Short answer

There is no legal way to sell CVV data to carding sites in the United States. The sale is access device fraud under 18 U.S.C. § 1029 and wire fraud under 18 U.S.C. § 1343. Federal courts impose prison terms, fines, restitution, and supervised release. Buying, brokering, or holding the data carries its own charges, and using another person's card number adds a mandatory two-year sentence under 18 U.S.C. § 1028A. Carding sites are criminal marketplaces, so every hand the data passes through creates a separate offense.

How to Earn from Selling CVV on Carding Sites: A Comprehensive Guide

What CVV means in a card-not-present purchase

Issuers place more than one verification value on a payment card. The CVV1 lives in the magnetic stripe and is read when a card is swiped. The CVV2, called CVC2 at Mastercard and CID at American Express, is the three or four digit code printed on the card itself. An online merchant never sees the stripe, so the printed value is the check that the person typing the number holds the physical card. That single check is why a stolen card number without the printed code sells for less in criminal markets and why carding sites solicit the full set of data.

carding site cvv requirements

Why the sale is a felony rather than a gray area

Federal law treats a card account number plus its verification code as an access device. Section 1029 covers producing, selling, transferring, and possessing those devices with intent to defraud, and the statutory maximums for the core trafficking offenses start at 10 years and rise with aggravating factors. Section 1343 covers the interstate wires used to move the data and the money. Sentencing guidelines add levels for the number of accounts, the dollar loss, and the use of a computer. A first offense with a few hundred accounts can produce a multi-year prison term, and the record follows the defendant for life.

carding site cvv requirements

Where card data leaks before it reaches a carding site

  • Skimming hardware and overlay pads placed on fuel pumps, ATMs, and self-checkout lanes
  • Phishing pages and text messages that copy a bank, a utility, or a delivery company
  • Merchant breaches caused by storing payment data in violation of PCI DSS
  • Credential stuffing against shopping accounts that reuse one password
  • Insider theft at call centers, hotels, and retail counters

Red flags that a checkout is being tested

  • Several orders to one address from different card numbers
  • Overnight shipping paired with a billing address that does not match the issuer record
  • A string of declines followed by small test purchases
  • Customer email domains registered days before the order
  • Requests to split one order across multiple cards

If your card data is exposed

  1. Lock the card inside your bank or issuer app.
  2. Call the number on the back of the card and report the exposure.
  3. Review the last 90 days of statements and mark every charge you do not recognize.
  4. Submit a written dispute for each unauthorized charge and save the confirmation number.
  5. Ask for a new card number instead of a replacement on the same account.
  6. Place a free fraud alert or credit freeze with each credit bureau.
  7. File a report with the FTC identity theft portal and, if money was taken, with the FBI Internet Crime Complaint Center.

What merchants must never do

PCI DSS forbids storing sensitive authentication data, including the printed card verification value, after a transaction is authorized. That rule covers databases, backups, log files, order notes, and help desk tickets. A merchant that keeps the code for chargeback defense is out of compliance and turns a routine dispute into a breach. Tokenization plus a compliant payment processor keeps the value out of your systems from the first keystroke.

related article

Bottom line

The phrase describes a felony market, not a business model. Card verification codes exist to prove that a cardholder is present, and the laws that punish trafficking in them also give consumers strong dispute rights when a number is stolen. Shoppers should monitor statements and freeze credit when data leaks. Merchants should never retain the code, should train staff to spot test orders, and should route every payment through a PCI DSS compliant processor.