What a CVV is
A CVV is a 3-digit code printed on the back of most Visa, Mastercard, and Discover cards. American Express prints 4 digits on the front. The issuer generates a new code for each card.
Sensitive authentication data means the full magnetic track, the CVV, and the PIN block. PCI DSS Requirement 3.3.1 forbids storing that data after authorization. A merchant that keeps CVV numbers past the transaction is out of compliance.
What "buy CVV online now" listings sell
Sellers on carding forums, Telegram channels, and darknet markets offer card numbers with the CVV attached. The data comes from skimmers, phishing pages, and breaches. Some listings are fabricated. Others are burned, meaning the issuer closed the account.
Federal law covers this under 18 U.S.C. 1029. A card number plus its CVV is an access device. Buying, selling, or possessing one with intent to defraud is a felony. Prison terms reach 10 years for most counts and 15 or 20 years for others. Restitution adds to the cost.
Pitfalls in these transactions
- Buyers pay in crypto. There is no refund path, and no escrow that a court will honor.
- Card data gets resold. The same number can appear in dozens of listings.
- Sellers log buyer IP addresses and wallet IDs. Some use them for extortion.
- Testing a purchased number on a live merchant site is a separate federal offense.
The FTC reported $10 billion in consumer fraud losses for 2023, a 14 percent rise from 2022. Card fraud is a large share of that total. Merchants absorb much of the cost through chargebacks and lost inventory.
Legitimate options for card holders
If the goal is to shield a real card at checkout, issuers offer virtual card numbers. These are single-merchant or single-use numbers tied to the real account. Apple Pay and Google Pay replace the card number with a token, so the merchant never sees the CVV.
Legitimate options for merchants
Tokenization and 3-D Secure shift liability and cut card-not-present fraud. PCI DSS 4.0 adds controls for payment pages and scripts. If a site asks you to type a CVV into a chat window or a form on a non-checkout page, that request has no legitimate purpose.