Selling CVV or CVC codes that belong to another person is carding, and carding is a federal crime in the United States. There is no legal marketplace, no compliant vendor, and no low-risk way to do it. This guide does not explain how to sell card data, because that activity is what the law calls trafficking in unauthorized access devices. If your real interest is working in payments, the legitimate entry points are fraud analyst, risk operations associate, chargeback specialist, and PCI compliance coordinator. What follows covers what a CVV is, why the data is legally protected, how merchants must handle it, and what to look for when you buy fraud and payment security tools.

read more

What a CVV or CVC code is

A CVV, also called a CVC, CID, or card verification value, is the short code printed on a payment card but not encoded on the magnetic stripe. Visa, Mastercard, and Discover place three digits on the back. American Express places four digits on the front. The code exists to prove the person entering the card number is holding the physical card, which is why a stolen card number alone is less useful to a fraudster without it.

related article

Why selling card codes is illegal in the US

Federal law at 18 U.S.C. 1029 covers fraud and related activity in connection with access devices. It criminalizes trafficking in and use of unauthorized access devices, and it carries fines and prison terms that escalate with the value and scale of the scheme. State statutes add their own theft and computer crime charges. Beyond the criminal exposure, the forums and private channels where card data circulates are routinely monitored or operated by investigators, and buyers in those spaces are frequently defrauded by the sellers they meet there. There is no consumer protection, no dispute process, and no recourse when a deal goes wrong.

best cvv website to sell for carding

How the card networks and merchants protect CVV data

The PCI Security Standards Council sets the rules that merchants, processors, and software vendors follow. Under PCI DSS, CVV and CVC values are classified as sensitive authentication data, and the standard prohibits storing them after a transaction is authorized. That means a legitimate online store cannot keep your code in a database, a help desk ticket, or a customer relationship management record for a later charge. Merchants that need to bill a customer again use stored payment tokens issued by the processor instead of the raw card data.

best cvv website to sell for carding

  • Tokenization replaces the card number and code with a reference value that is useless outside that merchant's system.
  • Network tokens go further and let the card network handle the credential on the merchant's behalf.
  • 3-D Secure adds an issuer-side check during checkout for higher-risk orders.
  • Address Verification Service matches the billing street number and ZIP code to what the issuer has on file.

What to look for when buying payment or fraud tooling

Buy on capability and compliance evidence, not on marketing claims. Ask each vendor for a current Attestation of Compliance, the exact scope it covers, and a written data retention schedule that states how long any card data lives in the system.

  1. CVV validation at authorization only. The tool should transmit the code for the check and never write it to storage or logs.
  2. PCI DSS Level 1 or validated Level 2 status. Level 1 applies to the largest processors, and Level 2 covers mid-size merchants. Confirm the level against your own transaction volume.
  3. Tokenization and network tokens. Support for both matters if you plan to offer repeat billing or one-click checkout.
  4. Rule controls. Look for velocity limits, geo mismatches, device fingerprinting, and the ability to tune thresholds without filing a support ticket.
  5. Chargeback workflow. Dispute intake, evidence packaging, and representment tracking should be built in rather than bolted on.
  6. Access controls. Role-based permissions and immutable audit logs are baseline, not premium features.
  7. Phone order handling. If your agents take cards by voice, the system should pause recording and mask the digits on entry.

On pricing structure, most providers charge a monthly platform fee plus a per-authorization or per-transaction rate, sometimes with a separate fee for dispute handling. Request a written quote at your actual monthly volume and peak season volume, and compare the effective rate rather than the headline rate, since tiers and overage charges change the total. Small merchants processing a few hundred orders a month often do better with a bundled processor gateway, while high-volume or multi-channel sellers usually need a standalone fraud platform that integrates with several acquirers.

Pitfalls to avoid

  • Any person or site offering to sell CVV data or fullz is committing a crime. Contact with them creates legal risk and a high chance of being scammed.
  • Storing the code in a spreadsheet, chat log, or ticketing system breaks PCI DSS and turns a routine audit into a breach investigation.
  • Assuming small businesses are exempt. Every entity that accepts card payments falls under the standard.
  • Treating chargeback alerts as fraud prevention. Alerts arrive after the loss.
  • Buying on price alone and skipping the compliance documentation review.

FAQ

Is selling CVV numbers legal anywhere in the United States?

No. Trafficking in card data that belongs to someone else is a federal offense, and state laws add separate charges.

Can a store save my CVV for faster checkout?

No. PCI DSS bars storage of the code after authorization. A merchant that wants faster repeat checkout should use a processor token instead.

What should I do if my card number and code are exposed?

Call the number on the back of your card and ask for a replacement card number. Review your statements, report the incident at IdentityTheft.gov, and consider a fraud alert or credit freeze.

Are CVV, CVC, and CID the same thing?

They are the same concept under different network names. Visa uses CVV2, Mastercard uses CVC2, American Express uses CID, and Discover uses CVV.

Do debit cards have these codes too?

Yes. Debit cards carry the same verification code, and the same storage restrictions apply to any merchant that accepts them.