Short answer
There is no legal way to sell CVV data right now or at any time. A CVV is a security code tied to one payment card. The issuer gives that code to the cardholder. A sale of the code to a third party without the cardholder's consent is carding. US law treats it as access device fraud.
What a CVV is
Visa calls the three-digit value on the back of a card CVV2. Mastercard calls it CVC2. American Express prints four digits on the front. Online merchants ask for the value at checkout to prove the buyer holds the physical card. Card networks build the value from the card number, the expiration date, and a key held by the issuer. The value changes when the card is reissued.
Selling CVV Dumps Now: A Comprehensive Guide
Some issuers now use a dynamic CVV on a card with a display or in a mobile app. The value refreshes on a timer. A stolen static CVV from an older card keeps its value until the card is replaced.
How to Sell CVV Numbers: Why It Is Illegal Carding and How to Stay Safe
Why the sale is a federal crime
A payment card and its CVV are "access devices" under 18 U.S.C. § 1029. A person who traffics in unauthorized access devices with intent to defraud can face a fine and up to 10 years in prison for a first count. Aggravated counts carry higher maximums. A conspiracy charge under 18 U.S.C. § 371 adds up to 5 years. Wire fraud under 18 U.S.C. § 1343 adds up to 20 years. Identity theft under 18 U.S.C. § 1028A adds a mandatory 2-year term that runs after the other sentence.
State law adds charges. Most states treat possession of card data with intent to sell as a felony. Some states set thresholds as low as one account.
How card data reaches sellers
Card data leaves a cardholder through a small number of paths. Enforcement reports list the common ones.
- Skimming at a fuel pump, ATM, or point of sale terminal.
- Phishing pages that copy a bank login or a checkout form.
- Malware on a phone or computer that reads stored card data.
- Breaches at a merchant or processor that keeps card data outside the rules.
- Social engineering calls that ask a cardholder to read the code out loud.
Buyer-side fraud also plays a part. A person can test a card number at a low-value checkout, then resell the number to another buyer. That resale is the market the search phrase points to.
Enforcement
The US Secret Service runs Operation Boiling Point. The operation targets carding sites, transaction laundering, and the payment channels those sites use. The FBI's Internet Crime Complaint Center collects reports from victims and publishes yearly loss totals. The FTC takes consumer reports at IdentityTheft.gov and runs cases against payment processors that move fraud proceeds.
Prosecutors link several counts in one case. A single carding site can produce charges for access device fraud, wire fraud, money laundering, and identity theft. Sentences stack.
If a CVV was sold from your card
- Call the number on the back of the card and ask for a block and a reissue. A reissue changes the card number and the CVV.
- Review the last 12 months of statements. Dispute charges you do not recognize in writing.
- Change the password on the bank account and turn on two-factor authentication.
- File a report at IdentityTheft.gov to get a recovery plan.
- File a complaint with the FBI at ic3.gov. Include dates, amounts, and merchant names.
- Place a fraud alert or a credit freeze with the three credit bureaus.
Federal law limits a cardholder's liability for unauthorized card charges. The card network rules and the Truth in Lending Act set the terms. A cardholder who reports a lost card before charges appear pays nothing in most cases.
What merchants should do
PCI DSS forbids storage of the card verification value after authorization. The rule exists because a stored CVV turns a database breach into a carding supply. Merchants that keep the value in logs, order notes, or a support tool break the standard and add legal risk.
- Tokenize the card number. Keep the token in the order record.
- Use 3-D Secure for card not present payments.
- Run address verification and CVV checks at checkout.
- Block multiple card attempts from one device or IP in a short window.
- Log failed attempts and review them.
A merchant that suspects a card testing attack should contact its acquirer and the card network. Some processors can block the traffic at the gateway.
Search terms and intent
Queries such as "sell cvv right now" point to fraud. Legitimate payment work uses different terms: payment tokenization, chargeback prevention, card not present fraud, and EMV 3-D Secure. A person who searches for a CVV market is looking for stolen data or for a buyer. Both roles carry the same statutes.