What Does "Sell CVV for Money" Mean?

Selling a CVV for money means trading the three or four digit security code on a payment card as a criminal product. The seller, the buyer, and any broker in the middle commit payment card fraud, and US federal law treats all of them as felons. No legal market exists for this data, and no version of the transaction is safe for either side.

The CVV is the code printed on the back of most cards, or on the front of American Express cards. It proves that whoever is typing card details holds the physical card. Strip that proof away and a card number turns into a string anyone can abuse.

Why Your Card Has a Security Code

Card networks added the CVV in the 1990s to cut down on mail-order and phone-order fraud. The code is not stored on the magnetic stripe and, under PCI DSS rules, merchants may not keep it after a transaction is authorized.

That single design choice explains most of what follows. If the code cannot be stored, then anyone advertising a bulk list of codes has either stolen them through skimming, phishing, or a breached database, or is lying about having them at all.

Is Selling CVV Data a Crime in the United States?

Yes. Trafficking card security codes is a federal felony, not a gray-area hustle.

  • 18 U.S.C. § 1029 covers access device fraud. Selling, transferring, or possessing card data with intent to defraud carries fines and prison time measured in years.
  • 18 U.S.C. § 1028 covers identity theft, with a mandatory two-year sentence stacked on top of other charges in aggravated cases.
  • State laws in every US state add their own fraud, larceny, and computer crime charges.
  • Conspiracy and money laundering charges often follow when payments move through banks, prepaid cards, or crypto.

Prosecutors do not need a completed sale to file charges. Offering card data for sale, or agreeing to buy it, is enough.

Why Most "CVV for Sale" Offers Are Scams

The people who claim to sell card codes for money prey on buyers who cannot complain to anyone. That makes the field a magnet for fraud aimed at fraudsters.

  • Payment-first scams. The buyer sends crypto or a gift card code and receives nothing.
  • Dead data. Codes from breached lists are often already canceled by the issuing bank.
  • Resold lists. One stolen card number can be sold to dozens of buyers within a day.
  • Blackmail. Some operators keep a buyer's contact details and demand more money to stay quiet.
  • Sting operations. US and international law enforcement run controlled channels to identify buyers and sellers.

How Stolen Card Data Gets Used

Card-not-present fraud is the main use case, because no physical card or chip check is required. Fraudsters test a code with a small purchase, then move to larger ones if the charge clears.

Common cash-out paths include gift cards, electronics shipped to vacant addresses, reshipping crews, and digital subscriptions billed to the stolen card. Issuers spot the pattern through transaction velocity and address mismatch checks, which is why many stolen codes get declined on the first real attempt.

How Banks and Merchants Block CVV Fraud

  • CVV validation. The code must match what the issuer holds for that account. A wrong code kills the transaction.
  • Address Verification Service (AVS). Billing street number and ZIP code must line up with issuer records.
  • 3-D Secure. The bank pushes a one-time passcode or app approval to the cardholder during checkout.
  • Velocity rules. Multiple cards tried from one device or IP address trigger blocks.
  • Device fingerprinting and machine learning. Fraud models score each order before it ships.

How to Protect Your Own CVV

  1. Never read the code out loud on a call you did not place. Banks do not ask for it, and neither do tax agencies or utilities.
  2. Cover the back of your card when paying in person, and keep it out of photos.
  3. Use virtual card numbers or tokenized mobile wallets for online checkout. The real code never leaves your bank.
  4. Shop with merchants that ask for the CVV plus a bank approval step, not just the card number.
  5. Check your statements each week instead of each month. Small test charges are the earliest warning sign.
  6. Freeze the card from your bank app the moment something looks wrong.

What to Do If Your Card Data Is Exposed

  1. Freeze or lock the card through your bank's app or website.
  2. Call the number on the back of your card and ask for a new number, not just a new card.
  3. Dispute any charge you did not make in writing.
  4. Report identity theft at IdentityTheft.gov and file a complaint with the FBI's Internet Crime Complaint Center.
  5. Change passwords on any shopping accounts that stored the card.

Frequently Asked Questions

Can you sell a CVV legally?

No. Card security codes belong to the issuing bank and the cardholder. Selling one is access device fraud with no legal exemption for "consulting," "testing," or "verification."

What is the punishment for selling CVVs?

Federal penalties include fines and prison terms of several years for a basic offense, with longer sentences when the fraud totals more money or involves identity theft. Restitution and a permanent criminal record come with it.

Why do fraudsters ask for the CVV instead of just the card number?

Because the CVV is the one piece of data a thief cannot guess and merchants are not allowed to store. Forcing a match is the cheapest defense a card-not-present transaction has.

Does the CVV ever appear on a receipt or statement?

No. PCI DSS forbids storing the code after authorization, and receipts and statements mask both the card number and the code.

Is buying a CVV a crime too?

Yes. Attempting to buy card data is a federal offense, and undercover operations routinely target buyers, not only sellers.