Short answer

A CVV dump shop is a storefront that sells stolen card numbers. Buying, selling, or holding that data is a federal crime in the United States. Law enforcement agencies run some of these sites as stings. Searches for them also lead to malware pages and phishing forms. A person who wants to protect a card should not look for these shops. A person who finds one should report it to the FBI Internet Crime Complaint Center.

CVV Dumps: No Legal Marketplace, Buy Card Security Instead

What the words mean

CVV is the three or four digit verification code printed on a payment card. A dump is a batch of card records copied from a payment system. A fullz record adds the cardholder name, billing address, and Social Security number. Research from security vendors priced a single United States card record at $5 to $60 on underground forums. Card data from other countries sold for less.

CVV Dumps Store Online: What It Is and How to Stay Safe

Legal exposure

18 U.S.C. § 1029 covers access devices, a category that includes card numbers. Penalties reach 10 years for a first offense and 15 years for a second. 18 U.S.C. § 1028A adds a mandatory 2 year term when identity documents are part of the case. Possession of 15 or more stolen card numbers raises the offense level under federal sentencing rules. A search alone is not a charge. A purchase or a download is.

related article

Risks to the person searching

Underground shops run on Tor and on private Telegram channels. Many are clones built to steal the buyer's own payment. Others push files that install credential stealers. A 2023 study of 400 card shop domains found that a quarter went offline within 90 days with no delivery. There is no refund path and no recourse.

how to find cvv dump shops

How card data leaks

Card numbers leave a merchant in several ways. Skimmers on fuel pumps and ATMs. Malware on point of sale systems. Breaches at payment processors. Phishing pages that copy a checkout form. Card testing, where a thief runs small charges to confirm a number works, appears as many low value authorizations from one IP address.

What cardholders should do

  • Turn on transaction alerts for every charge.
  • Use a virtual card number at online merchants.
  • Freeze the card in the issuer app when it is not in use.
  • Check statements each week, not each month.
  • Report a card test charge to the issuer. A $1 charge is still fraud.
  • File a report with the FBI Internet Crime Complaint Center or the FTC.

What merchants should do

  • Require CVV and address verification on every transaction.
  • Rate limit checkout attempts by IP address and device.
  • Watch velocity: many cards, one device, in a short window.
  • Follow PCI DSS storage rules. Do not keep the CVV after authorization.