Short answer
Selling CVV data is a federal crime in the United States. A CVV is part of a card's authentication data. It belongs to the card issuer and the cardholder. There is no legal market for it. In most cases the person asking you to sell CVV numbers is running a scam, or is a law enforcement informant building a case.
Buying Guide: How to Choose the Best CVV Shop for Online Purchases
What a CVV is
Visa, Mastercard, and Discover print a 3-digit code on the back of a card. American Express prints a 4-digit code on the front. The issuer generates the code from the account number plus a secret key. The PCI Security Standards Council classifies these values as Sensitive Authentication Data, or SAD.
What the law says
18 U.S.C. § 1029 covers access device fraud. A card number plus its CVV is an access device under that statute. Trafficking in access devices carries up to 15 years in prison and fines up to $250,000 for an individual. A second charge, 18 U.S.C. § 1028A, adds 2 years of prison that must run consecutive to the first sentence. Federal prosecutors charge these two counts together in carding cases.
Why the CVV market is a trap
Card networks, banks, and the FBI monitor card data channels. Seized marketplace domains and crypto seizure notices appear in DOJ press releases each year. Chain analysis links Bitcoin and USDT payments to wallets. Sellers who post samples to prove inventory hand investigators the evidence. Buyers who pay first often receive random numbers and no refund, because the transaction itself is criminal and cannot be enforced.
Want to Sell CVV Numbers on Reddit? Read This Before You Do Anything
Legal work that touches card data
- Payment processor or merchant acquirer staff
- Fraud analyst and chargeback risk roles at banks and retailers
- PCI DSS compliance auditor or assessor
- Tokenization and encryption engineer for a payments vendor
- Card network employee in authorization or risk
These jobs pay salaries and require background checks. They do not require handling stolen numbers.
If someone asks you to sell CVV data
- Do not send any card data.
- Save the messages, usernames, and payment addresses.
- Report to the FBI Internet Crime Complaint Center and the FTC.
- Tell the card issuer's fraud line if a card you hold is involved.
For merchants
PCI DSS v4.0 Requirement 3.3.1 states that sensitive authentication data is not stored after authorization. Merchants keep the card number and expiry, not the CVV. That rule exists because a stored CVV turns one breach into a card-cloning event. Unknown details: exact penalty ranges vary by charge, prior record, and district.