Sell CVV online for PayPal: the short answer

The phrase describes a fraud market that runs on hidden forums. Selling card data that belongs to another person is a federal crime in the United States. Buyers who pay for these listings lose money in most cases. There is no legal version of this business, and no legitimate processor or bank will touch it.

What a CVV is

A CVV is a 3-digit code printed on the back of a Visa, Mastercard, or Discover card. American Express prints a 4-digit code on the front. Merchants use the code to confirm that the buyer holds the card during a card-not-present charge. PCI DSS Requirement 3.2 bars merchants and processors from storing the CVV or CVC after authorization. That rule limits where the data can leak in the first place.

Why PayPal does not match the claim

PayPal login works with an email address and a password, plus a one-time code in many cases. Card verification values do not appear in that flow. A card number can be added to a PayPal wallet, but the CVV is used at the moment of linking, not for later account access. Listings that promise PayPal CVV data sell stolen card numbers, a script, or nothing at all.

Law and penalties

18 U.S.C. 1029 covers access device fraud. The statute reaches the sale, transfer, and possession of card numbers with intent to defraud. Maximum terms run to 10 years for a first offense and 15 years for cases with losses above set thresholds. 18 U.S.C. 1343 covers wire fraud. 18 U.S.C. 1028 covers identity theft. State laws add charges on top. Prosecutors stack counts by card number, so a list of 500 numbers can produce 500 counts.

What happens to buyers

Carding forums run on escrow and reputation systems that the forum operators control. Many sellers take payment in crypto and deliver invalid numbers. Others deliver numbers that work once, then draw a chargeback. Card issuers flag merchant categories with high fraud rates. Banks close accounts tied to card testing. A buyer has no recourse, because the purchase itself is a crime.

How card data gets stolen

Common sources include skimmers on gas pumps and ATMs, phishing email, and web skimming scripts injected into checkout pages. Breach reports from Verizon and the FTC track web skimming as a recurring pattern in e-commerce. Data from one breached merchant can appear on several forums within days.

Protection steps

  • Turn on 2FA for PayPal and for the email account tied to it.
  • Use a virtual card number at checkout when the issuer offers one.
  • Review statements each month and dispute charges in writing within 60 days.
  • Freeze your credit file at Equifax, Experian, and TransUnion.
  • Report card fraud to the FTC and to the FBI Internet Crime Complaint Center.