How do bots drain gift card balances before the holidays?
Why gift cards are the perfect target
Gift cards combine three properties fraudsters love: they are bearer instruments, they are sold in predictable number sequences, and their balances are checkable online. Whoever holds the number and PIN holds the value, with no name attached and no chargeback possible. Many retailers generate card numbers sequentially or with weak randomness, which shrinks the search space dramatically. A bot does not need to guess all sixteen digits; it needs to guess the variable portion, which can be a few thousand combinations per batch.
The timing is seasonal and deliberate. Card balances peak after the winter holidays, when millions of cards sit in drawers with full value. The checking campaigns run quietly in the months before, building inventories of live cards with known balances. Draining happens fast once the inventory is built: balances get spent on high-resale goods or converted through marketplace listings. By the time the legitimate recipient tries to use the card, the balance is gone and the trail is cold. Retailers see the fraud as a customer service problem, a wave of complaints about empty cards, months after the actual attack.
How the checker bots stay invisible
The smart operations never touch checkout. They target the balance inquiry page, which most retailers built as a convenience feature with none of checkout's fraud controls. No velocity limits, no device fingerprinting, no risk scoring, just a number and PIN field that answers truthfully. The bots query it the way a legitimate customer would, one card at a time, from residential IP addresses that look like home broadband. Distributed across thousands of IPs, each one makes only a handful of requests per day, far below any threshold.
Some operations go further and mimic human behavior: random delays between requests, realistic browser fingerprints, session cookies maintained across queries. The tell is in the aggregate, not the individual request. A single IP checking three balances looks innocent; ten thousand IPs each checking three balances from the same number range is a campaign. Retailers that only look at per-IP rates miss it entirely. Detection requires looking at the number space: when balance inquiries cluster around sequential card numbers, that is not customers checking gifts, it is enumeration.
Where the drained value goes
The fastest outlet is direct spending. Drained cards buy electronics, sneakers, and other high-resale goods for same-day pickup or fast shipping, converting the balance to merchandise before the victim notices. Gift cards with large balances get split across multiple orders to stay under manual review thresholds. Some operations prefer digital goods and subscription credits, which deliver instantly with no shipping address to trace.
The second outlet is resale. Live card numbers with verified balances sell on fraud forums at a discount to face value, typically fifty to seventy cents on the dollar. The buyer takes the execution risk while the checker operation sticks to what it does best: finding balances. A third outlet is laundering through the retailer's own systems: buying other gift cards with the drained balance, which resets the trail and extends the card's life. Each hop makes the funds harder to follow, which is why speed of detection matters more than perfection of prevention.
Controls that stop the checking
The highest-leverage fix is also the simplest: stop answering strangers. Require account login before showing a balance, and the enumeration economics collapse, because every check now costs an account. If login-gating hurts the customer experience, the middle ground is rate limiting plus friction: CAPTCHA on the lookup page, strict per-IP and per-device limits, and progressive delays after failed attempts. The goal is not to make checking impossible for humans but to make it uneconomical at bot scale.
Then instrument the number space. Monitor balance inquiries for sequential patterns, unusual geographic spread on a single card range, and inquiry-to-redemption ratios that no human population would produce. Alert on the patterns, not just the rates. And close the loop with cardholders: notify the purchaser when a balance is checked from an unfamiliar device or location, the way banks do for card transactions. The retailers that beat gift card draining treat the balance lookup as a security boundary, not a convenience widget, and they assume every number sequence they have ever issued is already in someone's target list.
Can strong card number randomness alone stop this?
It raises the cost but does not stop it. Random numbers make enumeration slower, but bots are patient and compute is cheap. Randomness must be paired with lookup controls: rate limits, login requirements, and pattern monitoring. Either layer alone is bypassable; together they break the economics.
Should we remove the online balance checker entirely?
That punishes legitimate customers for a fraud problem. The better move is to keep the checker but put it behind light authentication or friction. Most customers check a balance once; bots check millions. Design for the difference.
What should we tell customers whose cards were drained?
Replace the value promptly and say so publicly. The reputational damage of empty gift cards during the holidays far exceeds the fraud loss, and fast replacement turns victims into loyalists. Then fix the lookup controls so the next campaign finds nothing.