There is no legitimate place to sell CVV dumps. Selling stolen card numbers, magstripe data, or "fullz" is access device fraud under 18 U.S.C. § 1029 in the United States, a federal felony, and most states file their own charges on top of it. Penalties scale with the number of accounts involved and can run 10 to 15 years. Buying the same data is a crime too. So the straight answer to "where do people sell CVV dumps" is: on criminal forums that investigators monitor, and nowhere that ends well for the seller.
The version of this question worth answering is why that market keeps existing and what actually shuts it down. That part is useful to consumers and to small merchants.
Sell CVV Dumps Forum: Risks and Defenses
What "CVV dumps" actually refers to
A dump is payment card data lifted from a card or from a merchant system. Usually that means the track data encoded on a magnetic stripe, which is what a skimmer or a point of sale breach grabs. A CVV is the 3 or 4 digit verification value printed on the card or encoded in the stripe. A "fullz" bundle adds the cardholder's name, address, and sometimes a Social Security number, which is identity theft fuel, not just card fraud.
Card networks and PCI DSS treat the CVV/CVC as sensitive authentication data. Merchants may use it to authorize a transaction, but they are not allowed to store it once authorization is complete. That rule exists precisely because this value is the piece that makes stolen card numbers usable.
Why the marketplaces are a bad bet for anyone involved
- Carding sites are a favorite target for undercover work. Takedowns and seized domains are routine.
- The scene is thick with exit scams. Sellers and buyers rob each other constantly, because nobody involved can call the police.
- Money leaves traces. Crypto is not as anonymous as people assume, and old forum posts resurface in prosecutions years later.
- Possession alone can be charged. You do not have to complete a sale to be in trouble.
Who actually pays for it
Cardholders spend hours on the phone and weeks waiting on replacement cards. Small merchants eat chargebacks, fees, and sometimes lose their processing account entirely, which can end a business. Banks absorb the rest and pass the cost along through fees and interest. None of those people agreed to be part of the transaction.
If you are holding card data that is not yours
Do not try to sell it. Unauthorized possession of access devices is chargeable on its own. If you found a skimmer, received data by mistake, or discovered that your own business was breached, report it: the FBI's Internet Crime Complaint Center takes card fraud complaints, the FTC takes identity theft reports, and your card issuer or acquiring bank has a fraud line. Delete anything you should not have. If you run a merchant operation, your payment processor needs to know within the window your contract requires, because notification duties are time sensitive.
What actually reduces this crime
Controls work better than takedowns. Requiring the CVV/CVC on card-not-present transactions blocks numbers stolen without the physical card. Address verification and 3D Secure add friction for a fraudster and almost none for a real customer. Tokenization replaces the card number with a stand-in value, so a breach yields nothing usable. EMV chips killed the easy clone-a-stripe play at physical terminals. On the consumer side, virtual card numbers, transaction alerts, and a credit freeze all help.
I look at this from the buyer's side of the checkout page, and the pattern holds: fraud that gets through is usually a merchant skipping a control that costs almost nothing to switch on.
The short version
There is no legal marketplace for CVV dumps, no safe one, and no version of selling them that is not a felony. People asking this question fall into two groups. One group wants a shortcut and should stop. The other wants to understand how card fraud works so they can defend against it, and for them the answer is CVV validation, tokenization, and monitoring, not a marketplace.