There is no legal place to sell a CVV. The three or four digit card verification value is not a product a person can own or transfer; it is authentication data that proves the physical card is present, and U.S. law treats its sale as access device fraud. Sites and forums that advertise CVV marketplaces are criminal operations, law enforcement honeypots, or scams that collect a deposit from the seller and deliver nothing in return.

Why can't CVV numbers be sold?

A CVV is generated by the card issuer from the card number, the expiration date, and a secret cryptographic key. The value has no standalone use, so it cannot be inventoried, appraised, or resold the way a physical good can.

PCI DSS Requirement 3.2 also prohibits storing sensitive authentication data after a transaction is authorized. No legitimate processor, gateway, or merchant holds a stock of CVVs to offer for sale, which means every listing offered online originated from skimming, phishing, or a breach.

What is the legal penalty for selling CVV data?

In the United States, 18 U.S.C. 1029 covers fraud and related activity in connection with access devices. Trafficking in card credentials carries statutory penalties that include substantial fines and prison terms measured in years, with enhanced terms for repeat or organized conduct.

State prosecutors add charges such as identity theft, larceny, and computer crimes, and federal conspiracy charges can reach everyone in the chain, including the person who supplied the data.

What really happens when you search for a CVV marketplace?

  • Fake escrow: the buyer demands a deposit, a verification fee, or a minimum batch size, then disappears.
  • Monitored forums: carding boards are routinely observed by law enforcement and by security researchers who log seller identities.
  • Malware delivery: vendor tools, checkers, and generators frequently install infostealers on the device of the person running them.
  • No recourse: because the underlying deal is illegal, a seller cannot sue, dispute a payment, or report the theft without exposing the crime.

Legitimate ways to work with card verification data

Merchants, developers, and fraud analysts should never hold CVV data themselves. A PCI DSS validated payment service provider collects the value, authorizes the transaction, and returns a token that can be stored safely in your own systems.

Network tokenization and 3-D Secure authentication further reduce exposure because the merchant never sees the full credential. Consumers can request virtual card numbers from their issuer so that a single compromised value cannot be reused elsewhere.

What should you do if a CVV is exposed or offered for sale?

  1. Contact the card issuer immediately and request a replacement card and a new account number.
  2. Report the incident to the Federal Trade Commission and follow its identity theft recovery steps.
  3. File a complaint with the FBI Internet Crime Complaint Center so the listing can be investigated.
  4. Review statements for unauthorized charges and place a fraud alert or credit freeze if personal data was also exposed.

Frequently asked questions

Can I sell a credit card number that belongs to me?

No. Card credentials are issued under a cardholder agreement that prohibits transferring them to a third party, and selling them facilitates fraud even when the account is your own.

Is buying CVV data illegal too?

Yes. Purchasing or possessing card verification data with intent to defraud falls under the same access device statutes that apply to selling it.

Do any legitimate businesses buy CVV lists?

None. Legitimate fraud prevention firms work with tokenized, aggregated, or hashed data under contract with card networks, and they never purchase raw credentials from individuals.