A CVV dump is a batch of stolen payment card records that includes the card verification value, the three or four digit security code printed on the card. The short answer: it is stolen financial data. Buying, selling, or using one is a federal crime, and no legitimate greeting card or gift seller has anything to do with it. The useful part of the term is what it tells you about fraud risk when you buy cards, gift boxes, and gift cards online.
What a CVV dump actually contains
In fraud slang, a dump is a bulk file of card records. Each record typically pairs a card number and expiration date with a cardholder name, a billing address, and sometimes the CVV. The CVV is the piece that matters most for online orders, because a thief who holds only a card number often cannot complete a purchase without it. Sellers of this data trade on hidden forums and messaging apps, and they favor categories that are easy to flip: gift cards, digital codes, and anything shipped to a drop address.
- Card verification value (CVV): the code on the back of most cards, on the front for some brands.
- Fullz: a record that adds personal details, which makes identity theft easier.
- Card-not-present fraud: the umbrella term for misuse of card data in online or phone orders.
Why gift shops and card stores get targeted
Greeting cards and gifts sit in a high risk corner of retail. Order values are small, so a stolen card is less likely to trigger a bank alert. Delivery is often digital, which means no shipping address to verify and no parcel to intercept. Gift cards add a second layer, because a stolen card can buy a gift card code that is then resold at a discount. That combination is why card networks push extra verification on these merchants.
Warning signs on a card or gift website
- Checkout that never asks for a CVV or a billing address.
- Prices far below normal for branded gift cards.
- Payment by wire, crypto, or peer to peer transfer only.
- No business address, no return policy, and a domain registered weeks ago.
- Pressure to buy gift card codes in bulk while stock lasts.
Protecting your own card while you shop
- Use a card that generates single use or virtual numbers for small online shops.
- Turn on purchase alerts so you see every charge as it happens.
- Shop with a credit card rather than a debit card, since credit disputes are simpler.
- Keep the CVV out of saved notes, screenshots, and chat messages.
- Buy gift cards from the issuer or a major retailer, and check in store packaging for tampering.
If your card number appears in a dump
- Freeze the card in your banking app or call the number on the back.
- Request a new card number, not just replacement plastic.
- Review statements for small test charges that often precede larger ones.
- File a report at IdentityTheft.gov and, for online fraud, with the FBI Internet Crime Complaint Center.
- Change passwords on shopping accounts that stored the card.
What legitimate sellers do instead
Reputable card and gift merchants tokenize card numbers so raw digits never rest in their systems, require a CVV and billing address match at checkout, and add an extra authentication step on larger orders. They also cap how many gift cards a single order can contain. Those measures are why your own checkout sometimes asks for a code from your bank, and why a shop that skips them deserves suspicion.
Bottom line: a CVV dump is a crime product, not a shortcut. If a search result or a message offers you one, that is a scam or a felony, and the safest response is to report it and move on.