Card testing / carding
Fires a list of stolen or generated card numbers at the store's own payment API to find which ones validate — "card testing" before fraudsters spend. Test cards only, validated and discarded (no real charges).
Sign in with your console account.
This console talks to the control-plane API. In token/dev mode, paste an API token. Behind Akamai EAA, you're signed in at the edge and this step is skipped.
Fires a list of stolen or generated card numbers at the store's own payment API to find which ones validate — "card testing" before fraudsters spend. Test cards only, validated and discarded (no real charges).
Hammers the product API and walks every product page to lift the entire catalog — prices, SKUs, stock — the recon a competitor or reseller runs before undercutting or reselling you.
A wave of bots across many source IPs races to buy up every unit of the scarcest, highest-value items before real shoppers can — overselling stock. The tell is volume + distribution.
Replays leaked username/password pairs against the login from many source IPs, hunting for reused passwords. Against the seeded demo users, ~8 of 100 accounts fall — the ones reusing breached passwords.
A single bot runs the whole kill chain from one IP: scrape the catalog → pick the priciest item → pay with an approved card → land a real order. The tell is automation/behaviour, not volume.
Every run targets your own demo storefront, which sits behind the Akamai suite in monitor mode — the attack passes through while Akamai logs exactly what it detects. Review those detections in the Akamai console after a run.
Configure a run and press Run to see live results here.
| When | Scenario | Target | Status | Findings | By |
|---|
| ID | Label | Base URL |
|---|
The field account is shared with pre-sales. Reset its password here to rotate access — anyone signed in on the old password is signed out.
| Username | Role | Set password |
|---|