There is no legal place to sell CVV dumps in 2024. Selling, buying, or trading stolen card numbers, CVV/CVC codes, or bulk cardholder data is a federal crime in the United States under 18 U.S.C. § 1029, which covers trafficking in and unauthorized use of access devices. Every forum, marketplace, or self-described vendor that advertises dumps is a scam that takes payment and disappears, a law enforcement operation, or a front for further extortion. If your real goal is keeping card codes safe during legitimate online purchases, this guide explains how the CVV/CVC works, what a healthy checkout looks like, and what to do when card data is exposed.
What the phrase “CVV dumps” refers to
“Dumps” is criminal slang for batches of cardholder data copied from a payment terminal, a merchant database, or a phishing page, then offered as magnetic stripe tracks, card numbers with expiration dates, or numbers paired with CVV codes. That market exists only because card data was stolen. There is no consumer or business use case for buying it, and no bank, payment processor, or merchant platform lists it for sale. The phrase describes fraud, not commerce.
where can i sell cvv dumps 2024
How the CVV/CVC protects your online purchases
The card verification value is a short code printed on the card but not encoded in the magnetic stripe, which is why copying a card at a terminal does not expose it. It is also barred from storage after a transaction authorizes under PCI DSS. That combination is what makes card-not-present fraud harder: a thief with a stolen card number still lacks the code, and a legitimate merchant cannot retrieve it later.
Is Selling CVV Dumps Legal in 2024? The Law Explained
What to check at checkout
Legitimate payment flows follow predictable parameters. When those parameters change, stop and reassess.
CVV Dumps 2024 Market: What It Is and How to Stay Safe
- Card number field: 15 or 16 digits for the major consumer brands, within the 13 to 19 digit range allowed by the ISO/IEC 7812 standard.
- CVV field: exactly 3 digits for Visa, Mastercard, and Discover; exactly 4 digits for the American Express CID on the card front.
- Input handling: numeric-only entry with a fixed length cap, and the field cleared after submission.
- Transport: HTTPS with a valid certificate and the browser lock indicator on the payment step.
- Placement: the form is rendered by the processor or inside an iframe from the processor domain, not pasted into a general contact page.
- Step-up verification: a 3-D Secure prompt or one-time passcode for higher-risk orders.
- Post-order conduct: no follow-up email, chat message, or phone call asking you to resend the code.
Red flags and pitfalls
- Anyone offering to buy or sell “dumps,” “fullz,” or CVV listings. The activity is illegal and the counterparty is usually a fraudster targeting you.
- Requests to send a card number or verification code by email, text, or social media instead of a checkout form.
- Screen-sharing or remote-access tools suggested during checkout.
- A cart that asks for your online banking username and password.
- Pressure to pay with gift cards, wire transfer, or cryptocurrency where a card code would normally apply.
- Checkout pages served over plain HTTP, or pages that reload and blank the CVV field on every attempt.
If your card data was exposed
Contact your card issuer first and ask for the card to be frozen or replaced. Review statements and set transaction alerts. Then file reports so the pattern is documented: the FTC runs a recovery process at IdentityTheft.gov, and the FBI Internet Crime Complaint Center accepts internet-facilitated financial crime complaints. Merchants that leak card codes should also be reported to their acquiring bank and to the card networks, since retaining the CVV after authorization violates PCI DSS.
FAQ
Is there any legitimate marketplace for selling card data?
No. Card data belongs to the cardholder and the issuing bank. Transferring it for fraudulent use is a crime under 18 U.S.C. § 1029, which carries fines and imprisonment.
How many digits should a CVV field accept?
Three for most brands and four for American Express. A form that asks for five or six digits, or for the code along with a PIN, is not a standard card-not-present checkout.
Does a merchant ever need my CVV again after the order?
No. The code is used at authorization and must not be stored. Any follow-up request for it is a fraud attempt or a serious compliance failure.
Someone offered to buy my own card details. Is that legal?
No. Selling your own card data for someone else to use is still trafficking in an access device, and these offers are commonly used to collect photos of the card and ID for later abuse.