The benign explanation, which is usually the right one
Most small unexplained charges are card verification. A merchant confirms a card is real and active by authorizing a token amount — commonly $0.00, $0.01 or $1.00 — and then releasing it.
You will see this when:
- Adding a card to a subscription service, marketplace or app store
- Starting a free trial
- Setting up a new recurring payment
- Booking travel or lodging in advance
- Adding a card to a digital wallet
The signature is clean: one small charge, from a service you just interacted with, that disappears within a few days without ever settling. Nothing was taken.
The malicious version
Card testing is what happens when someone has obtained card numbers — from a breach, a skimmer, or a purchase on a criminal market — and needs to know which ones still work.
They run very small charges, because small charges attract less scrutiny from fraud systems and from cardholders. A card that clears a $1 test is a live card, worth using or reselling. A card that declines is discarded.
The test is reconnaissance. The real attempt follows.
Telling them apart
| Signal | Verification | Card testing |
|---|---|---|
| How many | One | Several, often close together |
| Source | A service you just used | Unfamiliar, often unrelated to each other |
| Timing | Right after you did something | No connection to your activity |
| Outcome | Drops off, never settles | May settle; often followed by a larger attempt |
| Descriptor | The service's name | Unfamiliar, sometimes an opaque code |
The strongest single signal is whether you did something to cause it. A $1 hold the same day you started a trial is a hold. A $1.14 charge from a merchant you have never heard of, on a quiet week, is worth acting on.
What to do if you suspect testing
Do not wait to see what happens next. That is precisely the window the test exists to open.
- Call the number on the back of your card and say you suspect card testing. That phrase is understood and gets a faster response than describing a small odd charge.
- Ask for the card to be blocked and reissued. A live number is the asset. Reversing one small charge does not remove it.
- Review recent statements for other small unfamiliar amounts — testing frequently comes in clusters that are easy to overlook individually.
- Check your recurring payments afterwards. A reissued number breaks legitimate subscriptions, and finding that out through a failed payment is avoidable.
- Report every unauthorized charge formally, including the small ones. On a debit card, your maximum liability rises the longer you wait, and prompt reporting is worth real money.
Where the number came from
Card testing implies someone already has your card number, and it is worth being clear that this rarely means your own device was compromised. The common routes:
- A merchant or processor breach. Numbers are taken in bulk from a business you paid legitimately, sometimes years earlier.
- Skimming. A physical device on a pump, an ATM, or a point-of-sale terminal.
- Phishing. A message that collected the number directly, sometimes long before it is used.
- Bulk resale. Numbers change hands in volume, and the buyer tests before using — which is why a test can arrive long after the original compromise.
The practical consequence: replacing the card resolves it, and changing your own passwords, while sensible, will not, because the number was not taken from you.
What happens if you wait
Testing is a prelude. What follows depends on what the number clears:
- Larger purchases, often digital or easily resold goods shipped to an address you have no connection to.
- Recurring charges set up quietly to persist, on the assumption a small monthly amount goes unnoticed.
- Resale at a premium, because a verified live number is worth more than an unverified one.
On a debit card this is materially worse than on a credit card, and not only because the money leaves your account immediately. Regulation E caps your liability on a sliding scale tied to how quickly you report — $50 within two business days of learning of the loss, $500 after that but within 60 days of the statement, and potentially unlimited beyond it. A test you decide to "keep an eye on" for three weeks can move you down a tier before the real attempt has even happened.
What reporting actually achieves
People hesitate over small amounts because reversing $1.14 feels disproportionate. Reversing the charge is not the point:
- The card gets blocked, which is the only thing that stops the sequence above.
- The number is flagged across the network, which affects its resale value and its use elsewhere.
- Your liability position is locked in at the best tier, before anything larger happens.
- Your bank has a dated record, which matters if a larger charge follows and the timeline is questioned.
None of that depends on the amount.
Where the small ones fit in the bigger picture
Small charges are over-represented among the charges people cannot identify, for a simple reason: an amount too small to correspond to a memorable purchase gives you nothing to reason from. The usual identification method — search your email for the amount — works poorly at $1.00.
That is what makes the pattern the useful signal rather than the individual charge. One small charge you can tie to something you did is routine. A cluster you cannot tie to anything is a card that needs replacing today.