Searches for "sell cvv at low rates" lead to carding forums, Telegram channels, and fake shops that trade stolen card numbers. Selling or buying that data is a federal crime in the United States. The "low rate" pitch is also a common scam: most sellers take payment in crypto and send nothing, or send card numbers that were already canceled. There is no legitimate market for CVV data at any price.
What the Phrase Actually Means
A CVV is the three-digit code on the back of most Visa, Mastercard, and Discover cards, or the four-digit code on the front of an American Express card. The code exists to prove the person paying holds the physical card. A "CVV list" is a batch of stolen card numbers bundled with cardholder names, billing ZIP codes, and expiration dates. Sellers advertise low prices per record because volume is the business model, not because the data is legitimate.
Why It Is Illegal
Federal law treats payment card numbers as access devices. Trafficking in them, including selling, buying, or transferring them, falls under 18 U.S.C. Section 1029 and carries prison time and heavy fines. The FBI's Internet Crime Complaint Center tracks carding as a persistent complaint category, and card networks monitor forums and shops for takedown referrals. Anyone who advertises CVV data for sale is exposing themselves to criminal prosecution and civil liability from card issuers.
Buy CVV/CVC Security for Online Purchases: A Comprehensive Buying Guide
Why the Cheap Listings Usually Burn the Buyer
- The seller collects payment and stops responding.
- The card numbers were declined or canceled weeks earlier.
- The buyer's wallet address and identity get logged for later extortion.
- Some storefronts are run by researchers or law enforcement building cases.
- Payment processors and exchanges freeze accounts tied to the transaction.
How to Protect Your Own Card Data
- Generate a virtual card number from your issuer for online purchases.
- Turn on real-time transaction alerts in your banking app.
- Keep the CVV out of saved notes, screenshots, and chat messages.
- Shop with merchants that support 3-D Secure verification at checkout.
- Review your statements every week and dispute unknown charges within 60 days.
- Report a compromised card to your issuer, then to the FTC at IdentityTheft.gov.
What Merchants Should Do
PCI DSS Requirement 3.2 prohibits storing the CVV after authorization, in any form, even encrypted. Merchants should tokenize card data at the point of capture so the CVV never reaches a database. Add rate limiting and velocity checks to block BIN attacks, which test thousands of card numbers against a checkout page. Require address verification and CVV checks on card-not-present orders, and flag orders where the two disagree.
If You Encounter These Offers
Do not engage, do not send funds, and do not download anything from the page. Report the listing to the FBI's Internet Crime Complaint Center and to the card network's fraud team. If your own card number appears in such a listing, call the issuer immediately and request a new number.