The short answer
A CVV dump is a batch of stolen payment card records that includes the card verification value: the three-digit code on the back of most cards, or the four-digit code on the front of American Express cards. Each record typically carries the card number, expiration date, cardholder name, and that security code. The code is the part most card-not-present fraud needs, because it is the closest thing an online checkout has to proof that the physical card is in hand.
For someone buying birthday cards, gift baskets, or personalised presents online, the useful takeaway is simple. The top defence is a payment method that a thief cannot reuse: a virtual card number from your bank, or a tokenised wallet checkout. I judged the options below on four criteria: whether a stolen number stays usable after checkout, how much friction it adds to a normal gift order, how well it handles refunds and returns, and how easy it is to cancel or dispute.
Why dumps matter to card and gift shoppers
Card and gift retailers sell low-value, high-volume items that ship to an address. That combination attracts fraud, and it also means a compromised card often shows up first as a small charge from a shop you do not recognise: a card, a mug, a box of chocolates. Small charges are easy to miss on a statement, which is why they get tested before a larger one follows.
Two protections sit behind the scenes. The PCI Data Security Standard forbids merchants from storing the card verification value after a transaction is authorised, so a breach at a well-run shop should not expose that code at all. And under the Electronic Fund Transfer Act, your liability for unauthorised use depends on how fast you report it, while credit card liability for unauthorised charges is capped at fifty dollars.
Option 1: Virtual card numbers from your bank
Pros
- The number is generated for one merchant or one purchase, so it cannot be reused elsewhere.
- You can set a spending limit and an expiry date before you check out.
- If the number leaks, you keep your real card number out of circulation.
Cons
- Not every bank offers them, and some bury the feature in a mobile app.
- A number locked to one merchant complicates returns to a different shop.
- Subscriptions and repeat gift orders need a fresh number each time.
Use it when: you are ordering from a smaller card or gift maker you have not bought from before, and the order is a one-off.
Option 2: Tokenised wallet checkout
Pros
- The shop receives a token, not your card number, so a later breach exposes nothing reusable.
- Works on most gift and greeting card sites without extra setup.
- Refunds and disputes flow through your existing card issuer.
Cons
- Requires a supported phone or browser, which rules out some desktop checkouts.
- You lose the ability to set a per-purchase cap.
- Small shops occasionally lack wallet support entirely.
Use it when: you shop on the same trusted sites often and want the least friction at checkout.
Option 3: Prepaid cards and store credit
Pros
- Your bank account and main card are never connected to the purchase.
- Losses are capped at whatever balance you loaded.
- Useful for gifts you send straight to someone else.
Cons
- Consumer protections are weaker than those on a credit card.
- Some prepaid cards carry activation or monthly fees.
- Disputes can be slow and may depend on the issuer's terms.
Use it when: you are paying a marketplace seller or a pop-up gift stall and want a hard ceiling on what can be taken.
Warning signs at a gift checkout
- A site asks for your card code in a chat message, email, or text. No legitimate retailer does this.
- The payment page is missing a padlock or asks you to re-enter details on a second domain.
- Someone offering to sell you a dump, a checker, or a full set of card details. This is a crime in most countries, and the seller is usually running a scam against buyers too.
- A small, unfamiliar charge appears after you buy a card or gift elsewhere.
If your card details are used
Call the number on the back of your card and ask for the charge to be reversed and the card replaced. Then check whether you are dealing with identity theft as well, since a dump can include your name and address. Report the loss to your issuer in writing so you have a timestamp, and file a report with your national fraud or cybercrime reporting body. Keep a copy of the report number. For debit card losses, speed matters more than for credit cards, so report within two business days if you can.