Short answer

There is no legal place to sell CVV data. A card verification value is a security code bound to one card and one account, not a product that anyone can own or resell. Criminal marketplaces for stolen card numbers do operate on the dark web, but every listing, purchase, and payout on them is a federal crime, and the people running those sites routinely steal from their own users. If you came here looking for a seller, no legitimate version of that search exists. If you came here to keep your own cards out of those markets, the sections below cover what actually works.

What a CVV is and why it gets targeted

The three or four digit code printed on a card exists to prove the physical card is in hand. Online checkout asks for it precisely because the card number alone is not enough. That makes the code valuable to a thief and worthless to a legitimate buyer. A stolen number without the code often fails at checkout, which is why carding listings advertise the code alongside the number, expiration date, and cardholder name.

How stolen card data reaches a market

Card data does not appear on its own. It arrives through payment skimmers placed on fuel pumps and ATMs, malicious scripts injected into checkout pages, phishing pages that clone a login or checkout form, and data breaches at merchants that stored card details when they should not have. After collection, the records are bundled and offered in bulk. Markets compete on volume, not on trust, and buyers frequently receive dead numbers, already-blocked cards, or fabricated records.

Legal reality

Buying, selling, transferring, or possessing stolen card credentials violates federal law in the United States, including statutes covering access device fraud and identity theft. Penalties include prison time, fines, restitution, and a permanent record. Payment networks also flag the accounts and devices involved, so proceeds are difficult to keep. Investigators monitor these marketplaces, and takedown operations have shut down major sites and prosecuted both operators and high-volume users.

Steps to protect your cards

  1. Turn on transaction alerts in your bank or card app so every charge reaches you by text or email.
  2. Enable multi-factor authentication on every shopping account and email address tied to your cards.
  3. Use a digital wallet or tokenized card number at checkout instead of typing the physical card number.
  4. Freeze your credit at all three bureaus if you are not applying for new credit.
  5. Check your statements line by line each month, and search for small test charges that often precede larger fraud.
  6. Shop only on sites with a valid HTTPS connection, and avoid entering card details on pages reached through a text or ad.
  7. Cover the keypad at ATMs and gas pumps, and wiggle card readers to check for attached skimmers.

If your card data was exposed

  1. Call the number on the back of your card and report the unauthorized activity.
  2. Request a new card number rather than a replacement card with the same number.
  3. Change the password on any shopping account where the card was saved.
  4. Review your credit reports for accounts you did not open.
  5. File a report with the Federal Trade Commission and, if money was lost, with your local police.

Where to report

  • The Federal Trade Commission handles identity theft reports and recovery plans.
  • The FBI Internet Crime Complaint Center accepts reports of card fraud and carding activity.
  • The Cybersecurity and Infrastructure Security Agency publishes account and authentication guidance.