You cannot legally sell a CVV, CVC, or CVV2 number. Those three or four digits on a payment card are security credentials tied to a specific account, and trading them is card fraud under federal law in the United States. Searches for "sell CVV now" surface either criminal marketplaces or scams that target the people doing the searching.
What does "sell CVV now" actually mean?
A CVV is the card verification value printed on a card or generated dynamically for a digital wallet. It exists to prove the person paying physically holds the card, which is why online merchants ask for it at checkout.
When someone advertises a CVV for sale, they are offering stolen payment credentials. Buyers typically use them for card-not-present purchases, and the cardholder often learns about the charge only after the money is gone.
Is it illegal to sell CVV numbers?
Yes. Selling payment card data is a federal crime in the United States and carries serious penalties.
- Access device fraud statutes cover trafficking in stolen card numbers and CVVs.
- Aggravated identity theft adds mandatory prison time when the data is used to commit fraud.
- Wire fraud and money laundering charges often stack on top of the card charges.
- State laws add their own penalties for identity theft and financial exploitation.
Prosecutors do not need the seller to have used the card. Offering the data for sale is enough to support charges.
Why are CVV sellers usually scammers?
Most listings promising CVVs at low prices are traps aimed at the buyer, not the cardholder. Common patterns include:
- Advance fee demands. The seller asks for a deposit, activation fee, or escrow payment, then disappears.
- Recycled or dead data. Numbers may be expired, canceled, or already flagged by the issuer.
- Malware delivery. Files that promise CVV lists often install credential stealers on the buyer's device.
- Extortion. Some operators collect payment details and then threaten to expose the buyer.
The people who lose the most in these schemes are often the ones who went looking for stolen data first.
How is CVV data protected in legitimate payments?
Card networks and merchants operate under the PCI Data Security Standard, which sets strict handling rules for card verification values.
PCI DSS prohibits storing CVV2 or CVC2 data after a transaction is authorized, even in encrypted form. That requirement is why merchants must ask you for the code on every new purchase instead of keeping it on file.
Processors tokenize card data so a real card number never sits in a merchant database. Tokenization means a breach at one retailer does not hand attackers a usable CVV.
How do consumers keep their CVV safe?
Small habits close most of the gaps attackers rely on.
- Never read your CVV aloud in a public place or type it into an unsolicited message.
- Check for HTTPS and a recognizable domain before entering card details online.
- Prefer virtual card numbers from your issuer for one-off purchases and subscriptions.
- Cover the back of your card and avoid photographing it, including for "verification" requests.
- Review statements for small test charges that often precede larger fraudulent ones.
What should you do if your CVV is exposed?
Contact your card issuer immediately and ask for the card to be replaced with a new number and a new CVV. In the United States, the Fair Credit Billing Act limits your liability for unauthorized charges, but you must dispute them promptly.
File a report with the FTC at IdentityTheft.gov and, if money was lost, with your local police. Reporting creates the paper trail issuers and investigators need.
Frequently asked questions
Can I sell my own CVV for money?
No. Selling access to your own account data still enables fraud, and it can expose you to charges as an accomplice or a money mule.
Where is the CVV on a card?
On most cards it is a three-digit code on the back signature panel. American Express prints a four-digit code on the front above the card number.
Do legitimate companies ever ask for a CVV by email?
No. Reputable merchants collect the code only inside a secure checkout page, never through email, text, or chat.