What a dark web CVV shop list is
A dark web CVV shop list is a catalog of card-not-present fraud sites. Those sites sell stolen card numbers, expiration dates, cardholder names, and the three or four digit security codes printed on cards. The lists circulate on forums, Telegram channels, and paste sites. No list holds steady. Shops open and close, domains rotate, and a list posted in a public place is stale within weeks.
Buying CVV With Bitcoin on the Dark Web: Why Buyers Lose
What the shops sell
- Card data alone: number, expiration date, security code.
- Fullz: card data plus name, address, phone, and sometimes a Social Security number.
- BIN data: numbers grouped by issuing bank and card type.
Reported asking prices run from under $1 to more than $50 per record. Data quality drives price. Verified sales figures do not exist. Sellers publish no audited numbers, and takedown notices remove the rest.
Buying Guide: Safe and Cheap CVV/CVC for Online Purchases
Why the lists fail as research sources
- Exit scams. A shop collects payment and ships nothing.
- Seized domains. Police agencies have taken over market infrastructure and run it as a trap.
- Malware. Many list pages host scripts that drain crypto wallets or harvest login credentials.
- Undercover storefronts. Some shops are run by investigators.
How card data leaves a card
Skimmers on gas pumps and ATMs copy magnetic stripe data. Scripts injected into e-commerce checkout pages, a pattern called web skimming or Magecart, capture form fields at the moment of entry. Phishing pages copy credentials and card data. Merchant and processor breaches release stored records in bulk.
Where to Find CVV on the Dark Web: Facts and Risks
Why buying or using the data is a crime
In the United States, trafficking in stolen access devices falls under 18 U.S.C. Section 1029. It is a felony. Terms reach 10 years, and cases involving 15 or more devices in a year or $1,000 or more in value carry longer terms. Testing a card number to see if it works is attempted fraud, not research.
What actually protects a card
- EMV chip and contactless payments. Each transaction carries a unique cryptogram that cannot be replayed.
- Tokenization. A virtual number replaces the card number for a single merchant or device.
- 3-D Secure. The issuer adds an authentication step at checkout.
- PCI DSS. Merchants that store, process, or transmit cardholder data must meet those controls.
- Card controls in banking apps. Freeze, spend limits, and transaction alerts catch misuse in hours.
The printed security code is static. It sits on the card and does not change, which is why card-not-present fraud survives after chip adoption. A merchant that asks for the code over the phone or in a chat window is a warning sign.
If you find one of these lists
Report it to the FBI Internet Crime Complaint Center and to the FTC. Do not enter credentials. Do not send payment. Do not run card numbers through a validation page.
Bottom line
There is no legitimate directory of CVV shops. The records in those shops belong to real account holders, and the money spent there goes to criminals who sell the same data to several buyers.