A CVV dump is a collection of stolen payment card records that includes the card number, expiration date, cardholder name, and the card's CVV or CVC security code. It matters because that three or four digit code is what online checkouts use to confirm the card is physically in the buyer's hands, so a dump gives a thief the one piece of data that makes a remote purchase look routine.

more on this topic

You do not need to be a security professional to protect yourself. Knowing what a CVV dump holds, why the security code is the valuable part, and how to react if your card is exposed covers most of the practical risk.

CVV Dump Format and Track Data: What Merchants Must Know

What a CVV dump usually contains

Entries in a CVV dump are not all identical. What they share is the information a merchant asks for at an online checkout.

cvv dump format track data

  • Primary account number, the long number printed across the card
  • Expiration month and year
  • Cardholder name as it appears on the card
  • The CVV2 or CVC2 code, three digits on the back of most cards and four on the front of American Express
  • Sometimes a billing address or ZIP code used for address verification

Some records also carry a bank identification number, a card brand, or a country of issue, because buyers of stolen data want to know which cards are likely to be accepted.

CVV Dump vs Fullz: Which Fraud Data Set Puts Online Checkout at More Risk?

Why the CVV or CVC code is the valuable part

The card number alone is weak currency. Anyone who has handled your card at a restaurant has seen it. The security code is different: it is printed on the card, not stored on the magnetic stripe, and the payment networks forbid merchants from keeping it after a transaction is authorized. That restriction is exactly why a CVV dump is treated as a premium product in criminal markets. A thief holding the number plus the code can fill out an online order form the same way you would.

How card-not-present fraud is attempted

When a criminal uses stolen card data online, the transaction is called card-not-present fraud. Because no card is swiped or tapped, the merchant relies on the data itself plus whatever fraud screening it has in place. Common patterns include:

  • Small test purchases to see whether a card still works before a larger order
  • Orders shipped to an address that does not match the cardholder's billing address
  • Digital goods, gift cards, or resalable items that arrive instantly and leave no delivery trail
  • Repeated attempts across several merchants in a short window

Issuers and merchants run velocity checks, address verification, and machine learning models to catch these patterns, which is why many dumped cards fail before they are used.

Signs your card data may have been exposed

  • A charge you do not recognize, especially a small one you are tempted to ignore
  • A replacement card arriving that you never requested
  • A data breach notice from a retailer, hotel, or service you use
  • A fraud alert or unexpected hard inquiry on your credit report
  • Declined transactions on a card that should have available credit

How to protect your CVV and card details

  • Never type your security code into an email, chat message, or text, and never read it aloud to someone who called you. No legitimate bank or utility asks for it that way.
  • Use a digital wallet or a virtual card number from your issuer for online shopping. Tokenized payments substitute a one-time or merchant-specific number, so a dump of that data is far less useful.
  • Save card details only with merchants you trust, and delete stored cards from sites you no longer use.
  • Turn on transaction alerts so every charge reaches your phone.
  • Do not keep photos of your card or your security code in a notes app or camera roll.
  • Use a unique password and two-factor authentication on shopping accounts, since an account takeover can expose a saved card.

What to do if your card or CVV is exposed

  1. Call the number on the back of your card and tell the issuer the data was compromised. Ask for the card to be closed and reissued, because a printed security code cannot be changed on its own.
  2. Dispute any unauthorized charges in writing and keep a copy.
  3. Change passwords on shopping and email accounts, then enable two-factor authentication.
  4. Place a fraud alert or freeze your credit files if your name, address, and card data were all taken together.
  5. Report the fraud to the FTC and, for online schemes, to the FBI's Internet Crime Complaint Center.

A CVV dump is only dangerous when the code reaches someone who can use it before the card is shut down. Fast reporting and tokenized checkout options shrink that window to almost nothing.