What the phrase actually describes

A CVV is the three digit code on the back of most Visa, Mastercard, and Discover cards, or the four digit code on the front of an American Express card. Issuers use it as proof that whoever typed the card number is holding the physical card. No bank, processor, or merchant sells that code as a product. When a storefront advertises card verification values at a low price, it is reselling payment credentials taken from someone else. Buying, selling, or using those numbers is a federal offense in the United States under 18 U.S.C. 1029, and the low price is the hook that pulls buyers into a second scam on top of the crime.

more on this topic

What follows is written for two readers: the person who wants to understand what those listings are, and the cardholder who wants to keep their own code off them.

i want to buy cvv online

Prerequisites

  • Know that a card verification value is not a purchasable item, at any price.
  • Keep your issuer's fraud line saved, or the back of your card within reach.
  • Plan to review your card activity at least once a week, not once a month.

Warning signs of a stolen-card marketplace

  • Prices listed per card, in bulk tiers, with discounts for larger orders.
  • Payment accepted only in cryptocurrency or gift card codes.
  • Claims of a high balance or a fresh card with a stated bank and country.
  • No company name, no address, no return policy, and no support number.
  • Contact only through Telegram, Discord, or a throwaway email address.
  • Testimonials posted as screenshots, never on a verifiable review platform.

How to protect your own CVV during real online purchases

  1. Enter your card details only on checkout pages with an https address and a visible padlock.
  2. Type the card number by hand instead of using autofill on a store you have not bought from before.
  3. Turn on your issuer's transaction alerts so every charge sends a text or push notice.
  4. Use a virtual card number from your issuer for subscriptions and one-off merchants.
  5. Decline to store the card on any site that does not need it for repeat billing.
  6. Check your statements each week and match every line to a receipt you recognize.
  7. Replace the card as soon as a merchant you used reports a breach.

What to do if your card number and code appear for sale

  1. Call the number on the back of your card and ask for the account to be closed and reissued.
  2. Review the last 12 months of statements for charges you do not recognize.
  3. Dispute each unauthorized charge in writing with your issuer.
  4. File a report at IdentityTheft.gov and keep the confirmation number.
  5. File a complaint with the FBI Internet Crime Complaint Center if a listing names your data.
  6. Change the password on every shopping account where that card was saved.

Parameters that matter in card-not-present checkout

  • CVV requirement: a merchant that asks for the code on each transaction has one layer of defense, and a merchant that never asks has none.
  • Address verification: matching the billing street number and ZIP to the issuer's record catches cards sold without an address.
  • 3-D Secure: an extra issuer prompt at checkout shifts liability and blocks most bulk card testing.
  • Storage rules: PCI DSS forbids keeping the CVV after authorization, so any site claiming to hold your code on file is out of compliance.
  • Liability window: in the US your liability for unauthorized charges is capped, but only when you report the card as lost or stolen without unreasonable delay.

Pitfalls to avoid

  • Assuming a low price means low risk. Buyers of stolen card data are the most common victims of the sellers.
  • Trusting a checker tool that validates a card. Those pages exist to collect your own credentials.
  • Ignoring a small unauthorized charge. Test charges often come before a large one.
  • Posting card details in a chat, a support ticket, or an email. No legitimate agent asks for the CVV.
  • Waiting for the statement cycle to close before reporting a charge.