What That Search Really Points To
Search those four words and you get a wall of storefronts with clean logos, price lists, and a checkout flow that looks like any other ecommerce shop. I have looked at enough of these pages to know the pattern. Behind the template is a carding market. The stock is other people's account numbers, expiration dates, and three digit verification codes. Nobody selling you those numbers owns them, and nobody buying them has permission to use them.
So here is the advice part, up front. There is no legitimate vendor, no buyer protection, no refund policy, and no version of this transaction that ends well for you. The rest of this page explains the mechanics and the penalties, because understanding both is the only useful thing I can offer someone who typed that query.
Why CVV Data Is the Piece Everyone Wants
The card number alone is half a key. The CVV2 on the back is the half that proves whoever is typing knows something only the cardholder should have. That is why card not present merchants ask for it, and why stolen CVV data commands a higher price than a bare card number on the underground markets. It is also why PCI DSS classifies it as sensitive authentication data that must never be stored after authorization.
The Legal Parameter Nobody Puts in the Sales Pitch
In the U.S., trafficking in card data falls under access device fraud, 18 U.S.C. § 1029. Possessing fifteen or more unauthorized access devices is enough to support a federal charge. Convictions carry fines and prison time measured in years, not months. Wire transfers and crypto both leave trails. Payment processors, hosting providers, and the FBI's Internet Crime Complaint Center all collect reports about the same markets. A storefront that vanishes overnight is not proof of a careful operator. It is proof that someone got hit.
Pitfalls Buyers Hit Every Single Time
- Dead stock. Cards get canceled within hours of a fraud report, so you pay for data that declines on first use.
- Exit scams. The seller takes the deposit and the site goes dark. There is no chargeback, because you cannot dispute a crime.
- Upsells and extortion. Some operators ask for a verification fee, then a release fee, then more.
- Malware wrapped in the deal. Checker tools and spreadsheets shipped with orders are a common delivery route for infostealers.
- Your own data on the menu. Plenty of these sites log buyer IPs and credentials. You become inventory.
- Sting operations. Some of those shops are staffed by people whose job is to identify buyers.
If You Run a Store, This Is Your Exposure
Every one of those searches is a person trying to push a fraudulent order through a real merchant. When I review a card not present setup, I look for three things: whether the CVV is genuinely verified and not just collected, whether the address verification result is enforced rather than logged and ignored, and whether high risk orders route to 3D Secure instead of auto-approving. If you store CVV after authorization, you are out of compliance with PCI DSS, and you have turned a breach into a catastrophe.
If Your Own Card Was Already Used
- Call the issuer and freeze the card. Ask them to note the fraud claim on the account.
- Pull twelve months of statements and dispute every charge you do not recognize.
- Change passwords on shopping accounts, and stop saving cards in browsers if you do not need the convenience.
- File a report at IdentityTheft.gov and with the FTC, then report the market to IC3.
The Bottom Line
There is no shortcut here, and the search itself is the warning sign. If you want to spend money on card security, spend it on a password manager, a virtual card number from your issuer, and transaction alerts on every account. That is a purchase you can actually complete, and it comes with a receipt.