No. Selling CVV dumps is illegal in the United States in 2024, and it is a criminal offense in Canada, the United Kingdom, the European Union, Australia, and every other market where card payments function. No statute, regulator, or card network has created a licensed market for stolen card data, and no exemption exists for small sales, private chats, or offshore hosting. Three criteria decide legality: whose account the data belongs to, whether the account holder authorized the transfer, and whether the seller has a documented business reason such as authorized security testing. Miss any one of them and the sale is a crime.
How to Safely Sell CVV Dumps in 2024
What a CVV dump actually is
In carding slang, a dump is a copy of the data stored on a payment card, usually track 1 or track 2 plus the card verification value. That data is enough to build a counterfeit card or to run a card-not-present transaction. In legal language the same data is an access device: a card number, an account number, or another means of account access. The label changes nothing. Selling a card number you do not own and were not authorized to transfer is trafficking in an access device, whether the buyer pays in cash, crypto, or store credit on a forum.
Federal law: 18 U.S.C. § 1029
The primary federal statute is access device fraud. It reaches the conduct that makes a CVV market work, including the following:
sell cvv dumps 2024 best price
- Producing, selling, or transferring counterfeit or unauthorized access devices.
- Trafficking in access devices, which covers selling card data to another person.
- Possessing 15 or more counterfeit or unauthorized access devices with intent to defraud.
- Using an access device to obtain money, goods, or services worth $1,000 or more in a one-year period.
Most convictions carry fines and up to 10 years in prison, with aggravated versions reaching 15 years. Prosecutors rarely charge one count. Wire fraud, identity theft, and conspiracy charges are commonly added, and the identity theft statute carries a mandatory consecutive term when it is charged. A sale that crosses state lines, runs over the internet, or settles through a payment processor supplies the interstate element without difficulty.
Selling CVV Dumps Online in 2024: Illegal and Often a Scam
State law covers the same conduct
Every state has identity theft, unlawful card use, and computer crime statutes that apply to card data trafficking. State charges can proceed even when federal prosecutors decline a case, and penalties scale with the dollar amount and the number of victims. A seller who moves data across three states can face charges in each of them. Local police departments and state attorneys general bring these cases on their own.
Outside the United States
The United Kingdom covers this conduct through the Fraud Act 2006 and the Computer Misuse Act 1990. Canada addresses it in section 342 of the Criminal Code, which prohibits possessing, using, or trafficking in credit card data. EU member states criminalize it under national implementations of fraud and computer misuse directives. Investigators share evidence across borders, and operators of card data marketplaces have been extradited to face charges. Hosting a shop in a country with weak enforcement does not create a safe harbor, because the victims, the banks, and the payment rails are elsewhere.
Card network and PCI rules make it a contract problem too
Separate from criminal law, the PCI Data Security Standard forbids storing sensitive authentication data, which includes the card verification code, after authorization. The prohibition applies even if the data is encrypted. Merchants and service providers that keep CVV values fail their assessments, and acquirers can terminate their processing. This closes off the argument that a legitimate business might buy or warehouse CVV data. There is no lawful commercial category for a CVV dump, because the industry rules bar the data from being stored at all.
What lawful work with card data looks like
- Authorized penetration testing with a written scope from the issuer or merchant.
- Fraud and risk teams working with tokens, hashed values, or non-sensitive data.
- Merchants transmitting the verification value in an authorization message without storing it afterward.
- Researchers using test card numbers and synthetic data under a lab agreement.
Two things tie these together: written authorization from the party that controls the account, and data minimization. Real fraud analysts rarely touch a live CVV, because the networks designed the system so they do not have to.
Legal handling compared with selling dumps
Handling card data under authorization
- Pros: no criminal exposure, processing relationships stay intact, and the work is insurable and defensible in a dispute.
- Pros: clear audit trail if a regulator or acquirer asks questions.
- Cons: compliance cost in assessments, network segmentation, logging, and staff training.
- Cons: data minimization limits what can be retained, which slows some analytics.
- Cons: written authorization takes time to obtain and renew.
Selling CVV dumps
Sellers advertise fast cash and anonymity as the upside of the trade. Neither claim survives a subpoena served on a forum, an exchange, or a wallet provider.
- Cons: federal felony exposure with fines and prison terms measured in years, plus state charges.
- Cons: additional counts for wire fraud, identity theft, and conspiracy.
- Cons: forfeiture of proceeds, devices, and accounts tied to the scheme.
- Cons: no legal recourse when a buyer or marketplace operator takes the money and disappears.
- Cons: blocked payment rails, closed accounts, and lifetime bans from processors.
That asymmetry answers the keyword question in practical terms. The activity carries felony risk with no enforceable contract behind it.
What this means for shoppers and merchants
- Never send a card verification value by email, chat, or text message. A legitimate merchant asks for it only inside a checkout form.
- Merchants should confirm that their payment page posts the value straight to the processor and that nothing writes it to a database or a log file.
- Use virtual card numbers for subscriptions and unfamiliar sellers so a leaked number has a short life.
- Report offers to buy or sell card data to the card issuer and to the FBI Internet Crime Complaint Center.
Use-case recommendation
If you are a merchant or a payment professional, treat any inbound offer to sell card data as a fraud signal, archive it, and report it. If you are a shopper, the only decision you need to make is whether the checkout page is the place you are typing your code. If you study fraud or work in security research, get your card data from issuer test BINs and lab agreements rather than from a marketplace. In all three cases the legal path is narrower than the illegal one is loud.
Short answers to common follow-ups
Is buying CVV dumps legal?
No. Buying is trafficking and possession with intent to defraud, and it carries the same statutory exposure as selling.
Can I sell the CVV of my own card?
Giving your card number to a merchant to complete a purchase is ordinary commerce. Handing your card details to someone you know intends to use them for fraud can make you part of the scheme, and the proceeds are still forfeitable.
Does an offshore site make it legal?
No. The location of the website does not change the law that applies to the seller, the buyer, or the banks that absorb the loss.
Did anything change in 2024?
No legislature decriminalized card data sales or created a licensing regime for them. Enforcement continued under statutes that have been in place for decades.