The short answer

There is no legitimate website that sells CVV data. The CVV (also written CVV2 or CVC) is the three or four digit code printed on a payment card. Its only job is to prove that whoever is typing a card number is holding the physical card. Sites, forums, and chat channels that advertise CVV data for sale are criminal marketplaces trading stolen card credentials. Buying, selling, or brokering that data is a federal crime in the United States, and most people who send money to those sites lose it to a scam on top of everything else.

What people mean by a "sell CVV online website"

The phrase describes storefronts that list card numbers with matching CVV codes, expiration dates, cardholder names, and sometimes billing ZIP codes. Listings are sorted by bank, card brand, or country, and priced in bulk. Some sites promise "fresh" or "high balance" cards. Those claims are marketing. The data behind them comes from breaches, skimming devices, phishing pages, and malware on checkout systems, and using it is card fraud.

A related search pattern involves people who already hold a card and want to sell its details for cash. Card network rules and state law treat that as enabling fraud, and the seller carries liability for charges made after the handoff.

How the card codes differ

  • CVV1: encoded on the magnetic stripe. Used when a card is swiped physically.
  • CVV2 / CVC2: printed on the back of Visa, Mastercard, and Discover cards. Used for card-not-present purchases.
  • CID: the four digit code on the front of American Express cards.
  • Dynamic CVV: a rotating code generated by a card or app. It expires within minutes and cannot be reused.

Each code is designed to be worthless on its own. A CVV2 without the account number, expiration date, and billing address fails authorization, and a merchant that follows PCI DSS rules never stores the CVV after the transaction is approved.

Why the trade is illegal

Federal law treats payment card numbers and their verification codes as access devices. Trafficking in them, producing them, or transferring them with intent to defraud falls under 18 U.S.C. 1029, which carries fines and prison terms. Related charges include wire fraud, aggravated identity theft, and conspiracy. Card networks and issuers also pursue civil claims against people who run or use these marketplaces.

How to protect your own card data

  1. Shop with merchants you can identify, and read the refund and delivery terms before you pay.
  2. Use a virtual card number or a tokenized wallet for online checkouts when your issuer offers one.
  3. Never type your CVV into an email, text message, or chat window, even if the request looks like it comes from your bank.
  4. Cover the back of your card in public and never photograph or scan it for someone else.
  5. Turn on purchase alerts in your banking app so every charge reaches your phone.
  6. Check your statements each month and dispute unknown charges inside the issuer's stated window.
  7. Set unique passwords for every merchant account through a password manager.
  8. Freeze your credit file with all three bureaus if your full identity, not just the card, may be exposed.

How to recognize a CVV-selling site or solicitation

  • Payment is accepted only in cryptocurrency or gift card codes.
  • Listings are sold in bulk tiers with claims about card balances or "success rates."
  • There is no legal entity, address, or support channel, only encrypted chat handles.
  • A "merchant" asks you to confirm your own CVV to receive a refund or release a held order.
  • The site promises a replacement or refund if a card fails, which no card network guarantees.
  • Contact arrives through a direct message, a job offer, or a "package mule" pitch that asks you to receive goods bought with stolen numbers.

If your card data was exposed

  1. Call the number on the back of your card and ask the issuer to close the account and reissue.
  2. Change the password on any merchant account where the card was saved.
  3. File a report with the FBI Internet Crime Complaint Center.
  4. Report the fraud to the Federal Trade Commission and request an identity theft recovery plan.
  5. Save screenshots, emails, order numbers, and transaction dates for the issuer and any investigator.
  6. Review charges on every other card in your wallet for the next two billing cycles.

What merchants must do

PCI DSS Requirement 3 forbids storing sensitive authentication data, including the CVV, after authorization, even in encrypted form. Checkout systems should tokenize the card number so the raw value never reaches the merchant's database, and any third party that handles card data should carry a current attestation of compliance. Skipping those controls is how breach dumps that end up on CVV-selling sites get built.

FAQ

Can I sell the CVV of my own card?

Selling your own card details to a stranger exposes you to charges, chargeback disputes, and account closure, and it can violate card network rules and state law. There is no safe version of this transaction.

Is it risky to browse a CVV-selling site out of curiosity?

Yes. Those sites host malware, credential-harvesting scripts, and wallet drainers. Visiting is not a neutral act, and interacting with one can create evidence of intent.

What should I do if a site asks for my CVV to "verify" me?

Stop the transaction. No legitimate refund, prize, or delivery process needs your CVV, and a real merchant will already have authorization on file.