There is no legal place to sell CVV numbers online. A CVV is a security credential tied to a real payment card and a real account holder, so offering one for sale means selling stolen financial data. In the United States that is a federal crime, and no legitimate marketplace, payment processor, or bank will knowingly participate in it.
What a CVV Actually Is
The CVV, also called the CVC or card verification value, is the short code used to confirm that whoever is entering a card number physically holds the card or has the issuer's authorization data.
- Visa, Mastercard, Discover: three digits on the back, part of the signature panel.
- American Express: four digits printed on the front, above the card number.
- It is generated by the issuing bank and tied to that single account.
- It is not the card number, not the PIN, and not something an account holder can assign to someone else.
Because the code belongs to the issuer and the cardholder, no individual has the standing to sell it. That is the core reason the question has no lawful answer.
Why Selling CVV Data Is Illegal
Federal law at 18 U.S.C. Section 1029 covers fraud and related activity in connection with access devices. It criminalizes producing, selling, transferring, or possessing card credentials obtained without authorization, and penalties can include substantial fines and prison time. State laws add their own charges, and card network operating rules bar merchants and processors from trading sensitive authentication data under any circumstances.
Buying is not a loophole. A purchase of CVV data is still trafficking in stolen access devices, and the buyer can be charged alongside the seller.
What Legitimate Work With Card Data Looks Like
Businesses that handle card payments do so inside a defined security framework rather than a gray market.
- PCI DSS Requirement 3.2 prohibits storing sensitive authentication data, including the CVV, after a transaction is authorized.
- Legitimate processors use tokenization, so a stored token replaces the card number and no CVV is retained.
- Fraud and risk teams analyze transaction patterns, not individual card codes.
- Chargeback and dispute work happens through the issuer and the card network.
If you want to work with payment data professionally, those are the roles that exist: fraud analyst, payments engineer, risk operations, compliance. None of them involve selling CVVs.
If Someone Asks You to Sell or Share a CVV
Unsolicited offers to buy card codes usually come from fraud rings, and the person being recruited often becomes the one who takes the legal risk.
- Anyone offering to buy a CVV is asking you to handle stolen property.
- Job ads that mention "card testing," "verifying cards," or "payment processing" with no company details are common recruitment tactics for money mule and fraud schemes.
- Never photograph or forward a card, yours or anyone else's, to a stranger.
- Keep the messages and report them to the FBI's Internet Crime Complaint Center.
If Your Own CVV Was Compromised
This is the situation most people actually face. If you suspect your card code was exposed, move quickly.
- Call the number on the back of your card and ask the issuer to block the card and issue a replacement.
- Review recent statements line by line and dispute anything you do not recognize.
- Change passwords on any shopping account where the card was saved.
- If personal data beyond the card was exposed, file a report at IdentityTheft.gov to get a recovery plan.
Where to Report CVV Fraud
- Your card issuer for the fastest freeze and replacement.
- The FTC for consumer complaints and identity theft recovery steps.
- The FBI's IC3 for online fraud, including marketplace and recruitment schemes.
- Your state attorney general if a business in your state mishandled your card data.
The Short Answer, Again
Nowhere. There is no legitimate venue to sell CVV numbers, because a CVV is not a product anyone owns. If you are a cardholder worried about your own code, the useful action is to contact your issuer. If you are a merchant or developer, the useful action is to keep CVV data out of your systems entirely and work within PCI DSS requirements.