What cheap CVV listings actually are
A CVV or CVC is a three or four digit verification code printed on a payment card. It exists to prove that the person typing it is holding the physical card. It is not a product, and no legitimate business sells it. Listings that advertise card verification values with instant payment are either stolen payment data offered for sale or, far more often, advance fee scams that collect a buyer's money and deliver nothing. Buying, selling, or brokering that data is card fraud under federal law and in every U.S. state.
If you arrived here looking to buy, the useful advice is the opposite of what you expected: do not send money, do not test any card numbers you are handed, and treat the whole interaction as evidence. Testing a card number you do not own is an attempt to commit fraud, even when the number turns out to be dead.
Buying Guide: How to Buy CVV/CVC Security for Online Purchases
How card verification data leaks
- Skimming devices and overlay pads on fuel pumps and ATMs.
- Phishing pages that clone a real merchant checkout.
- Malicious scripts injected into small merchant checkout pages.
- Breach dumps from retailers that stored data they should have deleted.
- Card details typed into chat apps, email, or forms on unsecured sites.
If you found a listing or already paid
- Stop all contact and send no further payment, including "verification" or "unlock" fees.
- Save the messages, listing text, wallet address, and screenshots before the seller deletes them.
- File a report with the FBI Internet Crime Complaint Center.
- Report the marketplace listing to the platform's abuse team.
- Call your card issuer and request a block on the merchant plus a replacement card.
- Contact the fraud line of any crypto exchange or peer to peer app you used, the same day.
- Report identity theft concerns if you shared your name, address, or ID documents.
Protect your own CVV at checkout
- Type the code only on a checkout page with a valid TLS certificate and a domain you recognize.
- Refuse to send the code by text, email, or chat, even to someone claiming to be your bank or a delivery carrier.
- Use a tokenized wallet or a virtual card number for merchants you have not bought from before.
- Enable transaction alerts on every card so an unauthorized charge reaches you within minutes.
- Review statements each month and dispute unknown charges as soon as they appear.
Merchant and developer checklist
Card network rules and the PCI DSS forbid retaining the CVV or CVC after authorization in any form, including logs and backups. Developers should pass the code to the processor and discard it, and must never write it to a database or a debug log. Small merchants should keep checkout scripts patched, use a hosted payment page, and avoid building a custom form if they cannot maintain it.
Prerequisites before you act
Have your card issuer's phone number and your last two statements ready. Know which payment method you used. Reporting speed matters: cardholder liability protection in the U.S. depends on prompt notice, and delays weaken a dispute.