What a CVV dump is
A CVV dump is a batch of stolen payment card records packaged for sale on criminal forums. Each record usually pairs a card number and expiration date with the three or four digit security code printed on the card, known as the CVV, CVV2, or CVC. Sellers trade these batches for cryptocurrency and buyers use them to place orders that the real cardholder never authorized.
There is no legal use for a CVV dump. Buying, selling, or using one is payment card fraud, and it carries felony exposure in the United States and most other countries. The sections below explain how the scheme works in the gift and greeting card trade so you can spot it, block it, and protect your own accounts.
Why greeting card and gift sellers are frequent targets
Gift shops sell low-priced items that ship fast and resell easily, which makes stolen card numbers attractive to fraud rings. Most orders are card-not-present, meaning no card is swiped and no signature is collected. Digital gift cards carry the highest risk because delivery is instant and the value is gone before a chargeback arrives, usually 30 to 90 days later.
Warning signs for shoppers
- A checkout page that asks for your CVV by email, text, or chat instead of a secure form.
- A shop with no physical address, no phone number, and prices far below market.
- Requests to pay by gift card, wire transfer, or cryptocurrency instead of a card processor.
- An order confirmation from a domain that does not match the store you thought you visited.
Steps to protect your card when buying gifts online
- Type the retailer's address into your browser instead of clicking a link in an email or ad.
- Check that the checkout page address begins with https and shows a padlock before you enter card details.
- Pay with a credit card rather than a debit card, since credit cards carry stronger fraud protections.
- Use a virtual or single-use card number from your bank for unfamiliar shops.
- Turn on transaction alerts so you get a message the moment a charge posts.
- Save the order confirmation and the merchant's contact details until the item arrives.
Steps for gift shop owners to reduce card fraud
- Never store the CVV after an authorization, which PCI DSS forbids.
- Require the CVV and the billing address postal code on every card-not-present order.
- Use the Address Verification Service and 3-D Secure checks your processor offers.
- Flag orders where the shipping address differs from the billing address and the buyer wants overnight delivery.
- Set velocity limits on digital gift card purchases per card, per email, and per IP address.
- Delay digital delivery by a few hours on first-time buyers so you can review the order.
- Keep your payment platform patched and confirm your host meets current PCI DSS requirements.
If your card is compromised
- Call the number on the back of your card and ask the issuer to freeze the account.
- Request a new card number rather than reusing the old one.
- Dispute every charge you do not recognize in writing and keep a copy.
- File a report at IdentityTheft.gov if your personal data was exposed along with the card.
- Report internet-enabled card fraud to the FBI's Internet Crime Complaint Center.
- Review statements for at least three months, since small test charges often come before large ones.