"Sell CVV to shop" is carding slang for offering stolen card verification values (CVV, CVC, CVV2) to buyers who use them to place fraudulent orders at online stores. It describes a criminal market, not a legitimate service. No lawful business sells card security codes, and anyone offering to do so is either committing access device fraud or running a scam against other criminals.
What does "sell CVV to shop" actually refer to?
The phrase combines two ideas: a stolen card's three or four digit verification code, and a target merchant where that code can be spent. Carding forums use wording like this to advertise stolen card data to people who want to buy goods with someone else's account. The "shop" in the phrase is usually the victim merchant, not the seller.
Because CVV codes are not stored by legitimate processors after authorization, any code being sold has to come from somewhere else. Common sources include phishing pages, skimming devices, malware on a shopper's device, and data breaches at small merchants. The result is the same: a real cardholder's money and a real store's inventory.
Why is selling CVV data illegal in the United States?
Trafficking card credentials falls under access device fraud, 18 U.S.C. Section 1029, which covers producing, selling, and using stolen account numbers and verification codes. Penalties escalate with the number of cards and the dollar value of the fraud, and prosecutors frequently add wire fraud and identity theft charges. Buying the data is treated as seriously as selling it.
Sell CVV on Shop: Why It Is Illegal and What to Buy Instead
Card networks also treat the activity as a merchant risk, not just a consumer problem. When fraud is traced back to a store, that store can face chargeback fines, higher processing rates, and losing the ability to accept cards at all.
How do online shops detect stolen-card purchases?
Legitimate merchants fight carding with layered checks rather than a single rule. The goal is to make stolen codes worthless at checkout before an order ships.
- CVV verification: Requiring the code on every transaction blocks data sold without it and catches codes that do not match the issuing bank.
- Address Verification Service (AVS): Comparing billing address to the issuer's records flags mismatches common in carding orders.
- 3-D Secure authentication: Pushing the cardholder into an issuer challenge defeats most bulk card testing.
- Velocity and device checks: Many small orders from one device, IP range, or email pattern signal automated card testing.
- Manual review rules: High-value orders, expedited shipping, and mismatched billing and shipping addresses are classic fraud markers.
PCI DSS also forbids storing sensitive authentication data, including CVV2, after authorization. Merchants that keep it in a database create the exact asset that carding sellers want to steal.
How do you spot a store or listing that claims to sell CVV data?
A genuine payment processor never asks a shopper to share a CVV by email, chat, or text. If a site or message offers to sell card codes, treat it as a fraud operation and report it. The same warning applies to anyone who asks you to "verify" your card by sending the code.
What should you do if your CVV is compromised?
- Freeze or lock the card in your bank's app, or call the number on the back to cancel it.
- Request a new card number, not just a new expiration date.
- Review recent statements and dispute charges you do not recognize.
- Report the theft at IdentityTheft.gov and file a complaint with the FBI's Internet Crime Complaint Center.
- Change passwords on shopping accounts and turn on multi-factor authentication.
Does the phrase show up in legitimate business contexts?
Not as a service offering. The words may appear in fraud research, security training material, or law enforcement reporting, where they are quoted to describe a threat. Outside those contexts, treat the phrase as a red flag for criminal activity.