If you are asking to sell cvv at shop checkout, the first thing to know is that there is no legal way to do it. The three-digit Card Verification Value belongs to the issuing bank and the cardholder, not to any merchant, employee, or reseller. Selling a CVV even once, even for a few dollars, puts you inside the access device fraud rules of the United States Code.
What Is CVV and Why Would Someone Want to Sell It?
CVV stands for Card Verification Value. Visa calls it CVV, Mastercard calls it CVC, and American Express calls it CID, but the job is the same: it helps a merchant confirm that the physical card is in front of the person placing an order. The code is printed on the card or, for Amex, on the front, and it is not stored on the magnetic stripe or the chip.
When a cardholder buys online, they enter the CVV to prove they are holding the card at that moment. That proof is the whole reason the number exists. A criminal who steals the card number and expiry date but not the CVV has a harder time using the card for card-not-present purchases.
Data thieves therefore look for the complete set: card number, expiry date, and CVV. Some try to sell those records to others who will make fraudulent purchases. The market they describe sounds like a business, but it is a chain of unauthorized transactions from the first step.
Which U.S. Laws Make Selling CVV a Federal Crime?
The main law is 18 U.S. Code Section 1029, which covers fraud and related activity in connection with access devices. A CVV plus a card number is an access device because it is a way to obtain money, goods, or services. Trafficking in those devices is a federal offense.
Prosecutors can bring charges even when the sale involves a single card. Under Section 1029, the maximum sentence for a first conviction is up to 10 years in federal prison. Repeat convictions and aggravated circumstances, such as possession of 15 or more unauthorized cards, can push the penalty toward 20 years.
- 18 U.S.C. 1029(a)(2) covers trafficking in unauthorized access devices.
- 18 U.S.C. 1029(a)(3) makes possession of 15 or more unauthorized devices a crime by itself.
- 18 U.S.C. 1028(a)(7) can add identity theft charges when names or personal identifiers come with the card data.
- Wire fraud statutes can apply when the sale uses email, messaging apps, or online marketplaces.
Federal agents and payment card investigators monitor forums and messaging channels where stolen card data is resold. The person who answers a “sell CVV” ad may be an undercover agent running an operation, not a real buyer. That is a common end for small sellers who thought they were making a one-time side deal.
If Shops Handle CVV Every Day, Why Can’t a Shop Sell It?
Stores see a CVV when the cardholder types it into a payment form. The merchant forwards that code to the payment processor for validation. The code is a token of consent from the cardholder for that one purchase only.
The consent does not transfer ownership. A merchant does not get a license to reuse, copy, or resell the code after authorization. Payment Card Industry Data Security Standard (PCI DSS) requirement 3.2 is clear: merchants must not store sensitive authentication data after the transaction, and that data includes the CVV.
Even a shop that legally processed a customer’s transaction is breaking the rules if it keeps the CVV in a database or log file. Selling that stored code later is not a gray area. It is misuse of data that was given for a single verification purpose.
Banks and card networks are the only entities allowed to issue card credentials. A card network does not license third-party stores to resell CVV to the public. If a merchant says it has permission to resell customer card data, that merchant is either confused or trying to sell an illegal product.
What Legal Alternatives Should a Merchant Use Instead of Selling CVV?
Legitimate online shops collect a CVV from the cardholder at the moment of each purchase. They send it to their payment processor, and they do not save it anywhere. That model creates no surplus data to sell in the first place.
Businesses that run recurring payments should use network tokens or stored credentials from their payment processor. Those tools let you bill repeat customers without collecting card data again.
- Use a Payment Card Industry (PCI) validated processor that handles CVV capture on its own checkout page.
- Switch to tokenization for saved cards and recurring billing.
- Enable 3-D Secure, like Visa Secure or Mastercard Identity Check, for extra cardholder proof.
- Run address verification and card security code checks, but never record the security code.
If your business model depends on customer data revenue, sell your own first-party marketing insights to partners, not raw card numbers. Cardholder payment data is not an asset you can trade. The penalties for treating it that way far outweigh the income.
What Should You Do If You Receive an Offer to Sell Stored CVV Data?
Sales offers usually arrive by email, direct message, or a post on a business forum. They may promise “fresh” cards, “live” numbers, or a cut of every purchase. These pitches are invitations to commit a federal crime, so treat them as red flags, not business opportunities.
- Do not open the data file or verify any test card numbers. Examining the sample can be its own crime if you know it is stolen.
- Save the sender’s username, email address, and timestamps as evidence.
- Do not confront the seller yourself. That can tip them off and compromise an investigation.
- Report the offer to the Internet Crime Complaint Center (IC3) at ic3.gov or to the Federal Trade Commission at ReportFraud.ftc.gov.
- Notify your payment processor and your card brand’s fraud team if the data appears to come from your business.
Merchants who receive such offers should also check whether their own systems were breached. A card data thief does not usually ask a merchant for permission first. If a stranger tells you they have your customers’ data, the correct response is to assume a compromise and begin a PCI forensic investigation.
Frequently Asked Questions About Selling CVV at a Shop
Could selling expired card data with a CVV be legal?
No. An expired card number is still an access device, and the bank that issued it still holds the account history. Criminals use expired or test cards to probe payment systems, so selling that data still supports fraud.
Can a customer sell the CVV from their own card?
No. The card agreement gives the cardholder the right to use the card for authorized purchases, not to transfer or resell the security code. Sharing your own CVV with another person can violate the issuer agreement and lead to card cancellation.
People who bought the data have asked for a refund. What should I do?
Do not send a refund, and do not continue the conversation. Any exchange of CVV data is illegal, so the only safe action is to halt contact and report the negotiation to law enforcement. Cooperating with investigators is the best way to reduce personal exposure.
Do any card networks license “legitimate” CVV resellers?
No. Visa, Mastercard, American Express, and Discover do not license resellers of card security codes. CVV is issued by the bank that personalizes the card, and the only authorized user is the cardholder.
Bottom Line: Selling CVV at a Shop Always Leads to the Same Answer
Every version of the “sell CVV” pitch starts and ends with the same facts. CVV data belongs to the cardholder and the issuer, and selling it violates federal law, PCI DSS rules, and card network agreements.
- There is no licensed shop, online store, or marketplace for CVV codes.
- One small sale can generate federal charges that last a decade or more.
- Legitimate payments always start with the cardholder’s direct entry of the CVV into a compliant checkout form.
- If someone asks you to sell stored card data, report the message and secure your systems.
The question “can I sell CVV at a shop?” has one accurate answer: no. Run your checkout the compliant way, keep no security codes after authorization, and you will never need to test the boundaries of that law.