Selling CVV data to a shop is not a business. It is carding, and in the United States it is a federal crime. A CVV or CVC is the three- or four-digit code printed on a payment card and encoded on the chip or stripe. Its entire purpose is to prove that whoever typed the number is holding the card. Anyone offering to buy those codes is running an advance-fee scam against the seller, harvesting identities, or working with law enforcement. This guide covers what the phrase means, where the offers actually lead, the exposure involved, and the controls that genuinely reduce card-not-present fraud.
Sell CVV Shop Review: Prices, Claims, and Legal Risk
What the phrase describes
"Sell CVV to shop" copies the language of underground carding forums, where stolen card records are packaged and resold. The shop is a storefront on a hidden or invite-only site, not a retailer. Real merchants never buy verification values. They receive one code, once, from the cardholder at checkout.
A card record in that market usually bundles a primary account number, expiration date, cardholder name, and the CVV. Sellers advertise bulk lots and freshly obtained data. Buyers use the numbers to place fraudulent orders for goods they can resell. Both sides commit access device fraud.
CVV Shops and Dump Sales: What They Are and How to Stay Safe
Why the offers fail
- Advance-fee scams: the operator demands a deposit, a verification payment, or a crypto transfer before releasing anything, then disappears.
- Data harvesting: the site collects the seller's identity documents, bank details, or wallet address and monetizes those instead.
- Sting operations: US and international agencies have run and seized carding storefronts, then used the captured account and transaction data in prosecutions.
- Dead data: issuers reissue numbers fast after fraud is detected, so purchased records often stop working within hours.
Legal exposure in the US
Trafficking in card data falls under 18 U.S.C. Section 1029, which covers fraudulent access devices and the equipment used to produce them. Related charges include wire fraud under Section 1343, identity theft under Section 1028, and conspiracy. Penalties climb with the number of accounts involved, and prosecutors routinely add aggravated identity theft counts that carry mandatory consecutive terms. A single interstate transaction is enough to establish federal jurisdiction.
Merchant controls that reduce CVV theft
If you run an online store, the goal is to shrink the value of a stolen CVV before it reaches your checkout page.
Require CVV plus address verification
- Pros: cheap to enable, no added friction for most buyers, and it filters bulk-stolen data that lacks the code.
- Cons: it does not stop a fraudster holding the full card record, and it can block legitimate buyers who mistype a billing address.
Add 3-D Secure or an equivalent step-up challenge
- Pros: shifts liability for qualifying transactions to the issuer, blocks automated card testing, and confirms the cardholder in real time.
- Cons: adds a redirect step that some buyers abandon, requires integration work, and can produce false declines.
Never store the CVV
PCI DSS forbids retaining sensitive authentication data, including the CVV, after a transaction is authorized. Keeping it in a database or an application log turns one breach into a full card dump and puts the merchant in scope for the harshest penalties.
What cardholders should do
- Never share a CVV over chat, email, or a phone call you did not initiate. No legitimate caller needs it.
- Use virtual or single-merchant card numbers where your issuer offers them, so a leaked code cannot be reused elsewhere.
- Review statements weekly. Small test charges often precede a large fraudulent purchase.
- Dispute unauthorized charges promptly. Under the Fair Credit Billing Act, cardholders can challenge billing errors and generally face limited liability.
- Report card fraud to the FTC and the FBI's Internet Crime Complaint Center so patterns get tracked.
Recommendations by use case
Online merchant on a tight budget: enable CVV and AVS first, then add step-up authentication on high-risk orders only, such as first-time buyers requesting expedited shipping.
Growing merchant under chargeback pressure: adopt a step-up challenge across the board, tokenize stored payment methods, and keep sensitive authentication data out of every system you control.
Shopper worried about card safety: use virtual card numbers at unfamiliar merchants and treat any request for your CVV outside a checkout page as fraud.
Someone who found a CVV-buying offer: there is no legitimate version of that transaction. Delete the contact, send no funds, and report the account to the platform hosting it.