Short answer

A CVV shop or dump store is an illegal storefront that trafficks stolen card numbers, card verification values, and magnetic stripe data taken from breaches, skimmers, and malware. Buying, selling, holding, or using that data is payment card fraud. In the United States, trafficking in unauthorized access devices is a federal crime under 18 U.S.C. 1029, and no legitimate version of this market exists. For a cardholder or a merchant, the useful question is not where these shops operate. It is how card data escapes a legitimate checkout in the first place, and which controls close those gaps.

more on this topic

What the terms mean

  • CVV (CVC/CVV2): the three or four digit verification code printed on a card or generated for a digital wallet. It exists to prove the physical card is present.
  • Dumps: Track 1 or Track 2 data copied from a magnetic stripe by a skimmer or lifted from a terminal's memory.
  • Fullz: a bundle of card data plus personal identifiers such as name, address, and Social Security number.
  • Carding: using stolen credentials to place unauthorized orders, usually through automated card testing against a weak checkout.

The common thread is that every one of these items is stolen property, and possession alone carries criminal exposure.

related article

How card data reaches a criminal market

Most inventory in these markets traces back to a small set of failures. A merchant database is breached and stores card numbers it should have tokenized or purged. A skimming overlay sits on a fuel pump or ATM reader. A phishing page copies a real checkout and harvests the form as the buyer types. Malware scrapes a point of sale terminal. A site stores the CVV after authorization, which PCI DSS forbids, so a single breach returns a complete and usable card profile. Each route is preventable with controls a normal business can deploy.

more on this topic

What US law says

18 U.S.C. 1029 criminalizes producing, selling, transferring, or possessing unauthorized access devices and the equipment used to make them. Penalties scale with the number of devices and the dollar loss, and conspiracy charges are common. State statutes add their own counts for identity theft and computer trespass. Reporting is handled by the FBI's Internet Crime Complaint Center and by the FTC for consumer identity theft cases.

related article

Protect a personal card in six steps

  1. Open your bank app and freeze the card whenever it is not in active use.
  2. Turn on transaction alerts so every charge above a small threshold reaches your phone.
  3. Request a virtual card number for online merchants you buy from once or twice.
  4. Review each statement line by line every month instead of scanning the total.
  5. Pull your three free credit reports on the annual schedule and dispute anything you do not recognize.
  6. Replace the card number at every merchant when a subscription or saved card is no longer needed.

Reduce exposure at a business

  1. Stop storing the CVV after authorization and confirm your gateway does the same.
  2. Tokenize card numbers so your database never holds a usable primary account number.
  3. Apply PCI DSS requirements to every system that touches cardholder data, including logs and backups.
  4. Turn on 3-D Secure or an equivalent step-up challenge for high-risk orders.
  5. Rate limit failed authorization attempts and flag the small-value bursts that signal card testing.
  6. Inspect card readers and terminals for overlays and tampering on a set schedule.

If your card data appears for sale

  1. Call the issuer and close the account rather than waiting for a charge to post.
  2. File a report and follow the FTC identity theft recovery plan to get an affidavit and a recovery roadmap.
  3. Submit a complaint to the FBI Internet Crime Complaint Center if the loss involves wire transfer or a large sum.
  4. Send a written dispute to the issuer and keep the confirmation number for your records.
  5. Update the card number everywhere it was stored, then monitor for a repeat attempt.

Bottom line

There is no safe way to participate in a CVV shop or a dump sale. The only durable defense is at the checkout: tokenize, never store verification codes, challenge risky orders, and give cardholders tools that limit what a stolen number can do.