Why this page does not point to a place that sells CVV data
The query "sell cvv website" describes a marketplace for stolen card data. This site covers greeting cards and gifts. There is no factual informational guide to write on that keyword that does not help someone commit card fraud. So this page answers the question behind the term instead: what a CVV is, who may hold it, and what the law says about selling it.
What a CVV is
CVV stands for card verification value. It is the three-digit code printed on the back of Visa, Mastercard, and Discover cards, and the four-digit code on the front of American Express cards. Banks generate the code from the card number, expiry date, and a key held by the issuer. It ties a transaction to the physical card. A merchant can ask for it. A merchant may not keep it.
What the law says
In the United States, 18 U.S.C. Section 1029 makes it a crime to traffic in access devices. That covers card numbers, CVVs, and the tools used to capture them. A first offense carries up to 10 years imprisonment, a repeat offense up to 15 years. Canada, the United Kingdom, and EU member states have comparable statutes.
Card network rules
Visa, Mastercard, and American Express all forbid storing the CVV after a transaction is authorized. PCI DSS Requirement 3.2 states that sensitive authentication data must not be retained after authorization, even in encrypted form. A processor that stores CVVs loses its certification.
What a card or gift shop should do
- Do not write the CVV into an order note, a database field, or a support ticket.
- Use a payment processor certified under PCI DSS that tokenizes card numbers.
- Keep shipping records for cards and gifts free of full card numbers.
- Route any customer or staff request for a card code to the processor, not to a spreadsheet.
- Report suspected card fraud to the FTC fraud reporting portal or to the FBI Internet Crime Complaint Center.
Unknown
The size of the market for stolen card data is not measured on one consistent basis. Published estimates differ by source and by year, and no figure here would be reliable.