What a CVV is

A CVV is a 3 or 4 digit code on a payment card. Visa calls it CVV2. Mastercard calls it CVC2. American Express calls it CID and prints 4 digits. The code sits on the card or inside the cardholder account. Merchants do not keep it after a transaction completes.

Buying CVV Online: A Comprehensive Buying Guide

What "CVV shops" sell

Sites that advertise fresh CVV data sell card numbers, expiry dates, cardholder names, and billing ZIP codes taken from other people. Listings show a "valid rate," a percentage of cards that still approve a charge. Prices run from about $5 for an unchecked card to $100 or more for a card with a confirmed balance. Payment is in bitcoin or another crypto asset.

Can You Buy a CVV Online? Legal Risks and Safe Payment Options

Why no trusted source exists

A trusted source cannot exist in this market. Every card in a shop was taken without consent from its owner. A seller with a lawful supply would sell to card networks, not to anonymous buyers on a hidden site. Ratings and reviews on those sites come from the same accounts that operate them.

buy cvv online store

Legal position in the US

18 U.S.C. § 1029 covers fraud and related activity in connection with access devices. Buying, selling, or holding stolen card data carries up to 10 years in prison and fines up to $250,000 for a first offense. One card is enough to charge. Prosecutors add identity theft counts under 18 U.S.C. § 1028A, which carries a 2 year mandatory term served after the first sentence.

more on this topic

Pitfalls buyers report

  • Exit scams. The shop takes payment and closes the buyer account. There is no recourse, because the transaction itself is illegal.
  • Data harvesting. Checkout pages log wallet addresses, IP addresses, and contact details, then sell those records to other shops.
  • Dead cards. A card can be canceled between listing and purchase. A 60% valid rate means 4 of every 10 cards fail.
  • Test charges. A small charge to confirm a card works alerts the cardholder and the issuing bank.
  • Device malware. Files sold as card checkers or generators often carry credential stealers.

Merchant rules that limit the data

PCI DSS Requirement 3.3.1 forbids storage of sensitive authentication data, including the CVV, after authorization. A leaked CVV points to a breach at the issuer, a skimming device, or a phishing page. It does not point to a merchant database.

Protection steps for cardholders

  • Turn on transaction alerts for every charge.
  • Use a virtual card number for online merchants. Those numbers lock to one merchant and expire.
  • Do not read a CVV aloud on a call. No bank asks for it.
  • Check statements each week. Report unknown charges within 60 days under Regulation Z.
  • Freeze the card in the issuer app when a charge looks wrong.