Short answer
Carding is the trade in stolen payment card data. A site that sells CVV data is a fraud marketplace, not a payment service. Buying card numbers is a federal crime in the United States under 18 U.S.C. 1029. Most buyers get dead numbers, test records, or the same card sold to dozens of other people.
best website to buy cvv for carding
What the term means
CVV is a card security code. Visa calls it CVV2, Mastercard calls it CVC2, and American Express calls it CID. The code is printed on the card. It is not stored in the magnetic stripe or the EMV chip. Carding forums use CVV as shorthand for the full record they trade: card number, expiry date, cardholder name, billing address, and the security code.
best website to buy cvv for carding
What those sites sell
Listings use terms such as fullz, dumps, and CVV. A fullz record claims to include the cardholder identity data. A dump claims to be data copied from a magnetic stripe. Both categories carry risk for the buyer. Card networks cancel compromised numbers in bulk after a breach is found. Issuers flag accounts tied to a known breach. A number sold in a batch has a short working life, if any.
best website to buy cvv for carding
Legal status in the United States
18 U.S.C. 1029 covers fraud and related activity in connection with access devices. Producing, selling, or possessing card data with intent to defraud falls under the statute. Penalties reach 10 years for some violations and 15 years when the offense involves more than one access device or $1,000 in value in a one year period. State laws add separate charges. The FBI and the Secret Service run card fraud investigations.
Why buyers lose money
Fraud forums run on escrow, reputation, and exit scams. A seller can collect payment and stop answering. Card testing triggers issuer rules. A card used for a test charge in one state and a purchase in another state raises a velocity flag. Chargebacks on card-not-present orders push merchants to cancel orders from new accounts. A buyer who files a complaint about a lost payment has no legal route, because the underlying transaction is a crime.
Checks merchants run on CVV and CVC
Online merchants send the CVV2 code in an authorization request. The issuer checks the code against its records and returns a match, no match, or not processed response. PCI DSS Requirement 3.2 forbids storage of sensitive authentication data after authorization. That data includes the full magnetic stripe, the CVV2, and the PIN block. Merchants that follow the rule hold no CVV2 value after the sale. A breach of their database yields card numbers but not the printed code.
What cardholders can do
Read the card statement each month. Turn on transaction alerts. Use a virtual card number for online purchases when the issuer offers one. Report a lost card at once. Freeze the account in the issuer app if a charge looks wrong. US law caps cardholder liability at $50 for unauthorized use, and most issuers waive it.
What merchants can do
Require the CVV2 on every card-not-present order. Run address verification. Set velocity rules per card, per IP address, and per device. Watch for small test charges followed by a large order. Keep the payment page on a PCI DSS compliant host.