There is no legal way to sell CVV numbers online. Trafficking card security codes violates 18 U.S.C. § 1029, the federal access device fraud statute, and carries prison time plus restitution to banks and merchants. Anyone searching for how to sell CVV online is looking at a felony, not a business model.
What does selling a CVV mean in practice?
A CVV is the 3 or 4 digit security code printed on a payment card. Selling that code, or a card number bundled with it, hands another person the data needed to charge a card that is not theirs. US law treats the code as an access device, the same category as a card number or a PIN.
The trade happens on dark web forums, private chat groups, and paste sites. Buyers use the data to place card-not-present orders at online stores. No seller holds a lawful license to the data, so every transfer is a crime.
Which laws make selling CVV data a crime?
- 18 U.S.C. § 1029 (access device fraud): covers producing, selling, transferring, or possessing card data with intent to defraud. Penalties reach 10 years for a first offense and 15 years for repeat offenses.
- 18 U.S.C. § 1343 (wire fraud): applies when card data crosses state lines or moves over the internet.
- 18 U.S.C. § 1028 (identity theft): applies when the card data ties to a real person's identity.
- State statutes: most states add their own identity theft and computer crime charges.
Charges stack. One carding operation can produce counts under several statutes at once, and each count carries its own sentence.
Can someone face charges for selling one CVV?
Yes. The federal statute sets no minimum number of cards. Selling a single code with intent to defraud is enough for a charge. Prosecutors group small cases with larger ones when the same devices, accounts, or chat handles appear.
How do banks and processors catch card data sales?
Issuers and payment processors score every transaction that runs through their systems. A batch of orders that share a card range, a device fingerprint, or a shipping address trips those rules within hours.
- CVV mismatch and address verification (AVS) failures flag a stolen card fast.
- Velocity checks catch one card used at several stores in a short window.
- Device and IP fingerprints link accounts that look unrelated on the surface.
- 3-D Secure challenges force a step the buyer cannot pass without the cardholder's phone or banking app.
Payment networks share fraud signals across members, so a card reported once gets blocked at many merchants at the same time.
What happens to people who sell stolen CVV data?
Federal prosecutions for access device fraud end in prison, supervised release, and restitution to the banks and merchants that absorbed the loss. Courts also order forfeiture of computers, phones, and any crypto or cash tied to the scheme.
Sentencing guidelines add time based on the number of victims and the total dollar loss. Cases with hundreds of compromised cards often land in the multi-year range. Cooperating with investigators may reduce a sentence, but it does not erase a conviction.
Why CVV data has less value than sellers claim
Card security has moved past the static printed code. Tokenization replaces the card number with a value that works at one merchant or for one transaction, and the real CVV never reaches the merchant after authorization.
PCI DSS forbids storing the CVV once a transaction is approved. That rule removes the easiest source of bulk card data and shrinks the pool that fraud markets can trade. Banks can also reissue a card and void the old code, which wipes out whatever a buyer paid for.
How to report CVV fraud and carding activity
- Report the fraud to your card issuer and request a new card number.
- File a complaint with the FTC at reportfraud.ftc.gov.
- Send details to the FBI Internet Crime Complaint Center at ic3.gov.
- Keep records: statements, screenshots, and any messages you received from a seller.
Reports help link cases. One complaint will not close an operation on its own, but a set of them gives investigators the pattern they need to act.
How to protect your own card data online
- Use virtual card numbers from your bank for online checkout.
- Turn on transaction alerts so a charge you did not make reaches you the same day.
- Enroll in 3-D Secure when your issuer offers it.
- Skip saving card details in store accounts you visit once.
- Review your statements every month rather than at year end.
Merchants should tokenize card data, run AVS and CVV checks on every order, and never store the security code. Those steps cut the resale value of stolen data and reduce chargebacks at the same time.
FAQ
Is selling CVV numbers legal anywhere in the US?
No. Federal law and every state criminalize the sale or transfer of card data that belongs to someone else. There is no license, registration, or permit that makes it lawful.
Can I sell a CVV from my own card?
You can give someone permission to use your own card for a specific purchase, but selling the code as data is not a recognized transaction. If the buyer uses it for anything beyond what you agreed to, you carry the loss and may face questions about your role.
What is the difference between CVV, CVC, and CVV2?
They are the same thing under different names. Visa uses CVV2, Mastercard uses CVC2, and American Express and Discover use CID. All of them refer to the code that proves the physical card is in hand.
Does a VPN hide a card data seller?
A VPN hides an IP address, not a payment trail, a seized device, or a person. Investigators use subpoenas, chat logs, and hardware forensics, and those routes survive most anonymizing tools.