Short answer

No. Selling CVV or CVC codes tied to someone else's payment card is illegal in the United States, and it has been since long before online shopping became normal. A CVV is a security credential that proves the person paying is holding the physical card or has lawful access to the account. Selling one means selling access to another person's money. Federal prosecutors charge that conduct as access device fraud, identity theft, or wire fraud, depending on how the data was obtained and moved.

read more

There is a narrow legal path, and it has nothing to do with selling codes. Banks, payment processors, fraud analysts, and security researchers handle card data every day under signed contracts, audited controls, and card network rules. If you are asking the question because you want paid work in payments or fraud prevention, the route is a job or a vendor agreement, not a marketplace listing.

Buy CVV with Bitcoin: A Secure Buying Guide

What the phrase "sell CVV" usually means

The wording gets used for a few different things, and all of the common ones are problems:

read more

  • Offering stolen three or four digit card codes, often bundled with card numbers and expiration dates, to buyers who then make unauthorized purchases.
  • Acting as a middleman for a card-checking service that tests whether stolen credentials still work.
  • Running an escrow or reputation scheme for a carding forum, which is the marketplace layer of the same activity.
  • Selling "fresh" or "fullz" records that combine card data with a person's name, address, or Social Security number.

In every one of those cases, the product is unauthorized access to a bank account. The fact that the seller never touches the plastic does not change the analysis.

related article

Why it is illegal

U.S. law treats the data on a payment card as an access device. The main federal statute is 18 U.S.C. 1029, which covers producing, selling, trafficking, and using counterfeit or unauthorized access devices. Courts have applied it to card numbers, magnetic stripe data, and the verification codes that authorize a transaction. A separate statute, 18 U.S.C. 1028, covers identity documents and identity theft when the card data is sold together with personal identifiers. Wire fraud charges under 18 U.S.C. 1343 typically follow when the data crosses state lines through the internet, which it almost always does.

State laws pile on top. Most states criminalize trafficking in personal identifying information and stolen financial records, so a single sale can trigger both federal and state counts. The volume of charges depends on the number of cards, the dollar amount of attempted purchases, and whether the government can show a pattern rather than a one-off.

What the penalties look like

Access device fraud carries statutory maximums that reach into the double-digit years of imprisonment for aggravated cases, and fines that scale with the loss. A first offense involving a small number of cards may resolve with probation, restitution, and a felony conviction. Cases involving hundreds of cards, organized distribution, or repeat conduct get treated far more seriously. Beyond the criminal exposure, a conviction blocks most jobs in banking, fintech, and information security, because those employers run fingerprint-based background checks and credit checks.

Civil exposure is real too. Card issuers and merchants can pursue damages for fraud losses, chargeback costs, and investigation expenses, and they often do so after a criminal case ends.

The legitimate version of this work

Companies do pay people to handle card security. The difference is authorization and scope:

  • Fraud analysts at issuers and processors review suspicious transactions under an employment agreement.
  • Payment security engineers build tokenization, so a merchant never stores the CVV after the authorization step.
  • Penetration testers assess payment systems only with written permission from the system owner.
  • Card network compliance staff audit merchants against the PCI Data Security Standard.

The PCI Data Security Standard, maintained by the PCI Security Standards Council, prohibits storing sensitive authentication data such as the full magnetic stripe, the CVV2, or the PIN block after a transaction is authorized. That rule exists precisely because a stored code is a stored liability. If you want to work in this space, the entry point is a certification, a support role at a processor, or an analyst position, not a private listing.

If you are being asked to sell or buy card data

You are almost certainly talking to a scammer, an undercover investigator, or both. Carding markets are saturated with fake data and exit scams, and buyers who send funds rarely receive anything usable. Some of the "sellers" are law enforcement running a controlled operation. The safe move is to stop responding, preserve the messages, and report the contact.

How to report card data trafficking

  1. Report internet-facilitated fraud to the FBI Internet Crime Complaint Center. Include usernames, platform names, timestamps, and any payment details you were given.
  2. Contact your card issuer immediately if your own card data may have been exposed, and ask for a replacement card.
  3. File an identity theft report with the Federal Trade Commission if personal information was involved, and use it to support fraud alerts or credit freezes.
  4. Send the complaint details to your state attorney general's consumer protection division when the seller is a business operating in your state.

Bottom line

There is no legal market for CVV codes, and no legitimate buyer. Anyone offering to purchase codes is either committing a crime, running a scam, or building a case. The transferable skill in this area is detecting fraudulent transactions and protecting card data, not moving it.