Is it legal to buy fullz or CVV data online?
No. Buying fullz, CVV numbers, or any card data that belongs to someone else is a federal crime in the United States. No licensed marketplace, broker, or vendor sells this material. Any site, chat group, or forum that offers it is trading in stolen property.
That answer holds whether you are the buyer, the reseller, or the person running the storefront. All three roles fall under the same federal statutes.
What does "fullz" actually mean?
Fullz is slang for a bundle of one person's personal and financial data sold as a single package. The name comes from "full information." Sellers price it higher than a lone card number because a complete profile supports identity theft, not just one fraudulent purchase.
Fullz and CVV Dumps: Why Buying Them Is a Losing Bet
A typical fullz listing can include:
- Card number, expiration date, and CVV
- Full name, billing address, and phone number
- Date of birth and Social Security number
- Address history, mother's maiden name, or security answers
- Bank login, email access, or government ID images in premium bundles
Each item on that list is a separate piece of regulated personal data. Combining them raises the severity of the crime under federal sentencing rules.
What penalties come with buying card data?
Federal law treats access device fraud under 18 U.S.C. Section 1029. Trafficking in card numbers carries prison terms that reach 10 to 15 years depending on the offense, plus fines and restitution.
Aggravated identity theft under 18 U.S.C. Section 1028A adds a mandatory two-year sentence that runs consecutively to the underlying fraud count. States stack their own charges on top. Prosecutors also pursue asset forfeiture of the crypto, hardware, and devices involved.
Buying one card is enough to trigger a charge. Investigators do not need a warehouse of stolen data to build a case.
Why do fullz purchases end in a scam?
The market runs on thieves defrauding other thieves, so the buyer has no recourse. Common outcomes include:
- Sellers take crypto payment and disappear with no data delivered
- Delivered cards were already reported stolen and get declined on first use
- Buyers are doxxed and blackmailed with their own payment trails
- Some storefronts are honeypots run by law enforcement
The FBI and its international partners have seized carding market infrastructure and indicted the operators along with active users. Buyers who believed they were anonymous showed up in those indictments.
How do you protect your own CVV and card data?
The CVV (card verification value) is the 3-digit code on the back of most cards and the 4-digit code on the front of American Express. It exists to prove the physical card is in hand during a card-not-present transaction. PCI DSS Requirement 3.2 prohibits merchants from storing that value after a transaction is authorized.
Practical steps that reduce your exposure
- Use virtual card numbers from your bank or a privacy tool for online checkout
- Turn on transaction alerts so every charge pings your phone
- Lock the card in your banking app when you are not shopping
- Never enter card details on a page reached from an unsolicited text or email
- Keep unique passwords on retail and email accounts, since account takeover often precedes card fraud
- Check statements for small test charges of $0.50 to $3
That last point matters. Card testers run tiny charges to confirm a number works, then follow with a large purchase. Report the small charge, because it is the same fraud event.
How do you spot a card-testing attack as a merchant?
Watch for a burst of low-value orders from one IP range, mismatched billing and shipping data, and repeated declines followed by approvals. Enable address verification and CVV checks in your gateway, and use rate limits on checkout. Fraud filters from your processor catch most of this before settlement.
What should you do if your card data is stolen?
- Freeze the card in your bank app or call the number on the back.
- Dispute the charges with the issuer in writing.
- Change passwords on your email, bank, and retail accounts.
- Report the theft at IdentityTheft.gov and file a police report if requested.
- Place a credit freeze with Equifax, Experian, and TransUnion.
Your liability is limited. Under the Fair Credit Billing Act, credit card holders owe no more than $50 for unauthorized charges, and nothing if the card never left their hands. Debit card protection is weaker: report within two business days to cap losses at $50, and within 60 days to cap them at $500.
Frequently asked questions
Are fullz sites real?
Some are real storefronts, but every one of them sells stolen data. Others are pure scams or stings. There is no legitimate version of this market.
Can I buy a card number to test my own payment system?
No. Use the sandbox test numbers your payment processor provides. Running real card data through a test environment breaks card network rules and PCI DSS.
Does a CVV stop fraud?
It blocks simple card counterfeiting, but it does not stop phishing, breach-based account takeover, or card testing. Treat it as one layer of defense, not a guarantee.
Is using a VPN enough to stay anonymous?
No. Payment trails, device fingerprints, shipping records, and chat logs all create evidence. Cases are built on those records, not on the connection alone.
The bottom line
There is no legal path to buying fullz or CVV data online, and no safe one either. The money usually vanishes, the data is often dead, and the legal exposure is real. If your goal is cheaper or safer card payments online, virtual card numbers, alerts, and card locks deliver that without the felony.