Selling CVV dumps is a federal crime in the United States, so there is no legal marketplace, vendor, or forum that can offer them. A CVV dump is a record of payment card data taken from someone who did not authorize its use, and moving that data for profit falls under access device fraud. Card networks, processors, and merchants all treat a stored card verification value as prohibited data. If you are searching for a place to sell card data, the accurate answer is that no lawful venue exists.
Sell CVV Dumps Telegram: What Those Listings Mean and How to Stay Safe
What a CVV dump contains
The term covers a few related records. A full track dump is magnetic stripe data copied from a physical card. A CVV dump is a set of card numbers paired with the three or four digit verification code printed on the card or generated for online use. Both are treated as sensitive authentication data because they let someone charge a card without holding the plastic.
Card verification values exist to prove the person entering a number is holding the card. That single purpose is why the value cannot double as a stored credential.
Why card networks block stored CVV data
PCI DSS Requirement 3.2 prohibits storing sensitive authentication data after authorization. The rule covers the full track, the card verification value, and the PIN block. It exists so that a database breach cannot hand an attacker a working set of card verification codes.
A merchant that keeps CVV values in a log file, a support ticket, or an order record is out of compliance, even if the data never leaves the building.
Legal exposure by role
Federal law treats each side of the transaction as a separate offense.
- Seller: offering card data for sale can be charged as trafficking in access devices, with penalties that scale by the number of records and the dollar value of the fraud.
- Buyer: purchasing the data to make charges adds unauthorized access device use and, in many cases, wire fraud and identity theft charges.
- Marketplace or forum operator: hosting the listings can bring conspiracy and aiding and abetting liability, even without a single completed sale.
What to do if you handle card data
- Stop writing CVV values into any order record, log, or customer profile.
- Replace stored card numbers with network tokens so the raw value never sits in your systems.
- Confirm your PCI DSS scope in writing with your acquirer and your qualified security assessor.
- Train support staff to request verification through the payment processor instead of asking a customer to read a code into a note field.
If your own card data was exposed
- Call the number on the back of the card and tell the issuer the code may be known.
- Ask for a new card number rather than a replacement card on the same account.
- Read every statement line for small test charges that often precede larger ones.
- Place a fraud alert or freeze your credit file with each of the three bureaus.
- File a report with the FTC and with the FBI's Internet Crime Complaint Center.
Card verification data is a security control, not a product. Keep it out of storage and it stops being worth anyone's effort to sell.