How are CVV dumps sold?
CVV dumps change hands in bulk on closed underground forums and private chat channels, not on public marketplaces. The supply comes from card data gathered by skimmers, phishing kits, and retailer breaches. Buying or selling that data is a federal felony in the US under 18 U.S.C. § 1029, and takedowns of these channels are routine.
This guide covers how the trade runs at a high level, why most stolen card records fail before they produce a charge, and the controls that keep the trade away from your cards.
Sell CVV Dumps Forum: Risks and Defenses
What is a CVV dump?
A CVV dump is a record of payment card data copied from a magnetic stripe or pulled from a breached payment system. A full dump carries the card number, expiration date, cardholder name, and billing address. When the three-digit CVV or CVC value is attached, the record is worth more, because that code is meant to confirm the physical card is in hand.
Where does the supply come from?
Skimmers and shimmers
A skimmer is a false cover on a gas pump, ATM, or payment terminal that copies the stripe as the card goes in. A shimmer sits inside the card slot and reads the chip contacts. Both devices feed the same supply chain.
How to Safely Sell CVV Dumps in 2024
Phishing and cloned checkout pages
Fake storefronts and spoofed payment forms collect the card number, expiry, and CVV in one submission. That trio is the most valuable harvest for a thief, because it survives the checks that block a bare card number.
Breaches and web skimmers
Retail database breaches expose stored card records in bulk. Web skimmers, also called formjacking, inject script into a live checkout page and copy what the shopper types before the data reaches the payment processor.
Why most dumps fail in practice
A dump list is not cash. Issuers, processors, and fraud engines flag stolen card data during authorization, often within seconds.
- Card testing: small charges reveal which cards still work. That pattern alerts the issuer, and the account gets closed.
- CVV and CVC mismatch: a wrong security code fails authorization on the spot.
- Address Verification Service: the billing street number and ZIP must match the issuer record.
- 3-D Secure: step-up authentication sends a one-time code to the cardholder's phone, which the thief does not have.
- Velocity rules: many charges from one IP range or one card BIN get blocked as a group.
What happens to your card after it appears in a leak
The first visible sign is often a small test charge, sometimes under a dollar, on a card you still hold. Fraud teams then see a cluster of declines on the same number. For the cardholder, the fix is a freeze and a reissue, not a password change.
- Freeze the card in the bank app. Most US issuers allow this in two taps, and it stops authorization in real time.
- Turn on alerts for every transaction, not just charges above a set threshold.
- Request a new card number. A reissue kills the dump entry, because the old number no longer maps to a live account.
- Check the account for recurring charges started during the exposure window.
How merchants and processors detect dump-driven fraud
Fraud teams watch for the fingerprint of a dump list, not a single bad order.
- CVV failure rate by BIN: a spike means a batch of stolen records is being tested.
- Authorization velocity: many small charges across many cards in a short window.
- Device and IP reuse: one device hitting dozens of cards points to a carding script.
- 3-D Secure coverage: forcing step-up on high-risk orders removes most dump attempts from the approval path.
Is selling CVV dumps illegal?
Yes. In the US, trafficking in stolen card data falls under 18 U.S.C. § 1029, a felony that carries prison terms and fines. Similar laws exist in the UK under the Fraud Act 2006 and the Computer Misuse Act, and across the EU and Canada. Card networks, issuers, and hosting providers all report these operations to law enforcement.
FAQ
Can a stolen card be used without the CVV code?
Sometimes, and only at merchants that skip the security code check. Card-not-present fraud gets much harder when the merchant requires the CVV and runs 3-D Secure. That gap is why records with a code attached carry a premium on the underground market.
Does 3-D Secure stop dump fraud?
It stops most of it. 3-D Secure pushes a verification step to the cardholder's device, and a thief holding only card data cannot pass it. Liability also shifts to the issuer when authentication is applied, which pushes merchants to turn it on.
What if my card number shows up in a breach notice?
Treat the card as compromised even if no charge appears. Freeze it, order a replacement number, and review statements for the next two billing cycles. A stolen number can sit unused for months before someone tests it.
Why do thieves sell dumps in bulk instead of using them?
Bulk sale moves the risk to someone else and pays out fast. The seller skips the card-testing work, the shipping addresses, and the chargeback trail that come with using a stolen card.