Order notes need an order to exist. The attempts that never became one live in logs or nowhere, and logs only record what was running at the time.
A BIN attack fixes one bank’s card range and varies everything else. Here is what that leaves behind in your own order data, and what it does not.
Eight labels, and most shops use three. Failed is a decline rather than an abandonment, and draft exists only because of the block checkout.
The decline reason your gateway gave is rarely on the order screen. It is in the notes panel beside it, written by machinery rather than by a person.
WooCommerce ships a second payment surface for orders that already exist. It calls your gateway directly, and none of your checkout validation runs there.
Failed orders are declines, not abandoned baskets. And the row count is not the attempt count, because WooCommerce reuses an order when the basket has not changed.
Bursts of small failed authorisations, repeated addresses and throwaway emails look nothing like ordinary declines. Here is how to tell them apart with evidence you already have.