What a "CVV shop" is really selling
I get why the phrase pulls people in. The pitch is always the same: high quality, fresh, cheap price, instant delivery. But there is no legitimate market for other people's card numbers. A CVV shop is a reseller of stolen payment data, usually dumped from a breach, a skimmer, or a phishing page. The number on sale belongs to someone who never agreed to sell it.
The "cheap price" is the part that should stop you cold. A card with a working CVC code selling for a few dollars is not a bargain, it is a red flag. Either the data is dead and the seller is scamming the buyer, or it is live and you are now the one committing card-not-present fraud.
Why the cheap listings are usually worthless anyway
- Banks kill compromised cards fast, so a batch is often dead within hours of being posted.
- Many listings are recycled from old breaches and have already been reported and reissued.
- Vendors test codes on their own before selling, which triggers the issuer's fraud rules.
- "Refund policies" and escrow on these forums are run by the same people selling you the data.
What using one actually exposes you to
Buying or using someone else's card credentials is a federal offense in the US, and the paper trail is worse than most people assume. The payment you use to buy the data ties back to you. The delivery address, the IP, the device fingerprint, and the merchant's AVS and 3-D Secure logs all get retained. Card networks and issuers pool this into shared fraud databases, so a single flagged transaction can follow you into every future attempt to open an account.
What real CVV and CVC security looks like
On the merchant side, the rules are strict for a reason. PCI DSS prohibits storing the CVV, CVC2, or CAV2 value after a transaction is authorized, which means a properly run store never has your security code sitting in a database for a breach to scoop up. When I check whether a shop handles card data responsibly, I look for hosted payment fields or tokenization, so the card number never touches the merchant's own servers, and I look for 3-D Secure prompts on higher-risk orders.
- Tokenization swaps your card number for a token that only works at that merchant.
- Address Verification Service compares the billing address you enter against the issuer's record.
- 3-D Secure adds a bank-side check before the charge goes through.
- Virtual card numbers let you set a spend cap and kill the number after one use.
If your own card number turns up somewhere
- Freeze the card in your banking app before you call anyone.
- Dispute the charges and request a new card number, not just a new card.
- Pull your free credit reports and look for accounts you did not open.
- File a report with the FTC and, for card-not-present fraud, the FBI's Internet Crime Complaint Center.
- Change the password on any shopping account that stored the card.
The short version: there is no safe way to buy someone else's CVV, and there is no shortage of people willing to sell you one that does not work. Spend the effort on protecting the card you actually own instead.