There is no legal place to sell CVV data. A card verification value is an authentication credential, not a product, and trafficking in it is a federal crime in the United States under 18 U.S.C. § 1029, which covers fraud and related activity in connection with access devices. Every marketplace that trades this kind of data operates outside the law, outside payment network rules, and outside any consumer protection.
People searching for where to sell CVV usually fall into one of three groups: someone who stumbled onto card data and wonders what it is worth, a researcher mapping the fraud economy, or a merchant or fraud analyst trying to understand how card data moves. The sections below answer the legal question first, then explain the technical and practical facts behind it.
What a CVV Actually Is
The CVV, CVC, or CVV2 is the short code printed on a payment card. It exists to prove that whoever is typing the number physically holds the card, which is why online checkout forms ask for it. Card networks designed that code as an anti-fraud control, and PCI DSS rules bar merchants from storing it after a transaction is authorized. That design detail is the reason a stolen CVV is valuable to a criminal and worthless as a legitimate asset: it cannot be stored, audited, insured, or resold through any regulated channel.
Why Selling CVV Data Is a Crime
Selling card credentials is not a gray area or a licensing problem. It is prosecuted as a felony.
- Access device fraud. Producing, selling, transferring, or possessing card account credentials with intent to defraud falls under 18 U.S.C. § 1029.
- Related charges. Cases often add wire fraud, bank fraud, aggravated identity theft, and money laundering counts.
- State law. Every U.S. state has its own identity theft and unlawful-use statutes that apply alongside federal charges.
- Penalties. Convictions carry prison time, fines, restitution, and a permanent record that closes off most financial and security jobs.
The person doing the selling is usually the easiest link in the chain to identify, because the transfer leaves payment trails, chat logs, and crypto wallet records that investigators can subpoena.
What Happens on Card-Data Markets
Criminal forums and dark web shops do exist, and law enforcement monitors them. That environment has predictable features, and none of them favor the seller.
- Exit scams. Buyers and operators routinely disappear with funds, and there is no recourse because the transaction itself is illegal.
- Test transactions. Buyers validate stolen numbers by making small purchases, which triggers fraud alerts at the issuing bank.
- Infiltration. Federal agents and private fraud investigators operate inside these spaces and build cases from the inside.
- No escrow. There is no dispute resolution, no insurance, and no way to enforce a deal without exposing yourself further.
Anyone weighing this path should assume the data is being tracked and that the counterparty is either a scammer or an investigator. Both outcomes end badly for the seller.
Legitimate Work That Involves Card Data
There are lawful, paid careers built around card security. They all require authorization and a paper trail.
- Penetration testing. Contracted engagements where a client gives written permission to test their payment systems.
- Bug bounty programs. Published scopes from vendors and payment processors that pay for responsibly reported flaws.
- Fraud analytics. In-house roles at banks, issuers, and processors modeling transaction risk.
- PCI assessment. Qualified security assessors who audit how merchants handle cardholder data.
- Security research. Academic and industry study of tokenization, EMV cryptograms, and 3D Secure flows using synthetic or sandbox data.
If you have genuine card data from a breach or a found card, the channel is a report to the issuer or the card brand, not a sale.
If Your Own CVV Was Exposed
Act on it the same day.
- Call the number on the back of your card and ask the issuer to freeze the account and reissue the card.
- Review recent statements for small test charges, which often precede larger theft.
- Change passwords on shopping accounts and turn on two-factor authentication.
- Report identity theft at IdentityTheft.gov, the Federal Trade Commission's official reporting portal.
- File a complaint with the FBI's Internet Crime Complaint Center if money was taken online.
How Merchants Keep CVV Data Out of Reach
For businesses, the practical answer to card-data risk is to never hold the data in the first place. Require the CVV at checkout, pass it straight to the processor, and store only a token. PCI DSS forbids retaining the verification code after authorization, and tokenization plus 3D Secure authentication removes most of the value a thief could extract from a breach. Merchants that follow those rules have nothing to sell and nothing to lose.