A fullz with CVV shop is an illegal storefront that sells stolen identity records bundled with the card verification value from payment cards. There is no lawful version of this market. In the United States, buying, selling, or holding that data is a federal crime, and card networks void any purchase built on it. The useful lesson in the term is defensive: how stolen card data moves, and how to keep your own numbers out of it.
What "Fullz" and CVV Mean Together
A fullz record is a bundle of personal identifiers for one person: legal name, home address, date of birth, sometimes a Social Security number, phone number, and bank account details. The CVV, also printed as CVV2, CVC2, or CID, is the three or four digit code on a payment card. When both are sold as one lot, a buyer holds enough to pass identity checks and attempt card-not-present orders. That pairing is why the phrase appears so often in fraud reporting and why card issuers treat it as a high-risk signal.
Why the Shops Exist and Why They Are Illegal
The supply comes from data breaches at merchants, gas pump skimmers, phishing pages that clone a checkout screen, and malware planted on retail networks. Records get resold in bulk, then repackaged into smaller listings. Federal law treats the whole chain as criminal. Trafficking in stolen access devices such as card numbers falls under 18 U.S.C. 1029, and identity documents and identifiers fall under 18 U.S.C. 1028. Penalties include prison terms measured in years and heavy fines. Card network rules add a second layer: a merchant that stores the CVV after a transaction is out of compliance, and the data becomes evidence in any investigation.
Signs Your Card or Identity Is Exposed
- A small test charge appears, followed days later by larger ones.
- You see card-not-present purchases you never made.
- Credit inquiries or new accounts show up on your report.
- Password reset emails arrive for accounts you did not touch.
- Mail stops arriving, or a change of address notice appears.
- A breach lookup returns your Social Security number or date of birth.
Protecting Your CVV in Daily Use
- Keep the code off paper, photos, and chat messages. Read it only on the payment screen.
- Type the merchant domain yourself instead of following a link from an email or text.
- Use a virtual card number for subscriptions and unfamiliar stores. Most large issuers generate one with its own CVV that you can freeze.
- Turn on transaction alerts for every card you hold.
- Skip "save my card" on one-time purchases and on shared devices.
- Place a credit freeze at all three bureaus if your Social Security number was part of a leak.
For Merchants and Site Operators
- Never store the CVV after authorization. PCI DSS Requirement 3.2 prohibits retaining sensitive authentication data.
- Tokenize card numbers so they never reach your servers.
- Require the CVV plus address verification on card-not-present orders.
- Watch for card testing: bursts of small declines from one IP address or one device fingerprint.
- Patch your e-commerce platform and payment plugins on a set schedule.
- Keep checkout on your own domain. Third-party iframes can hide a skimmer.
If a Fraudulent Purchase Appears
- Call the issuer, lock the card, and request a replacement number.
- Dispute the charge in writing and save the confirmation number.
- File a report at IdentityTheft.gov if identifiers beyond the card may be involved.
- Send evidence of a stolen-data listing to the FBI Internet Crime Complaint Center.
The Bottom Line
No legitimate service sells fullz with CVV. Treat any offer as a crime in progress and as a sign that the underlying data is already loose. Shoppers protect themselves with virtual numbers, alerts, and freezes. Merchants protect customers by refusing to store verification codes at all.