What does a "sell CVV website" actually offer?
A "sell CVV website" is a storefront that trades stolen credit card numbers and their verification codes. Buying from one, selling through one, or running one breaks federal access device fraud law, 18 U.S.C. § 1029. Most sites that market card verification values as a product either defraud the buyer or feed evidence to investigators.
The search term pulls up two kinds of pages: cloned storefronts that vanish after a few weeks, and honeypots that record IP addresses and payment trails. Neither leads to a working, lawful purchase.
What is a CVV or CVC code?
The CVV is the 3-digit code printed on the back of most Visa, Mastercard, and Discover cards. American Express uses a 4-digit code on the front, called the CID. Banks created it to prove that the person typing the number holds the physical card.
Card data splits into two groups. The account number (PAN), name, and expiration date sit on the magnetic stripe and get shared with merchants. The CVV does not. Under payment card rules, merchants may not store the CVV after a transaction authorizes.
Is selling CVV data legal in the US?
No. Trafficking in stolen card numbers is a felony. Federal prosecutors charge it under 18 U.S.C. § 1029, and add wire fraud (18 U.S.C. § 1343) and aggravated identity theft (18 U.S.C. § 1028A) when the facts support it.
A first conviction under § 1029 can bring a prison term of up to 10 years and a fine. State laws add their own charges for identity theft and fraudulent use of a credit card. The person who buys the data carries the same exposure as the person who sells it.
Why do these sites show up in search results?
Search rankings come from page structure, not from legitimacy. Operators build thin pages around carding slang, swap domains after takedowns, and run mirror sites to stay visible.
Some of those pages belong to law enforcement. Undercover operations have run carding forums and marketplaces for months before indictment. Visiting such a page leaves a record.
What happens to buyers on these sites?
- Cards arrive canceled. Issuers flag and close accounts fast once fraud shows on a batch.
- The same numbers get resold to many buyers, so an "exclusive" list dies within hours.
- Payment goes through crypto with no refund path, and the seller blocks the buyer.
- Some buyers face extortion. Sellers keep chat logs and threaten to report the buyer to police.
There is no consumer protection, no dispute process, and no way to verify that a seller holds real data before paying.
How does card data end up for sale in the first place?
- Skimmers attached to gas pumps, ATMs, and point-of-sale terminals
- E-skimming scripts injected into checkout pages, often called Magecart attacks
- Phishing pages that copy a bank or store login screen
- Breaches at merchants or processors running unpatched software
- Malware on a home computer that captures keystrokes and form data
Each path targets the same prize: the account number plus the CVV, which together pass a card-not-present check. That is why protecting the code matters as much as protecting the number.
How do you protect your CVV and CVC?
- Never read the code over the phone to a caller who contacted you first. Banks do not ask for it on inbound calls.
- Use a digital wallet when you can. Network tokens replace your card number with a token tied to one merchant or device.
- Lock the card in your bank app between purchases. Most major issuers offer a freeze toggle.
- Turn on transaction alerts for every charge above an amount you choose.
- Check the checkout page for a padlock and a real domain, then close the tab if anything looks off.
- Shop with virtual card numbers when your issuer offers them.
How do merchants keep CVV data out of reach?
PCI DSS Requirement 3.2 classifies the CVV, full track data, and PIN blocks as sensitive authentication data. Merchants may not store any of it after authorization, and auditors test for it during assessments.
Tokenization swaps the card number for a placeholder value, so a breach at the merchant yields tokens rather than usable cards. 3-D Secure adds an issuer check at checkout and shifts fraud liability to the issuing bank in many cases.
What should you do if your card data leaks?
- Call the issuer and ask for a new card number, not just a new card.
- Dispute every charge you do not recognize, in writing.
- File a report at IdentityTheft.gov to get a recovery plan.
- Send a complaint to the FBI's IC3 if the fraud came from an online seller or marketplace.
- Freeze your credit at Equifax, Experian, and TransUnion.
FAQ
Can you sell CVV numbers without breaking the law?
No. The only lawful transfer of card data happens between a cardholder and the issuer, or between banks under contract. A third party who trades card numbers or verification codes has no legal claim to the data.
Are all CVV-selling sites scams?
Not all. A small number do trade real stolen data, which makes them criminal operations rather than scams. The buyer commits a crime in both cases.
Does a CVV stop online fraud?
It raises the cost of fraud. A stolen card number alone fails most checkout checks, so criminals need the code or a full set of card data. Breaches still expose both, which is why tokenization and 3-D Secure cut losses more than the code does.
Where do you report a site that sells card data?
Report it to the FBI's IC3, the FTC, and the card network's fraud line. Include the domain, the date, and any messages you received. Do not send payment or card details as part of the report.