The short answer
There is no legitimate market for selling CVV or CVC numbers online. The three or four digit code printed on a card has one job: to prove the person typing the card number has the physical card in hand. It is not a product, a commodity, or a subscription. Any listing that promises "legit CVV," "fresh" data, a verified vendor, or escrow protection is either moving stolen card data or, far more often, selling nothing and collecting payment from buyers who cannot complain to police without implicating themselves.
If you searched this phrase because someone offered you a deal, treat that offer as a scam until proven otherwise. If you searched it because you run an online store and want to know what you are allowed to do with the codes your customers type in, the answer is narrower and stricter than most people expect.
What the "legit CVV seller" pitch actually is
The pattern barely changes. A seller shows screenshots of a dashboard, a balance, or a chat full of supposed happy buyers. Payment is requested in cryptocurrency or a gift card, because both are hard to reverse. Then comes the second ask: a "activation fee," a "verification deposit," or a minimum order. The first payment is the product. There is no second step that ends with working card data.
Two outcomes are common. In the first, money vanishes and the account goes quiet. In the second, the buyer receives card numbers that were skimmed or bought in a breach. Using them turns a bad purchase into federal card fraud, and the trail runs through the buyer's own IP address, wallet, and bank account.
Why real merchants never sell CVVs
Payment card rules forbid it. The PCI Data Security Standard requires that sensitive authentication data, which includes the CVV and CVC, is not stored after a transaction is authorized. That applies even if the data is encrypted, even if the merchant has a good reason, and even if the customer consents. There is no lawful channel where a business sells the verification codes it receives. A merchant that keeps them is out of compliance and sitting on a liability.
That is also why recurring billing does not use the CVV. Subscriptions rely on a token or a stored card number from the issuer, because the code cannot legally be kept for the next charge.
What the code is actually for
Card-not-present transactions carry more risk than swipes, so issuers and networks use the CVV as one signal among several. It confirms the card is in hand. It is paired with address verification, which checks the billing street number and ZIP against issuer records. Neither is a guarantee. A stolen card number with the code copied from the back still passes both, which is exactly why online stores watch velocity, device fingerprints, and shipping patterns instead of trusting a single field.
If you sell online, this is the practical checklist
- Never store the CVV in a database, a spreadsheet, a help desk ticket, or a note field. If a customer emails it, delete the message after processing.
- Let a validated payment provider handle the field so the code passes through rather than settling on your systems.
- Turn on address verification and require the code for card-not-present orders, then review the mismatches instead of auto-voiding all of them.
- Train staff to never read a full card number or code back in a chat, and never ask for either by email.
- Keep your checkout on a current PCI DSS version and confirm your provider's compliance in writing.
If you are a shopper
A site asking you to email your card number and code is a red flag. So is any checkout that skips a secure payment page, or a seller on a marketplace who wants payment off-platform. Virtual card numbers from your issuer limit the damage if a merchant is breached, since the number can be frozen after one use.
Unauthorized charges should go to your card issuer first, then to the FTC's identity theft reporting service if accounts or personal data are involved. Suspected fraud marketplaces are worth reporting to the FBI's Internet Crime Complaint Center, even if you lost money and feel foolish. Those complaints are how the pattern gets mapped.
The bottom line
Legitimate CVV sales do not exist. The code is a verification signal, not inventory. Anyone trying to sell it is breaking the law or taking your money, and sometimes both.