Sell CVV dumps: the short answer
"Sell CVV dumps" is a phrase from the carding market. It has no place in the payments industry. Banks, processors, and merchants do not sell card numbers, CVV2 codes, or magnetic stripe data. A site that advertises bulk card data sells stolen records or runs an outright scam. U.S. law treats both as crimes.
What the terms mean
CVV and CVC
CVV stands for Card Verification Value, a term Visa uses. Mastercard calls it CVC2. American Express calls it CID. The code sits on the card: three digits on the back for Visa and Mastercard, four digits on the front for American Express. Online merchants use it to show that the buyer holds the physical card.
Dumps
A dump is data copied from a card magnetic stripe. Track 1 holds the cardholder name and account number. Track 2 holds the primary account number, expiration date, service code, and a discretionary value. The CVV2 is not on the stripe, so a dump alone does not cover a checkout form that asks for it. Sellers often bundle a dump with a "fullz" record that adds name, address, date of birth, and government ID number.
The market
Stolen card records move through closed forums, chat apps, and short-lived storefronts. Listings often claim a "valid rate" or guarantee a replacement for dead cards. Those claims are unverifiable. Payment is crypto only. Law enforcement agencies report that many of these vendors take payment and deliver nothing.
Why the trade is illegal in the United States
18 U.S.C. § 1029 covers fraud and related activity in connection with access devices. A credit card account number is an access device. Trafficking in access devices carries a maximum of 10 years for most offenses, with higher maximums for aggravated conduct, plus fines.
Records that include Social Security numbers trigger 18 U.S.C. § 1028A, aggravated identity theft. That count adds a mandatory two-year sentence that runs consecutive to the underlying sentence.
State laws add charges. Card data possession with intent to defraud is a felony in every U.S. state.
How the data gets stolen
- Skimming hardware on fuel pumps, ATMs, and self-checkout lanes
- Malware on merchant point-of-sale systems
- Phishing pages that copy a bank or retailer login
- Breaches at processors, hotels, and online retailers
- Fake support calls that ask the cardholder for a code
How the industry blocks the trade
- PCI DSS Requirement 3.2 bans storage of sensitive authentication data, including the CVV2 and the full magnetic stripe track, after authorization.
- Tokenization swaps the card number for a token so merchants never hold the real number.
- 3-D Secure asks the issuing bank to authenticate the cardholder during online checkout.
- EMV chips stop cloning at terminals. Card-present fraud fell after chip rollout, and card-not-present fraud rose.
- Address Verification Service, card verification code checks, and velocity rules flag odd orders.
What a cardholder can do
The Fair Credit Billing Act caps credit card liability at $50 for unauthorized charges. Debit card rules differ. Report a lost debit card within two business days to hold the cap at $50. Wait longer and the cap can reach $500 or more. Visa and Mastercard zero-liability policies cover most consumer cases.
- Freeze the card in the bank app and order a new number.
- Review statements and dispute unknown charges in writing.
- Use virtual card numbers for online checkouts.
- Turn on transaction alerts for every charge.
- Never read a one-time code to someone who calls you.
Red flags of a card data storefront
- Bulk card data for sale to the public
- Crypto-only payment with no refund path
- Contact limited to a chat handle
- No company registration, address, or license
- Claims of a guaranteed "valid rate"
No legitimate seller can guarantee that a card works, because a legitimate seller does not hold card data at all.