Stolen CVV data is sold on dark web carding forums, automated shop sites, and private chat groups where criminals trade payment card numbers in bulk. Selling that data is a crime in the United States and most other countries, and federal prosecutors charge it as access device fraud. This guide explains what a CVV is, why the data gets traded, and how consumers and merchants can block the damage.
Where does CVV data get sold?
No legitimate marketplace sells CVV data. The trade runs through hidden forums that require an invite, shop pages that feed card numbers through a bot, and direct chat deals between two parties. Card numbers move in batches, and sellers test them with small purchases before offering them to buyers.
- Carding forums: invitation-only message boards where sellers post batches and buyers leave feedback scores.
- Automated shops: listings that sort card data by bank, country, card brand, and cardholder details.
- Encrypted chat: one-to-one trades with no escrow and no buyer protection.
- Broadcast channels: large groups that resell data scraped from previous breaches.
Naming specific markets has little value here. Sites get seized or shut down on a regular basis, and the operators behind them face indictment. What matters for a cardholder or a merchant is how the data reaches the market and how to stop it.
What is a CVV or CVC?
A CVV is the three- or four-digit code printed on a payment card. It exists to prove the person paying has the physical card in hand. Card networks use different labels for the same check value, including CVC, CVV2, and CID.
Is the CVV the same as the card number?
No. The card number identifies the account, while the CVV is a check value derived from the number, the expiry date, and a secret key held by the issuer. Online merchants ask for the code because a card number alone can be copied from a receipt, a photo, or a leaked database.
Do merchants store CVVs?
The PCI DSS standard forbids storing the CVV, the full magnetic stripe, or the PIN block after a transaction is authorized. That rule is why most breaches leak card numbers and expiry dates but not the verification code. When a CVV does leak, it comes from a skimmer, a phishing page, or a merchant that ignored the standard.
Why does stolen CVV data have a price?
A card number plus CVV can complete a card-not-present purchase, which is the easiest kind of fraud to run from a distance. Buyers look for cards from banks that do not challenge online transactions, and they pay more when the data includes the cardholder name, address, and ZIP code. Prices rise with how fresh the data is and whether the card has been used before.
Do people who sell CVV data get caught?
Yes, and the arrest tends to start on the buyer side. Law enforcement runs undercover accounts, seizes server hardware, and traces cryptocurrency payments on public blockchains. Large forums have collapsed after administrators were indicted, and agency cooperation means a seller in one country can be charged in another.
What are the legal consequences?
- In the US, 18 U.S.C. § 1029 covers trafficking in access devices, with prison terms of up to 10 years for a basic first offense plus fines.
- Cases that involve many cards or high dollar losses carry longer maximum sentences.
- State laws add charges for identity theft and larceny, and victims can sue for damages.
- Other countries apply similar statutes, so moving an operation offshore does not remove the risk.
How do you protect your own cards?
- Use virtual card numbers from your bank or a payment app for online purchases. Each number is tied to one merchant.
- Turn on transaction alerts so a charge you did not make shows up in seconds.
- Shield the keypad when entering a PIN, and check card readers and ATMs for loose parts before use.
- Buy only on sites with HTTPS and a checkout that requests the CVV. That request signals a normal risk check.
- Review statements each month and dispute unknown charges fast.
How do merchants cut CVV fraud?
- Never store CVV, magnetic stripe, or PIN data after authorization. PCI DSS does not allow it.
- Add 3-D Secure or a similar step-up check for high-risk orders.
- Verify the billing address and CVV on every card-not-present order, and flag mismatches for review.
- Watch for patterns: many orders from one IP, several cards shipped to one address, rush shipping requests.
- Tokenize card data at the processor so your own systems never hold the number.
What should you do if your card data is stolen?
Call the issuer and ask for a block and a replacement card. Report the fraud through IdentityTheft.gov if it is part of a wider identity theft case. Keep a record of the calls and reference numbers, because you may need them if the issuer pushes back on the dispute.
Frequently asked questions
Can you buy or sell CVV data legally anywhere?
No. No jurisdiction permits trafficking in stolen payment card data. Some sites claim to sell valid cards for testing or research, but using real cardholder data without consent is not legal, and those offers are scams aimed at the buyer.
Is looking at dark web markets illegal?
Visiting a hidden site is not a crime by itself in the US, but buying, selling, or possessing stolen card data is. Security researchers work with law enforcement or a legal team before touching this material.
Why do some card numbers sell without a CVV?
Those listings contain the card number and expiry date only, and they are worth less because many online checkouts ask for the code. Attackers use them for cloned-card fraud at terminals or for subscription sites that skip the CVV check.
The short version: the dark web market for CVV data exists, it is illegal on both sides of the trade, and the defenses against it are well known. Virtual cards, transaction alerts, and strict CVV handling at checkout remove most of the opportunity.