Sell CVV dumps: the short answer
"Sell CVV dumps" is a phrase from fraud markets. It describes the sale of stolen payment card data. The data comes from two sources: card numbers with the printed verification code, called CVV or CVC, and "dumps," which are copies of the data encoded on a card's magnetic stripe. Selling this data is a federal crime in the United States. Buyers and sellers both face prison time under 18 U.S.C. 1029. This page describes the market and the law. It does not give instructions or sources for buying or selling card data.
What the terms mean
CVV and CVC
Visa, Mastercard, and Discover print a 3-digit code on the back of the card. American Express prints a 4-digit code on the front. The code is a check value. The issuer computes it from the card number, the expiration date, and a secret key. A merchant that asks for the code can confirm the buyer holds the card.
The code is not the PIN. The PIN authorizes a transaction at a terminal or an ATM. The CVV is a data check for card-not-present orders.
Dumps
A dump is the raw content of Track 1 and Track 2 on a magnetic stripe. Track 2 holds the card number, the expiration date, and a service code. A dump can be written to a blank card with a stripe encoder. That card then works at terminals that read the stripe.
Where the data comes from
- Skimmers placed on gas pumps, ATMs, and point-of-sale terminals.
- Breaches at merchants that stored data they were not allowed to keep.
- Phishing pages and fake checkout forms that capture card fields.
- Malware on a consumer device or on a merchant network.
What US law says
18 U.S.C. 1029 covers fraud and related activity in connection with access devices. A payment card number is an access device under the statute. Producing, selling, or transferring card data with intent to defraud carries a prison term of up to 10 years. Offenses that involve 15 or more counterfeit or unauthorized devices carry up to 15 years. A prior conviction raises the maximum to 20 years. 18 U.S.C. 1028A adds a mandatory 2-year term when the offense involves identity theft.
Who pays the loss
Under the Fair Credit Billing Act, 15 U.S.C. 1643, a consumer's liability for unauthorized credit card charges is capped at $50. Debit card rules under the Electronic Fund Transfer Act set $50 if the loss is reported within 2 business days, and up to $500 if it is reported later. A cardholder who still holds the card pays nothing in most cases. The loss moves to the issuer, and the issuer recovers part of it from the merchant's acquirer when the merchant did not follow card rules.
Rules for merchants
PCI DSS Requirement 3.3.1 states that sensitive authentication data is not stored after authorization. That data includes the full magnetic stripe, the CVV or CVC, and the PIN block. A merchant that keeps the code after an authorization decision is out of compliance. Merchants that store card numbers must encrypt them and mask the display.
What cardholders can do
- Read statements each month and report charges you do not recognize.
- Use chip or contactless payment at terminals instead of a swipe.
- Do not send card photos or codes by email or chat.
- Turn on transaction alerts with the issuer.
- Freeze the card in the issuer's app when it is not in use.
What is not known
Public data on the size of the stolen card market is an estimate. Few reporting parties share raw logs. Figures from industry and law enforcement sources differ by method and by year.