Legal options come first

If you need a card number for an online purchase, three legal sources exist: the card your bank issued, a virtual card number from that same bank or a fintech, and a prepaid card bought at retail. Everything else sold under the term "cvv shop" is stolen data.

A CVV shop is a storefront that resells card records. Each record holds the 16-digit primary account number, the expiration date, the cardholder name, and the 3 or 4 digit verification code. Sellers price records by country and by the balance a buyer can drain. Buying one is a federal crime in the United States under 18 U.S.C. 1029, Fraud and Related Activity in Connection with Access Devices. A first offense carries up to 10 years in prison and a fine up to $250,000. Possession of 15 or more unauthorized access devices is a separate offense under the same statute.

What the CVV is

Visa, Mastercard, Discover, and UnionPay print the code on the back: 3 digits. American Express prints 4 digits on the front. The networks call it CVV2, CVC2, CID, or card verification code. The code is a check that the buyer holds the physical card.

PCI DSS Requirement 3.2 bars merchants from storing sensitive authentication data after authorization. A card verification code cannot sit in a merchant database. If a site asks you to type a stored CVV again, that site is out of compliance.

Parameters to check on your own cards

  • Address verification (AVS) and CVV match: enable both. A mismatch on either raises decline rates.
  • 3-D Secure: the issuer app receives a push and you approve the charge. Liability moves to the issuer.
  • Network tokens: a device-specific token replaces the 16-digit number. Apple Pay, Google Pay, and bank wallets use this.
  • Spend controls: set a per-transaction cap, turn off international charges, and turn off online charges when the card is idle.
  • Statement descriptor: the merchant name on your statement should match the site you paid.

Pitfalls in the underground market

  • Price: US records list at $5 to $30 in these markets and higher for business cards. Low prices signal test data or a dead record.
  • No enforcement: shops advertise replacement windows and checkers. Disputes go nowhere.
  • Escrow: escrow accounts on Telegram and carding forums are run by the same operators in many cases.
  • Buyer harvesting: some shops log the buyer IP address, wallet credentials, and contact details.
  • Test authorizations: charges of $0 to $1 appear on the victim statement and trigger a call to the issuer.

If your card data leaks

  1. Call the issuer and ask for a new number. Keep the old account open long enough to move recurring billing.
  2. Freeze the card in the bank app.
  3. Read 12 months of statements.
  4. File a report at IdentityTheft.gov and with the FTC. In the US, the FBI runs IC3 for internet crime.
  5. Dispute each charge. The Fair Credit Billing Act and Regulation Z give you 60 days from the statement date.

Credit card liability under the FCBA caps at $50, and the four major US networks set $0 for reported unauthorized use. Debit card liability under the Electronic Fund Transfer Act is $50 if you report within 2 business days, $500 up to 60 days, and unlimited after that.

Loss data

The FTC reported $12.5 billion in consumer fraud losses in 2024, up from $10 billion in 2023. Imposter scams were the most reported category. The FBI IC3 receives complaints on credit card fraud, identity theft, and business email compromise. Industry estimates for the share of card fraud that happens without the card present vary by source.