Selling CVV numbers on a website is a federal crime in the United States. A CVV is cardholder data that only the card issuer and the account holder may use, and offering it for sale on a site, forum, or chat channel falls under 18 U.S.C. § 1029 (access device fraud). There is no legal marketplace, no licensed broker, and no workaround.

more on this topic

This guide covers what the CVV actually is, why CVV sales get prosecuted, how stolen codes reach criminal markets, and what shoppers and merchants do to shut that traffic down.

more on this topic

What is a CVV code?

The CVV (card verification value) is a 3 or 4 digit code printed on a payment card. Visa, Mastercard, and Discover place a 3 digit code on the back, to the right of the signature strip. American Express uses a 4 digit code on the front, above the card number.

sell cvv dumps website

The code proves that whoever is typing the card number holds the physical card. Because the CVV is not written to the magnetic stripe or the chip, a breach that copies track data does not hand over the CVV.

How to Safely Sell CVV Dumps Websites

Why is selling CVV data a crime?

US law treats card numbers, expiration dates, and CVV codes as "access devices." Selling, trafficking, or transferring them with intent to defraud is a felony.

  • 18 U.S.C. § 1029 (access device fraud): up to 10 years in prison for an offense involving one access device, and up to 15 years when the case involves two or more.
  • 18 U.S.C. § 1028A (aggravated identity theft): a mandatory 2 year sentence that runs on top of the fraud term when another person's card data is used.
  • 18 U.S.C. § 1343 (wire fraud): any sale arranged over the internet, email, or a messaging app qualifies.
  • State law: most states add identity theft and computer crime charges of their own.

What happens to people who try to sell CVV data on a website?

Carding storefronts change domain names every few weeks, and the people running them get caught first. Federal agents buy card data through those sites to build cases, and hosts, registrars, and payment processors close a storefront the moment a complaint lands.

  • Servers get seized, and buyer lists become evidence.
  • Crypto payments leave a ledger that investigators can follow.
  • Buyers face the same charges as sellers when they use the data.
  • Many listings are bait. The operator takes the crypto and disappears.

How do CVV codes get stolen?

Card data reaches criminal markets through three main paths.

  1. Merchant breaches: attackers break into a payment system and copy card numbers as they pass through.
  2. Skimming and phishing: fake checkout pages, gas pump overlays, and lookalike bank emails collect numbers and codes straight from the cardholder.
  3. Malware on a home device: keyloggers capture what a shopper types into a checkout form.

CVV theft takes extra work because payment card industry rules keep the code out of stored records after authorization.

How do merchants block stolen CVV use at checkout?

  • CVV verification on every transaction, with a decline when the code fails.
  • No storage of the CVV after authorization. PCI DSS Requirement 3.2 forbids keeping sensitive authentication data once the transaction is complete.
  • 3D Secure and strong customer authentication, which push verification to the issuer's app.
  • Address verification (AVS) and ZIP checks that catch mismatched billing data.
  • Velocity limits and device fingerprinting that flag many card tests from one IP address.

How can shoppers protect their CVV?

  • Type the code only on a site you reached by typing the address yourself or through a saved bookmark.
  • Use a digital wallet or a virtual card number so a merchant never holds your main card's details.
  • Cover the back of the card when you hand it to a cashier.
  • Check statements every week, not once a month.
  • Freeze the card in your bank app the moment something looks wrong.

How do you report a CVV-selling site or card fraud?

  1. Call the card issuer and ask for a replacement card and a fraud block.
  2. File a report at IdentityTheft.gov, the FTC's official channel.
  3. File a complaint with the FBI's Internet Crime Complaint Center at ic3.gov.
  4. Send the site address, screenshots, and payment details to your state attorney general.

Reporting matters because one storefront often resells data from thousands of cards.

Frequently asked questions

Is it legal to sell CVV numbers to a cardholder?

No. Card network contracts ban sharing card data with third parties, and any buyer who then uses the number commits access device fraud. A cardholder also loses dispute rights when the code leaves their control.

Can a merchant or payment processor sell CVV data?

No. Merchants, processors, and gateways sign network agreements that prohibit storing or selling sensitive authentication data. A merchant that resells card data loses its account and faces charges under the same statutes as any other seller.

Why can't a website store CVV codes after a payment?

PCI DSS Requirement 3.2 prohibits retaining sensitive authentication data after authorization. Storing the code turns a breach into a ready-made card-not-present kit and breaks a core payment security rule.

Does the CVV stop all online fraud?

No. A stolen code can be typed into a checkout page as fast as a real shopper types it. The CVV helps most when it sits next to AVS, 3D Secure, and transaction monitoring.

Bottom line

There is no legal route to sell CVV numbers on a website, and the sites that claim to offer one are scams, police operations, or short-lived storefronts that end in seized servers. Shoppers protect themselves with virtual cards, issuer alerts, and quick reports. Merchants protect themselves by verifying the CVV, never storing it, and adding authentication that reaches the cardholder's phone.