Hackers used the attack as a means to verify if the payment cards they stole works, using a series of $0 transactions through the use of PayPal Payflow Pro module that is integrated with Magento 2.1.x and 2.2.x shopping cart system. These stolen credit card information were from credit card skimmers, a small device that can copy the user information from a magnetic-stripe card for use in fraudulent transactions online. Hackers were able to confirm what particular cards are still operational and those cards that are no longer valid, at the expense of websites using Magenta online shopping cart.”]
Source: https://hackercombat.com/fraudulent-transactions-using-stolen-credit-card-continues/