Fraudsters deploy bots on merchant’s payment processes to either test stolen-credit-card-numbers or build complete cardholder dataset. Web application firewall defenses are not capable of detecting carding and card cracking attempts. Gift cards and loyalty programs are highly susceptible to token cracking. Such attacks decipher valid coupon numbers, voucher codes, etc.