ZHENESJAKOTHVIRUFRAR

Velocity Check

One-Line Definition

A velocity check is a fraud-prevention rule that flags or blocks a transaction when the same card number, IP address, email, device, or account exceeds a predefined number of purchase attempts within a set time window — catching stolen-card abuse before the money leaves the building.

Real-Life Analogy

Think of a bank teller who notices the same person walking up to the counter six times in one afternoon, each time withdrawing cash with a different ID but the same face. No single withdrawal looks illegal. The pattern does. A velocity check is that teller's instinct, automated and applied to digital payments: it doesn't judge any one transaction in isolation — it watches the *rhythm* of transactions and asks, "Does this pace make sense for a real customer?"

A legitimate shopper buying groceries buys once and leaves. A fraudster testing a batch of stolen cards on your checkout page hits "Pay" 40 times in 10 minutes because most cards will decline and a few will work. Velocity checks exist to catch that second behavior.

Core Formula

Velocity is fundamentally a count-over-time measurement. The generic form:

Velocity Score = Number of transactions in window W
                 ─────────────────────────────────
                 Threshold T for that attribute

If Velocity Score ≥ 1, the rule fires and the transaction is flagged for review, challenged with 3D Secure, or declined outright.

In practice, merchants run several velocity counters in parallel, each keyed to a different attribute:

AttributeExample ThresholdWindowTypical Action
Card number (PAN)3 attempts60 minutesDecline + alert
IP address10 attempts24 hoursStep-up auth (3DS)
Email address5 orders24 hoursManual review
Device fingerprint8 attempts1 hourBlock device
BIN (card issuer range)20 attempts1 hourRate-limit checkout
Shipping address4 orders48 hoursHold fulfillment

A real-world rule set might look like: *"Decline if the same card is used more than 3 times in 60 minutes, OR the same IP makes more than 10 payment attempts in 24 hours, OR the same email places more than 5 orders in a day."* Thresholds are tuned per merchant — a SaaS company billing monthly needs very different limits than a flash-sale fashion brand.

Comparison with Related Terms

Velocity checks are often confused with neighboring fraud tools. They overlap, but they are not the same:

TermWhat it measuresTime-sensitive?Example signal
**Velocity check***How many* transactions from one attribute in a windowYes — core to the logic6 card attempts in 10 min
**Amount check***How much* is being spentSometimes$4,000 order on a $50-average account
**Geo check***Where* the transaction originatesNoCard issued in Brazil, IP in Vietnam
**CVV/AVS check**Whether card data matches issuer recordsNoCVV mismatch on 3 of 4 tries
**Velocity + amount combo**Count *and* value togetherYes5 attempts totaling $9,000 in an hour
**Behavioral biometrics***How* the user types, swipes, navigatesYes (continuous)Bot-like form-fill speed

The key distinction: velocity is about frequency, not identity, geography, or amount. That's why it's cheap to implement and catches card-testing attacks that slip past static checks — a fraudster using a valid stolen card with a matching CVV still fails a velocity rule if they hammer your checkout 30 times.

Use Cases

1. Card testing (carding) prevention. Fraudsters buy lists of stolen card numbers and test them in bulk with small purchases. A velocity rule of "max 3 payment attempts per card per hour" kills this attack almost instantly. This is the single most common deployment.

2. Promo and coupon abuse. A user creates 12 accounts from one IP to redeem a first-order discount 12 times. IP and device velocity caps stop it without punishing genuine customers.

3. Account takeover (ATO) detection. After stealing login credentials, attackers often place several orders quickly before the real owner notices. An email or account velocity check triggers a step-up challenge.

4. Refund and chargeback rings. A small group of accounts repeatedly buys and refunds to launder money or abuse return policies. Velocity on refund requests per account surfaces the ring.

5. Cross-border expansion risk. When a merchant launches in a new market, fraud rates spike because the fraud team has no history. Velocity rules act as a fast, configurable safety net while the team builds market-specific models.

6. Bot and scalper control. Limited-edition drops attract bots that submit thousands of orders per minute. Device and IP velocity caps throttle them.

Misconceptions

"Velocity checks stop all fraud." No. They stop *high-frequency* fraud. A patient fraudster who uses one stolen card for one purchase looks identical to a normal customer on velocity alone. Velocity must be layered with AVS, CVV, 3DS, and behavioral signals.

"Higher thresholds are safer for conversion." Loosening thresholds reduces false declines but lets carding through. The trade-off is real: too tight, you block legitimate repeat buyers (think a family sharing one IP buying gifts); too loose, you eat chargebacks. Most teams tune thresholds by running rules in "monitor only" mode for 2–4 weeks first.

"Velocity = rate limiting." Rate limiting is a *technical* control that caps requests per second to protect infrastructure. Velocity checks are a *risk* control that evaluates transaction patterns to protect revenue. They can share a time window, but they serve different masters.

"One rule covers everything." A single global threshold is a blunt instrument. Mature setups use attribute-specific, segment-specific rules — different limits for new accounts vs. 5-year customers, or for digital goods vs. physical shipping.

"It's a set-and-forget rule." Fraudsters adapt. A threshold that caught 90% of carding last quarter may catch 40% this quarter as attackers slow down to 2 attempts per hour. Velocity thresholds need periodic re-tuning against fresh fraud data.

Related Terms

- Card testing / carding — the attack velocity checks are most often deployed against.

- Rate limiting — infrastructure-level request throttling, often confused with velocity.

- 3D Secure (3DS) — step-up authentication frequently triggered by a velocity flag.

- Device fingerprinting — supplies the device attribute velocity rules track.

- BIN attack — a form of card testing that cycles through many cards in one issuer range.

- Chargeback — the financial loss velocity checks aim to prevent.

- Risk scoring engine — the system that aggregates velocity, geo, amount, and behavioral signals into one decision.

- False decline — the main cost of setting velocity thresholds too aggressively.