There are no legitimate tips for selling CVV dumps. A CVV dump is stolen card data, and selling it violates the U.S. federal access device fraud statute, 18 U.S.C. § 1029, which carries up to 10 years in prison for a basic offense and up to 20 years for aggravated cases involving higher losses. The practical advice is defensive: understand how dumps circulate so your own card number and CVV never end up in one.
What is a CVV dump?
A CVV dump is a record of payment card data, typically the card number, expiration date, cardholder name, and the three or four digit CVV. The CVV is the security code printed on the card, and it exists so a merchant can prove the physical card is present.
Dumps usually come from skimmers, merchant breaches, and phishing pages, not from cardholders who gave anything away on purpose. Card networks and issuers treat any sale of that data as fraud, not commerce.
Why is selling CVV dumps a federal crime?
U.S. law treats card numbers as access devices. Trafficking in them, including selling, buying, or transferring them, is a felony even if no purchase was completed.
- 18 U.S.C. § 1029 covers producing, selling, and possessing access devices with intent to defraud.
- Aggravated identity theft charges can stack on top when a stolen card is used against a real account holder.
- State laws add their own penalties for identity theft and larceny by credit card.
How do dumps reach buyers online?
Fraud forums and messaging apps advertise card data, but the listings are also a common vector for scams that target buyers. Sellers disappear after payment, deliver dead cards, or use the conversation to install malware.
Consumers who search for dumps often land on phishing pages built to collect their own card details. That is why card-safety guidance replaces purchasing advice here.
How do you protect your CVV during online purchases?
- Use virtual card numbers from your issuer so the real CVV never leaves your possession.
- Do not store cards in browsers or shopping apps unless the merchant enforces strong account security.
- Verify the checkout is on the merchant's own domain and that the page uses HTTPS before entering a code.
- Prefer merchants that follow PCI DSS, which prohibits storing the CVV after an authorization is approved.
- Turn on transaction alerts so an unexpected charge surfaces within minutes, not on your monthly statement.
What should you do if your CVV was exposed?
Freeze or lock the card in your issuer's app immediately, then request a replacement number, because a compromised CVV cannot be reset the way a password can. Review recent charges and dispute anything you did not authorize in writing.
Report the incident to your card issuer, then file a complaint with the FBI's Internet Crime Complaint Center if the data came from a scam or breach. The FTC also publishes identity theft recovery steps at IdentityTheft.gov.
Where do you report someone selling CVV dumps?
Report the seller to your card issuer's fraud team, the platform hosting the listing, and the FBI through IC3. Keep screenshots, handles, and payment records, since investigators use those details to link cases.
FAQ
Is it safe to buy CVV dumps online?
No. The transaction is a federal crime, and most sellers are running advance-fee or malware scams against the buyer.
Do stolen CVV codes still work?
Modern issuers use real-time risk scoring, tokenization, and 3-D Secure challenges, so many dumped codes fail at checkout. Success rates quoted in listings are unreliable marketing.
Can a merchant legally store my CVV?
No. PCI DSS prohibits retaining the CVV or full magnetic stripe data after authorization, and merchants who do so fail compliance audits.