The short answer
There is no legitimate seller of CVV2 codes. The CVV2 is the three-digit value printed on the back of most cards, four digits on the front for American Express. Its only job is to prove that the person typing card details has the physical card in front of them. A code sold in bulk by a stranger cannot prove that. It is a stolen credential, and buying one is a crime in essentially every country where cards are issued.
So if you arrived here looking for a price list, a vendor, or a marketplace, that is the end of the road. What I can do is explain the term properly, because it shows up constantly in card-not-present work, and small gift and greeting-card shops run into it every day.
Why the code exists at all
When you swipe or tap a card in person, the terminal reads the chip or magstripe. The card is physically present, so fraud is harder. Online, by phone, or by mail order, there is no card to inspect. The CVV2 fills that gap. It is not stored on the magnetic stripe, and it is not printed on receipts. That is deliberate: if it leaked everywhere, it would be worthless as a check.
Card networks treat it as sensitive authentication data. Under PCI DSS, a merchant must not retain the CVV2 after a transaction is authorised, even in an encrypted database. I have seen small shops try to keep it in an order note so staff can re-charge a custom order later. That single habit turns a minor compliance gap into a serious one.
What shops selling cards and gifts should actually do
Most greeting-card and gift businesses take payments in one of three ways: a hosted checkout, a card terminal, or a phone order. Each has its own trap.
- Hosted checkout. Let the payment processor collect the card fields. Your site never touches the CVV2, which keeps your compliance scope small.
- Phone orders. Write the card number on a slip and you have created a liability. Enter it straight into the terminal or virtual terminal, then destroy the slip.
- Email and chat. Never ask a customer to send a card number or CVV2 by email or DM. If they offer, tell them not to.
On the verification side, ask your processor about AVS checks on the billing address and 3-D Secure for higher-value baskets. Gift baskets and personalised cards tend to sit in the range where fraudsters test stolen numbers, so simple velocity rules help: several declined attempts from one IP, several cards on one account, or a burst of orders shipping to different addresses are all worth a manual look.
If someone offers to sell you card data
Unsolicited offers usually arrive as spam, forum posts, or direct messages to a shop's social account. They are either law enforcement bait, an outright scam where you pay and receive nothing, or a genuine criminal marketplace. None of those outcomes is good for you. Report the approach to your payment processor and to your national fraud reporting body, and keep the message.
If your own card details were exposed, contact the issuer, ask for a replacement number, and check statements for small test charges. Card fraud is not abstract. It is prosecuted, and the paper trail on a botched purchase tends to point straight back at the buyer.