What a CVV dump is
A CVV dump is a record of payment card data copied from a card and offered for sale on carding forums or in private chat groups. The cardholder gave no permission. The seller does not own the card. Buying, selling, or using the record is card fraud in most countries.
CVV stands for card verification value. Visa, Mastercard, and Discover print a three-digit code on the back of the card. American Express prints a four-digit code on the front. The code proves the buyer holds the physical card during a remote purchase.
What sits inside a dump
- Track 1 or Track 2 data read from a magnetic stripe: card number, expiry date, cardholder name, service code.
- In some listings, a billing address, ZIP code, or phone number.
- The CVV2 printed on the card appears in a small share of listings, because that code is not stored on the stripe.
That gap matters. Most dumps carry no printed verification code. A stolen number alone fails at checkout when the merchant asks for the code and the billing address, and when the bank blocks the card after the first flagged charge.
How the data gets taken
Skimmers on fuel pumps and ATMs, breached merchant databases, and phishing pages feed the supply. Data moves in bulk, then gets resold. A card number has a short working life. Address verification checks and chargebacks push much of the loss back to the merchant that accepted the order.
Consumer steps
- Turn on transaction alerts in the card issuer's app.
- Read statements each month and dispute unknown charges inside the issuer window, which is 60 days for many US cards.
- Tap or insert the chip at the terminal. A stripe swipe exposes more data.
- Freeze the card in the app, then ask for a new number.
- File a report with the FTC at IdentityTheft.gov, and with IC3 when the loss is large.
Merchant steps
PCI DSS forbids storing the CVV2 after a transaction is authorized, including in encrypted form. Tokenization swaps the card number for a reference value. Address Verification Service and 3-D Secure add checks at checkout. A greeting card or gift shop that sells online should confirm its payment provider runs these controls, because the shop carries the chargeback risk when fraud gets through.
Loss totals for card fraud vary by source and year. Treat any single figure with care.