Short answer: there is no lawful place to sell CVV fullz. Fullz are bundles of stolen payment card data, and offering them for sale in the United States is trafficking in access devices under 18 U.S.C. 1029, a felony that can stack with identity theft charges under 18 U.S.C. 1028. This guide covers what fullz contain, why the illegal market is smaller and less profitable than listings suggest, and three legitimate paths that pay for the same card-security skills. The paths are ranked on three criteria: legal standing, transferable skills, and entry requirements for someone with no security clearance or industry contacts.
What fullz actually contain
The word comes from "full information." A fullz bundle typically pairs a card number and expiration date with the cardholder name, billing address, phone number, and sometimes a Social Security number or date of birth. The card verification value printed on the card is the piece most online merchants require at checkout, which is why fullz listings treat CVV and CVC codes as the headline item. None of that data belongs to the person offering it. Each listing is a stranger's identity packaged for resale, and the victim is the cardholder whose account gets drained and whose personal details get recycled for years.
Why the illegal market is riskier than the listings suggest
Card networks and issuers have spent two decades making stolen numbers hard to cash out. Tokenization replaces the card number with a surrogate that works for one merchant or one device. Fraud models score transactions in real time. Chargeback liability pushes merchants to require the CVV and to run address verification. The practical result is that a large share of fullz offered online are dead on arrival: cards canceled, balances drained, or numbers generated to look valid. Buyers get defrauded by sellers. Sellers get traced through chat logs, crypto trails, and shipping addresses. Both sides carry exposure, and the buyer has no recourse when the data fails.
If you found stolen card data
- Do not copy, forward, or store it. Every extra copy adds exposure for you and for the victim.
- Report it to the card issuer or the merchant's fraud team if you can identify either one.
- File a complaint with the FBI Internet Crime Complaint Center, which handles cyber-enabled financial crime.
- If it surfaced at your workplace, escalate to your incident response lead and your acquiring bank under your PCI DSS incident response plan. Do not investigate on your own.
Legitimate work that uses the same knowledge
Fraud analytics
- Pros: High demand at issuers, processors, and ecommerce companies. You work with transaction data, rules engines, and chargeback patterns, which is the same material carding forums talk about from the other side. Clear promotion path into risk strategy.
- Cons: Shift work is common in fraud operations. Entry roles may start in a review queue before you touch modeling. Background checks are strict, which is a feature rather than a bug.
Best for: someone who likes pattern hunting and wants a fast on-ramp without a graduate degree.
PCI compliance and payment security assessment
- Pros: You learn the control framework from the inside, including the rule that card verification values must never be stored after authorization. Consulting and internal audit roles pay well and travel is optional at many firms.
- Cons: Certifications cost money and take months. The work is documentation heavy. Deadlines cluster around assessment cycles.
Best for: detail-oriented people who prefer policy and evidence over live incidents.
Coordinated vulnerability research
- Pros: Merchants and payment platforms run disclosure programs that pay for findings. You test your own systems or systems you have written permission to test. Published research builds a public reputation.
- Cons: Payouts vary and are unpredictable. Scopes are narrow, and testing outside them is a crime, not a hobby. Requires real skill in web and API security.
Best for: self-taught technical people who already write code and want to stay on the defensive side.
What merchants should already have in place
- Never store the CVV, CVC, or CID after authorization. PCI DSS treats it as sensitive authentication data that must not be retained.
- Tokenize card numbers so a breach does not hand over usable credentials.
- Require both address verification and the card verification value at checkout, then watch velocity and device signals.
- Train support staff to spot social engineering calls that ask them to read a code aloud or bypass verification.
What cardholders can do
- Use virtual card numbers from your issuer for online subscriptions and unfamiliar merchants.
- Turn on transaction alerts so a test charge shows up as a message, not a surprise.
- Never read your CVV to someone who called you. Call the number on the back of your card instead.
- Review statements on a fixed day each month and dispute anything you do not recognize.
Bottom line
If the question was where to sell CVV fullz, the honest answer is nowhere that keeps you out of federal court, and the buyers on those markets are as likely to rob you as pay you. The knowledge around card data, fraud detection, and payment security is in steady demand on the defensive side. Those jobs come with a salary, references, and no handcuffs.