Selling CVV at low prices is not a legitimate market. Any listing, forum thread, chat bot, or social post that advertises card verification values for a few dollars is trading stolen payment data, and buying, selling, or using that data is a federal crime in the United States. The low price is the lure, not a bargain.
What a CVV Actually Is
A CVV, also called CVC or CVV2, is the three or four digit code printed on a payment card. It exists to prove the physical card is present during a card-not-present transaction, such as an online order or a phone purchase. The code is generated by the issuer and is not printed on receipts. Under the PCI Data Security Standard, merchants and processors are not permitted to store it after a transaction is authorized. That single rule explains why any marketplace claiming to offer CVVs in bulk is holding data it should never have had.
Why Low Prices Are a Warning Sign
- Legitimate card data is never resold. There is no wholesale channel, no discount tier, and no verified vendor.
- Cheap listings usually mean bulk dumps of stale, canceled, or randomly generated numbers.
- Many sellers take payment and vanish, so the buyer ends up the victim of the same fraud pattern.
- Some operations use the transaction to harvest a buyer's identity, contact details, or wallet address for extortion.
A five dollar CVV is either useless data, a scam aimed at the person paying, or evidence of a crime. None of those outcomes is a purchase worth making.
The Legal Reality in the US
Federal law treats payment card data as an access device. Trafficking in it, possessing it with intent to defraud, and using it to obtain goods or money are separate offenses, each carrying prison time and fines. Buying is not treated as a lesser act than selling. A person who searches for cheap card data and follows through can face the same kind of charge as the person who posted the listing.
How Card Data Reaches These Listings
- E-skimming scripts injected into checkout pages to capture card details as shoppers type them.
- Phishing pages that clone a familiar payment form and forward the entries to an attacker.
- Breaches at merchants that stored sensitive authentication data they were not supposed to keep.
- Physical skimmers and camera overlays at fuel pumps, ATMs, and unattended kiosks.
Practical CVV Security for Online Shoppers
- Never send a CVV by email, text, or chat, and never store it in a notes app or password field labeled as something else.
- Confirm you are on the merchant's real domain before typing card details, and check that the checkout page is served over HTTPS.
- Prefer tokenized wallets, virtual card numbers, or a single-use card for unfamiliar sites.
- Turn on transaction alerts and review statements for small test charges, which often precede larger ones.
- Treat urgency, unusual payment methods, and requests to move a conversation off a platform as red flags.
For Merchants and Site Owners
Do not store the CVV, and keep it out of logs, support tickets, and order notes. Use hosted payment fields or tokenization so the code never touches your servers, keep checkout scripts under a content security policy, and patch the storefront platform promptly. Card verification codes are a verification control, not a data asset to collect.
If You See These Offers
Do not engage, and do not test a card number to see whether it works. Report the listing to the platform hosting it and file a complaint with the FBI's Internet Crime Complaint Center or the FTC. If your own card is exposed, contact the issuer right away, freeze the account, and dispute any charge you did not make.