There is no legal way to sell CVV data. The three or four digits on the back of a card exist to prove the person typing the number has the physical card in hand. Selling those codes, or buying them, is carding, and in the United States it lands under access device fraud at 18 U.S.C. § 1029, wire fraud, and identity theft statutes. That is a felony with prison exposure measured in years, plus fines and restitution to the banks. That is the short answer.

What people mean by "selling a CVV"

The phrase describes the criminal trade in stolen card data: full card numbers, expiration dates, cardholder names, and the security code that makes an online purchase go through. Sellers list batches on hidden forums and messaging apps. Prices are low, sometimes under a dollar per record, because the supply is huge. What the listings never say is that most of those markets are run by the same crews stealing the data, and the buyers get scammed, extorted, or identified.

Why the CVV is the piece that breaks the fraud

Card networks treat the code as a verification value, not data worth keeping. PCI DSS is clear on this: merchants and processors must not retain the CVV, CVC, or full track data after authorization, even in encrypted form. So a database breach that spills card numbers often misses the code entirely. When I read a breach report, the first question is whether the CVV was in scope. If it was, that is not a breach problem, it is a compliance failure. The missing code is also why stolen numbers without a CVV get declined online.

What actually happens to sellers

  • Federal charges: access device fraud, wire fraud, conspiracy, and aggravated identity theft. Prosecutors stack counts.
  • Financial ruin: restitution orders follow you after release, and banks bring civil claims too.
  • Exposure: issuers and card networks run their own intelligence, and undercover investigators work these forums as a matter of routine.
  • Getting burned by your own market: escrow scams, doxxing, blackmail, and malware tucked inside the "tools" sellers are told to run.

How the ecosystem gets disrupted

Banks and processors look for patterns, not single transactions. Many cards from one IP, mismatched billing and shipping addresses, sudden spikes in low-value digital goods. Tokenization swaps the card number for a substitute that is useless if stolen. 3D Secure adds an authentication step. Address verification and CVV checks stop the simple attempts. On the consumer side, a card lock in the banking app and a virtual card number for unfamiliar sites do more than any advice about watching statements.

If you are here because of fraud

Report it. Call the number on the back of the card, ask for the fraud team, and get the card frozen. Then file with the FTC at IdentityTheft.gov and with the FBI's IC3. If you are a merchant who found card data sitting on your systems, your acquirer and the card brands have notification requirements, and that CVV should not have been there in the first place.