A CVV dump is a batch of stolen card records that carries the card verification value, the three or four digit code printed on the card. It is a criminal product traded on hidden markets, not a tool a shopper can legitimately obtain or use. The data usually appears because a card was skimmed at a terminal, typed into a phishing page, captured by malicious code on a checkout, or leaked by a merchant that mishandled payment data. This guide explains what sits inside a dump, how it gets spent against online stores, and which protections stop a replayed CVV from turning into a shipped order. The options below are judged on four criteria: whether they defeat a reused security code, cost to the cardholder, friction at checkout, and how widely merchants accept them.

what is cvv dump

What a CVV dump contains

The contents vary by source, but a usable record typically includes the card number, the expiration date, the cardholder name, and the CVV or CVC2 code. Some records add the billing address, phone number, or bank name to help a fraudster pass an address verification check. Higher tier records sold as fullz or dumps with track data include magnetic stripe information copied from a skimmer, which matters for physical card cloning rather than online checkout.

what is cvv dump

Why the code leaks at all

Payment card industry rules forbid merchants and processors from storing sensitive authentication data, including the CVV, after a transaction is authorized. A dump therefore points to one of a few failure points: a skimmer on a fuel pump or ATM, a fake storefront that collects card details, malware injected into a real checkout page, or a processor that ignored the standard. The code is not meant to sit in any database, so its presence in a dump is itself evidence of a breach or a scam.

Best CVV Dump Sites: A Merchant Security Comparison

How the data gets spent online

Buyers of a dump rarely walk into a store. They run scripted attempts across many merchants, test low value orders to see which cards still work, and route shipments through reshipping addresses. Merchants counter with risk scoring, velocity checks, device fingerprinting, address verification, and step up authentication that asks the cardholder to approve a purchase in a banking app. This is why a stolen CVV fails more often than it succeeds, and why dumps are sold in bulk at low unit prices.

CVV Dump vs Fullz: Which Fraud Data Set Puts Online Checkout at More Risk?

Top pick: issuer virtual card numbers with a fresh CVV

Several major US issuers let you generate a virtual card number in the banking app or a browser extension. The virtual number comes with its own CVV that can be limited to one merchant, one transaction, or a spending cap. If that CVV later appears in a dump, it is worthless anywhere else.

  • Pros: the code cannot be replayed at another merchant; you can freeze or delete the virtual number without replacing the underlying card; most issuers charge nothing for it; works for phone orders and subscriptions.
  • Cons: some merchants reject virtual numbers or fail on recurring billing; setup takes a few minutes per number; support varies by issuer, so a declined order can be hard to diagnose.

Use case: checkout on unfamiliar sites, free trials, and any subscription you expect to cancel.

Runner-up: network tokenization at checkout

Visa Token Service and Mastercard's tokenization programs replace the real card number with a token tied to a specific merchant, device, or wallet. The security code is not stored alongside it, so a breach at the merchant yields little that can be spent elsewhere.

  • Pros: no action needed from the shopper; wide acceptance through mobile wallets and saved cards; reduces the value of any single merchant breach.
  • Cons: you do not control when it applies; the token still points to an account that can be closed by the issuer; it does not help if your card data leaked from a source outside that merchant.

Use case: everyday shopping with a card you keep on file at retailers you trust.

Runner-up: transaction alerts, card controls, and step up authentication

Real time alerts, merchant category blocks, and an approval prompt in the banking app give you a chance to catch a fraudulent order before it ships.

  • Pros: free with most accounts; a challenge prompt breaks automated scripts; alerts often arrive within seconds.
  • Cons: alerts land after the authorization, so timing matters; aggressive blocks cause false declines on legitimate purchases; a determined fraudster can target merchants that never trigger a challenge.

Use case: a primary card used at many merchants, paired with virtual numbers for risky sites.

What does not stop a CVV dump

A VPN hides your connection, not your card data. Antivirus helps with malware but cannot undo a breach at a merchant. Password managers protect account logins, which is a separate problem from card data theft. Sites that claim to check whether your card appears in a dump are frequently harvesting card numbers themselves, so treat them as a risk rather than a service.

If your card data shows up in a dump

  1. Freeze the card in your banking app and request a new number and CVV.
  2. Review statements for small test charges, which usually precede larger ones.
  3. Dispute unauthorized charges with the issuer and follow its fraud process.
  4. File a report at IdentityTheft.gov if the incident grows beyond a single card.
  5. Report the scam to the FBI Internet Crime Complaint Center if a specific storefront or message targeted you.

Choosing by situation

For a one time purchase on a site you have never used, generate a virtual number with a spending cap. For recurring bills at established retailers, rely on tokenized checkout and keep alerts turned on. For a card you carry in a wallet and swipe at terminals, enable a freeze option and review transactions weekly. None of these steps makes you invisible to fraud, but together they remove the resale value of a stolen CVV, which is the whole point of the dump market.