The short answer is that there is no lawful way to sell CVV data online. A CVV or CVC is a verification code created so that only the cardholder and their bank can approve a charge, and offering those codes for sale is trafficking in an access device, which is a federal offense in the United States. Every site, forum thread, or chat channel that advertises a CVV supply is a fraud operation, a law enforcement trap, or a scam aimed at the person trying to sell. The work that does pay sits on the defense side of the same problem: card security, fraud analytics, and payments compliance. The paths below are compared on three criteria that matter for a real career decision: whether the work is lawful, what you need to start, and how steady the income is.

Why selling CVVs is prosecuted, not tolerated

Card verification data is treated as a credential, and credential trafficking is one of the few areas where federal prosecutors, card networks, and banks all pursue the same target with the same evidence. A listing, a chat log, or a payment record is enough to build a case, and the offense does not require that anyone actually used the code.

What the statute covers

18 U.S.C. Section 1029 makes it a federal crime to produce, sell, or transfer unauthorized access devices, a category that includes card numbers paired with their verification codes. Charges in these cases commonly include access device fraud, wire fraud, and aggravated identity theft, and the fact that you only sold the data rather than using it is not a defense.

Who absorbs the loss

The cardholder spends hours on disputes and card replacement. The merchant eats chargeback fees, lost inventory, and higher processing costs. The issuing bank funds the investigation. Card networks pass those costs back to every merchant in the form of higher interchange. That is why the payments industry funds fraud teams instead of ignoring the problem.

What a CVV actually is and who may handle it

Under PCI DSS, the CVV is sensitive authentication data. A merchant or processor may transmit it to authorize a single transaction, but it may not be stored after authorization, and it may never appear on a receipt or in a database. That single rule explains why genuine card security work revolves around encryption, tokenization, and matching, rather than around collecting codes.

Legitimate card-security paths compared

Fraud and chargeback analyst

You review transaction patterns, flag suspect orders, and manage disputes for a bank, processor, or large retailer.

  • Pros: entry friendly, high demand, clear promotion ladder into fraud strategy and data roles.
  • Cons: shift work in some operations centers, repetitive case queues, exposure to hostile customers.

Best fit if you want to start earning in the field within months and learn how carding attempts actually look in raw transaction data.

PCI compliance assessor or internal auditor

You test whether a company handles card data the way the standard requires and write up the gaps.

  • Pros: certification carries weight across industries, project based rhythm, strong day rates for qualified assessors.
  • Cons: certification exams are costly, travel is common, and the work is documentation heavy.

Best fit if you already have audit, risk, or IT controls experience and want to specialize in payments.

Payments security engineer

You build the systems that keep card data out of scope: tokenization, point to point encryption, 3-D Secure flows, and key management.

  • Pros: highest ceiling of the group, deep technical skill that transfers across fintech, remote friendly.
  • Cons: requires real software or infrastructure experience, on call rotations, constant standards updates.

Best fit for developers and sysadmins who want their work to sit directly on the card data path.

Threat intelligence and anti-fraud researcher

You track carding marketplaces and fraud tooling, then turn that into detection rules, takedown support, or customer warnings.

  • Pros: intellectually engaging, visible impact on real takedowns, blends analysis and security work.
  • Cons: smaller job pool, some roles require clearance or law enforcement partnership, emotional exposure to victim data.

Best fit if you write well, read forums critically, and want to study fraud without participating in it.

Controls that make resold CVVs useless

  • Address verification and CVV checks on every card not present transaction.
  • 3-D Secure or network tokenization so the merchant never sees the code.
  • Velocity limits on card testing patterns, such as many small authorizations from one device.
  • Device fingerprinting and behavioral signals at checkout.
  • No storage of sensitive authentication data after authorization, per PCI DSS.

If someone asks you to buy or sell CVVs

Do not send money, do not send data, and do not negotiate. Save the messages and report the contact. In the United States you can file a complaint with the FBI Internet Crime Complaint Center and report identity theft or card fraud to the Federal Trade Commission. If your own card data was exposed, call the number on the back of your card so the issuer can block the account.

Which path fits your situation

  • No security background yet: start as a fraud or chargeback analyst.
  • Audit or risk background: pursue PCI assessment work.
  • Software or infrastructure background: target payments security engineering.
  • Research and writing strength: aim for threat intelligence focused on payment fraud.

Each of these roles exists because CVV data is worth stealing. Working on the controls that make it worthless is the version of this interest that pays, lasts, and keeps you out of federal court.