Short answer
No. A site that sells CVV codes is not a legal business. In the United States, selling, buying, or moving card account data falls under 18 U.S.C. 1029. That statute covers trafficking in access devices and carries fines plus prison terms that reach 10 years or more. Search results for this phrase lead to three things: scam shops that take payment and send nothing, phishing pages that harvest the buyer's own card and identity data, or law enforcement operations. None of them sell valid card data at a discount.
What a CVV is
A CVV is the short code printed on a payment card. Visa, Mastercard, and Discover use three digits on the back. American Express uses four digits on the front and calls it a CID. The code proves the person entering card numbers holds the physical card. It is not stored in the magnetic stripe and not stored in the EMV chip. That design is the point: a skimmer that copies the stripe still lacks the code.
Card networks also call this value CVV2, CVC2, or CAV2 when it is used in a card-not-present transaction. The number changes when the card is reissued.
Why card data sales are illegal
Payment card numbers are access devices under federal law. Buying them in bulk, selling them, or holding them with intent to defraud is a felony. Sentences rise when the offense involves 15 or more devices, when losses pass $1,000 in a 12-month period, or when the conduct crosses state lines. State laws add charges for identity theft and computer crimes.
Payment industry rules add a second layer. PCI DSS Requirement 3.2 bars merchants and processors from storing the CVV after a transaction is authorized. A business that keeps those codes is out of compliance. That failure is a common finding in breach investigations.
What the offers are
Public claims about fresh or valid card dumps do not describe a real product. The common patterns:
- Advance-fee scams. The buyer pays in cryptocurrency and receives nothing, or receives a file of test numbers that fail.
- Phishing. The signup form collects the buyer's email, phone, and payment details, then reuses them.
- Stings. Federal agents run storefronts and forums to build cases against buyers and sellers.
- Malware drops. Downloaded checker tools install credential stealers on the buyer's device.
The legal exposure is the same in each case. A purchase attempt creates records of intent.
How card codes get stolen
Most breaches start with the merchant, not the cardholder. Causes include skimming devices on fuel pumps and ATMs, card-not-present fraud using data leaked from a retailer, phishing emails that copy a bank login page, and malware on a point-of-sale terminal. Card testing follows: a fraudster runs small charges to see which numbers work.
How to protect your card
- Use a virtual card number for online purchases when your issuer offers one. The number ties to one merchant or one spending limit.
- Turn on transaction alerts in the bank app. Set the threshold at $1.
- Keep the CVV out of saved fields. Re-enter it for each purchase.
- Shop on sites with a full checkout page and a working phone number. Skip sites that ask for the CVV over email or chat.
- Check your statements each week. Card testing charges start small.
- Freeze your credit at all three bureaus. It blocks new accounts opened with your data.
If your card is used
Report the charge to the issuer. Under the Fair Credit Billing Act, your liability for unauthorized credit card charges caps at $50, and most issuers waive it. Debit card rules differ: report within two business days to keep the cap at $50. File a report at IdentityTheft.gov if your Social Security number or other identifiers were exposed. Send a complaint to the FBI Internet Crime Complaint Center if you lost money to a fraud site.
Related terms
People search for buy cvv, cvv shop, and carding forum with the same intent. The answer does not change. No licensed payment processor, bank, or card network sells card codes to the public.