analyzing transaction frequency patterns. Flags suspicious rapid-fire purchases from same source.

Overview

What is Velocity Checking?

Velocity checking is a fraud prevention technique that monitors and limits the frequency of transactions from the same source over specified time periods. By analyzing patterns like multiple cards from the same IP address, the same card to multiple shipping addresses, or rapid-fire purchase attempts within minutes, velocity checking identifies card testing attacks, account takeover fraud, and organized fraud rings. For high-risk merchants, velocity rules are essential - without them, fraudsters can test 50-100 stolen cards in under an hour, causing thousands in fraud losses and triggering fraud chargebacks that damage your processing relationship.

Card testing attacks are the primary target of velocity checking. Fraudsters obtain databases of stolen card numbers (often without CVV codes or expiration dates) and need to determine which cards are still active. They attempt small $1-5 purchases on your site to validate cards - successful authorizations indicate active cards they can use for larger fraudulent purchases elsewhere. Without velocity limits, a single fraudster can test 200+ cards in 30 minutes. Velocity rules blocking "more than 3 cards from same IP within 10 minutes" stop these attacks immediately, preventing fraud losses and reducing processor scrutiny.

Transaction velocity types include: Card velocity (same card used multiple times in short period), IP velocity (multiple transactions from same IP address), email velocity (same email for different cards/addresses), shipping address velocity (different cards to same address), BIN velocity (multiple cards from same issuing bank BIN range), and device fingerprint velocity (same device attempting multiple purchases). Each velocity type catches different fraud patterns - comprehensive fraud screening implements 6-10 velocity rules simultaneously.

Legitimate velocity must be accommodated. Family members ordering gifts, corporate purchasing departments, and high-frequency repeat customers can trigger velocity limits. Best practice implements smart velocity logic: strict limits for first-time customers (3 cards per IP per hour), relaxed limits for established customers (10 transactions per hour), and whitelist exceptions for known corporate accounts. This balances fraud prevention with avoiding false declines that harm revenue.

In depth

Everything you need to know.

Your fraud screening system tracks transaction metadata in real-time: IP addresses, email addresses, card BINs, shipping addresses, device fingerprints, and authorization timestamps. When a new transaction arrives, the system queries recent transaction history (typically 1-24 hour lookback windows) to count velocity metrics. For example, checking "how many transactions from this IP address in the past hour?" or "how many different cards used with this email in the past 24 hours?" The system compares actual velocity against configured thresholds: if threshold is "max 3 cards per IP per hour" and this transaction would be the 4th, it triggers a velocity violation. Based on configuration, the system either auto-declines the transaction, flags it for manual review, or allows it with increased fraud scoring. Modern velocity checking uses sliding time windows (counting transactions in last 60 minutes continuously) rather than fixed windows (resetting hourly) to prevent fraudsters from gaming the system by waiting for window resets.

Velocity checking prevents devastating card testing attacks that can destroy merchant accounts overnight. A fraudster testing 200 stolen cards at $2 each generates $400 in authorized transactions - harmless until all 200 cardholders dispute charges as fraud, creating 200 chargebacks. At $20 per chargeback fee, this single attack costs $4,400 plus potential monitoring program enrollment if it spikes your chargeback rate above thresholds. For merchants near 1% chargeback limits, a single card testing attack can push you from 0.9% to 1.6%, triggering Visa VDMP with $5K-10K monthly fines. Velocity limits prevent this entirely by blocking the attack after 3-5 test transactions. Beyond card testing, velocity checking catches organized fraud. Fraud rings often use multiple stolen cards to make large purchases shipped to the same address (package reshipping schemes). Without velocity limits, a fraud ring ships $10K-50K worth of products before you detect the pattern. Velocity rules blocking "more than 2 different cards to same address within 24 hours" catch this immediately, preventing massive fraud losses.

Illustrative example — not a specific client engagement.

  • A supplement merchant without velocity checking experienced card testing attack: fraudster tested 180 cards over 2 hours ($360 in $2 authorizations). All 180 charged back as fraud, creating $3,600 in fees and spiking chargeback rate from 0.8% to 1.9%, entering Visa VDMP. Implementing velocity limits (max 3 cards per IP per hour) would have blocked attack after 3 attempts.
  • An online course platform implemented IP velocity (max 5 cards per IP per hour) and caught fraud ring attempting to purchase $15K in courses with 12 stolen cards from same IP. All 12 transactions auto-declined by velocity rules, preventing $15K fraud loss and 12 future chargebacks.
  • A gaming platform set strict velocity (max 2 cards per IP per hour) but received complaints from Internet cafes where legitimate customers shared IPs. They created tiered velocity: 2 cards per IP for new customers, 8 cards per IP for IPs with 5+ successful purchase history. This preserved fraud protection while eliminating false declines from legitimate high-velocity locations.
  • Implement multi-dimensional velocity: card, IP, email, shipping address, device fingerprint - catching different fraud patterns
  • Set strict limits for first-time customers: max 3 cards per IP per hour, max 2 cards per shipping address per day
  • Relax limits for established customers: 10+ successful purchases without disputes earn trusted customer status with higher limits
  • Use sliding time windows (transactions in past 60 minutes) rather than fixed hourly resets
  • Configure actions by risk level: high velocity auto-declines, moderate flags for manual review, low passes with fraud scoring
  • Review velocity violations weekly: analyze what percentage are legitimate vs. fraud to optimize thresholds
  • For B2B merchants: create whitelist for known corporate customers with unique velocity profiles
  • Setting velocity limits too loose - allowing 20 cards per IP per hour doesn't prevent card testing attacks effectively
  • Using only card velocity - missing IP velocity and email velocity that catch different fraud patterns
  • Not whitelisting legitimate high-velocity customers - blocking corporate purchasing departments or repeat customers
  • Fixed time windows instead of sliding windows - fraudsters wait for hourly reset then test another batch
  • Not monitoring velocity rule effectiveness - setting rules but never reviewing how many flags are fraud vs. legitimate
  • Applying same velocity limits to new vs. established customers - treating trusted repeat customers like potential fraudsters
APPROVED

Put this to work
for your business.

MIDs structures high-risk acquiring across 30+ banks — smart routing, fraud and chargeback control built in. Tell us your category and volume and we'll build the setup around it.