Short answer
Phrases such as "sell CVV on Telegram group" point to carding, a form of payment fraud. The seller offers stolen card numbers with their expiry dates and CVV security codes. There is no legal market for this data. Buying, selling, or possessing stolen card numbers is a federal crime in the United States under 18 U.S.C. § 1029.
What a CVV is
The CVV is the 3-digit code on the back of Visa, Mastercard, and Discover cards. American Express prints a 4-digit code on the front and calls it the CID. Card networks treat the code as sensitive authentication data. It shows that the person entering the number has the card in hand.
Card-not-present fraud uses card data without the plastic. A stolen number, expiry date, and CVV are enough for an online charge at some merchants.
Why Telegram groups appear in carding
- Usernames and phone-number privacy settings hide identity.
- Public channels are searchable. Private groups need an invite, which sellers hand out in small batches.
- Telegram cloud chats are encrypted between the client and its servers. They are not end-to-end encrypted. Only Secret Chats use end-to-end encryption, and those cover one-to-one chats, not groups. Telegram states this in its own FAQ.
- Accounts are cheap to create and abandon.
The law
18 U.S.C. § 1029 covers access devices. The term includes card numbers, CVVs, PINs, and account passwords. Trafficking in counterfeit or unauthorized access devices is a felony. Sentences reach 15 years for trafficking counts, plus fines. Possession of 15 or more counterfeit devices with intent to defraud is also a charge.
Prosecutors add counts under 18 U.S.C. § 1028 for identity theft and 18 U.S.C. § 1343 for wire fraud. One card number can support more than one count.
What a cardholder sees
Signs of a compromised card:
- A charge for a small amount the holder does not recognize, often a test before a larger charge.
- A decline on a card that should have available credit.
- A fraud alert text or email from the issuer.
- A new card arriving without a request.
Steps to protect a card
- Use virtual card numbers at online checkout when the issuer offers them. Each number ties to one merchant.
- Turn on transaction alerts for every charge above a chosen amount.
- Enable 3-D Secure or the network step-up check at checkout.
- Keep the CVV out of notes apps, email, and chat messages.
- Shop on sites that use a payment processor, not a raw card form.
If a card number is exposed
- Call the issuer. Ask for a block on the number and a reissue.
- Review statements for 12 months. Test charges come first.
- File a report with the FTC. The agency runs the federal identity theft reporting process.
- Report the incident to the FBI Internet Crime Complaint Center.
- Change passwords on shopping accounts and any account that stored the card.
What merchants must do
PCI DSS forbids storage of the CVV after a transaction is authorized. A merchant that keeps CVV data in a database, a log, or a support ticket is out of compliance. Tokenization replaces the card number with a token that has no value outside one system. That step removes the data a carding group wants to sell.
Report, do not buy
An offer to sell CVV data is evidence of a crime. Buyers face the same statute as sellers. The safe action is to report the group to the platform and the incident to the card issuer.