card number is just a number.
with enough resources, time and automation, fraudster just whack the trx over and hope the issuer (eg bigpay) would accept it.
run through a long list of card numbers, sure it will hit.
those illegal and high-risk stuffs, there are security in place to prevent such txn to even get passed thru bigpay: filter from mastercard network and bigpay's fraud monitoring system.
if somehow bigpay accepted it, they will have hard time to explaining to BNM as these txn are highly illegal in Malaysia.
recent cases attacking bigpay is using social engineering hack to trick bigpay user to divulge certain info.
sure any gullible aunty uncle and even professional users would get tricked cuz of one fundamental weakness: we are human
system checking can only do so much without drastic impact to user experience and usage. block too much, the card is useless and mastercard would revoke bigpay's issuing licensed. block too little, user base would get annoyed due to ongoing scams targeting them.
most important is users are educated adequately to know and safeguard their card.
Touchwood i hvt received this kinda txn yet, and i believe most probably those data leaked due to we made txn using public wifi or public computer. Always logout or clear cache once u login with public computer as well