Selling CVV numbers is a federal crime in the United States, and it is prosecuted as access device fraud and identity theft. A CVV is an authentication secret that proves the person paying is holding the physical card, so anyone who wants to sell CVV data is trading stolen credentials, not a product. The realistic outcomes are criminal charges, civil liability, and permanent loss of access to the payment accounts involved.
What a CVV Actually Is
Card networks use slightly different names for the same idea. Visa calls it CVV2, Mastercard calls it CVC2, and American Express calls it CID. It is the three or four digit code printed on the card, separate from the card number, and it is not stored in the magnetic stripe or the chip.
That design is deliberate. The code exists to confirm that the buyer has the card in hand during a card-not-present transaction, such as an online checkout or a phone order. Payment security standards built around PCI DSS explicitly prohibit merchants from storing the code after an authorization is complete. A value that merchants are forbidden to keep is not a legitimate item to trade.
Why Selling CVV Data Is a Crime
US law treats card credentials as access devices. Under 18 U.S.C. section 1029, trafficking in access devices, including card numbers and verification codes, carries felony penalties that can include prison time and substantial fines. Related charges often stack on top of that:
- Wire fraud, when the scheme crosses state lines or uses electronic communications
- Aggravated identity theft, when the credentials belong to a real person
- Money laundering, when proceeds are moved through bank accounts, crypto, or prepaid cards
- State-level fraud and computer crime charges, which vary by jurisdiction
Being the seller does not reduce exposure. Investigators pursue the people who supply the data as actively as the people who cash it out, and chat logs, wallet addresses, and forum posts are the evidence used in those cases.
How CVV Markets Work and Why They Collapse
Underground markets for card data depend on a steady flow of credentials taken from breaches, skimmers, phishing pages, and malware. The data has a short shelf life. Issuers flag unusual activity, cards get reissued, and the codes a buyer purchased stop working within days. Sellers respond by inflating volume, which drives down prices and increases disputes between criminals who have no recourse when a deal goes wrong.
Those same markets are also heavily monitored. Card networks, banks, and law enforcement share intelligence on the channels used to move stolen credentials, and forum accounts tied to selling activity become evidence rather than assets. Nobody who wants to sell CVV data should assume the anonymity holds.
Legal Ways to Earn From Payment Security
There is real demand for people who understand how card data is attacked and how it is protected. Legitimate paths include:
- Fraud analyst or risk operations roles at banks, processors, and merchants
- PCI DSS compliance and payment security consulting
- Penetration testing and bug bounty programs run by card networks and fintechs
- Security research with coordinated disclosure to the affected vendor
- Chargeback and card-not-present fraud prevention work in e-commerce
These roles pay for the same knowledge without the legal exposure, and they come with contracts, references, and a career that can continue past the next breach cycle.
How to Protect Your Own CVV
- Never read the code aloud in a public place or send it over text, email, or chat
- Do not save it in a note, spreadsheet, or photo gallery
- Use virtual card numbers from your issuer for subscriptions and unfamiliar sites
- Check card readers and terminals for loose parts or overlays before inserting a card
- Review statements line by line, since small test charges often precede larger ones
If Your Card Was Used Without You
Contact your issuer immediately and ask for a freeze or replacement. You are generally not responsible for unauthorized charges, but speed matters. File a report through the FTC's identity theft resources, keep a copy, and report internet-enabled fraud to the FBI's Internet Crime Complaint Center. A police report helps if the issuer or a merchant asks for documentation.
The short answer stays the same: there is no legal path to sell CVV data. The knowledge behind the request, though, has legitimate outlets in payment security work, and those outlets come with paychecks instead of indictments.