You cannot get a CVV for carding from any legal source. A CVV is issued by the bank to the cardholder and appears on the physical card or inside the bank's app. Buying, selling, or using someone else's CVV is card fraud and a federal crime in the United States under 18 U.S.C. § 1029.

more on this topic

Carding means using stolen card details to buy goods or move money. Anyone searching for a CVV supplier is looking for stolen data, whether they frame it that way or not. This guide explains what a CVV is, why no legitimate seller exists, and how to keep your own code out of criminal hands.

read more

What a CVV is and where it comes from

A CVV (card verification value) is a short code the issuer generates and ties to your account. Visa, Mastercard, and Discover print three digits on the back of the card. American Express prints four digits on the front. The code proves the payer has the physical card in hand.

trusted seller for carding cvv

Networks use different labels: CVV2, CVC2, CID, or card security code. The name shifts by network. The purpose does not: it separates a real card from a bare card number copied in a breach.

read more

Only the issuer and the cardholder should know the code. Merchants pass it to the payment processor for a one-time check, then discard it. PCI DSS rules bar merchants from storing the CVV after authorization, which is why a stolen card number often arrives without one.

Why no legal place sells CVVs for carding

Every CVV belongs to a real person and a real bank account. Nobody hands over that code so a stranger can spend their money. There is no storefront, subscription, or broker that sells CVVs with the owner's consent, because no owner consents.

The numbers advertised on Telegram channels, dark web forums, and "CVV shops" are stolen records. They come from data breaches, gas pump skimmers, phishing emails, and malware on infected computers. Sellers repackage that stolen data and charge for it.

  • Breach dumps: card numbers pulled from merchant databases, often without the CVV.
  • Skimming: hardware planted on ATMs, fuel pumps, and card readers.
  • Phishing: fake bank pages that ask for the full card, CVV included.
  • Malware: keyloggers and form grabbers that lift checkout data.

Possessing someone else's card data with intent to defraud is a federal offense under 18 U.S.C. § 1029. Buying a CVV, testing it on a merchant site, or reselling it all fall under the same law. Many "vendors" also run a scam of their own, selling dead numbers or invented records to buyers who have no way to complain.

What are the penalties for carding?

Federal law sets prison terms of up to 10 to 15 years for card fraud offenses, along with fines and restitution to victims. State laws add their own charges, including identity theft and larceny. Sentences stack when a scheme crosses state lines or involves multiple victims.

Convictions also carry practical fallout: a permanent criminal record, loss of banking access, and immigration consequences for non-citizens. Banks cooperate with the FBI and the Secret Service on carding investigations, and payment networks share fraud data across issuers.

How do banks and merchants stop carding attempts?

Card networks built several layers of defense that make a stolen number hard to spend. Each layer adds friction for a fraudster and none for a legitimate buyer.

  • CVV verification: a checkout that requires the code rejects numbers lifted from a breach dump.
  • Address Verification Service (AVS): matches the billing address to bank records.
  • 3-D Secure and one-time passcodes: push a code to the cardholder's phone before the charge clears.
  • Tokenization: replaces the card number with a one-time token so a breach yields nothing reusable.
  • Fraud scoring: flags odd velocity, new devices, and mismatched geography.

These checks explain why carding forums are full of complaints about declined transactions. A stolen number without a matching CVV, address, and device history rarely clears a modern checkout.

How do you protect your own CVV?

Treat the three or four digits like a password. Anyone who has your card number and CVV can spend your money online without the plastic in hand.

  1. Never read your CVV to an inbound caller. Banks do not ask for it, and neither should a utility or a tech support agent.
  2. Skip typing it into unfamiliar sites. Check the domain spelling and the browser padlock first.
  3. Use virtual card numbers from your issuer for subscriptions and one-off purchases.
  4. Store cards in a tokenized wallet like Apple Pay or Google Pay instead of a notes app.
  5. Set transaction alerts and review statements each month for charges you do not recognize.
  6. Cover the keypad at ATMs and tug the card slot before inserting your card.

If your card data leaks, call the issuer and ask for a new number. Report identity theft at IdentityTheft.gov and file a complaint with the FBI's Internet Crime Complaint Center. Speed matters, since carding charges often post within hours of a leak.

Frequently asked questions

Is it illegal to ask for a CVV online?

Asking a cardholder for their own CVV during a purchase is normal commerce. Soliciting stolen card data to buy, sell, or use it is part of a fraud scheme and falls under federal law. Only the cardholder should ever supply that code, and only at a checkout they started.

Can I use my own CVV for online purchases?

Yes. That is what the code is for. You supply it at checkout, the issuer confirms it matches, and the merchant discards it after the authorization.

Why does a site ask for my CVV again?

Some merchants re-verify the code for high-value orders, new shipping addresses, or stored cards. PCI DSS forbids them from keeping the CVV after the first authorization, so they must ask for it each time.

What happens if I buy CVVs from an online seller?

You risk criminal charges, a lost payment with no recourse, and malware hidden in the files you download. The seller keeps your money either way. Report the offer to the Internet Crime Complaint Center instead of engaging.

The bottom line

There is no legitimate market for CVVs, because the code is a security feature that belongs to one cardholder. Searches for a CVV supplier lead to criminal forums, scams, or both. The only lawful use of a CVV is entering your own at a checkout you trust.