A CVV2 shop is a black market storefront that sells stolen payment card records, including the three or four digit security code printed on a card. It is not a greeting card store, a gift shop, or any kind of legitimate retailer. Buying from one is a crime in most countries, the records are often stolen or fabricated, and the cards are frequently cancelled before a buyer can use them.
What the CVV2 code actually is
The code is a short verification number that proves the person entering card details is holding the physical card. It is not stored in the magnetic stripe or the chip, and it is not printed on receipts.
- Visa, Mastercard, and Discover print a three digit code on the back, inside or beside the signature strip.
- American Express prints a four digit code on the front, above the card number.
- Merchants may ask for it during a card not present order, such as a gift basket delivered to another address.
- Under PCI DSS rules, a merchant may use the code to authorise a sale but must not keep it afterward.
Why CVV2 shops exist
Card data has resale value because a criminal can attempt a purchase without ever touching the plastic. These sites dress themselves up as boutiques, use stock photos, and post fake reviews to look credible. The catalogues are usually recycled breach data, generated numbers, or cards that banks have already flagged. Buyers who pay for the data hand over money to the same criminal network that stole the data in the first place, which is why the operators rarely face complaints from their own customers.
The legal position
Possessing, trading, or using another person's card credentials is a criminal offence in the United States, the United Kingdom, the European Union, and most other jurisdictions. Penalties include prison time, fines, and a permanent record that follows a person through background checks for jobs, rentals, and credit applications. Victims of card fraud can also pursue civil claims against anyone who used their data.
How to protect your card when you order cards and gifts online
- Type the retailer's address into the browser bar instead of clicking a link from a message or advertisement.
- Check that the checkout page address begins with https and that the padlock symbol is present.
- Pay with a credit card rather than a debit card, since credit cards carry stronger fraud protection in most markets.
- Use a virtual or single use card number from your bank for unfamiliar shops.
- Keep a saved list of the shops you trust and buy from those sites only.
- Review your statement each month and match every entry to a purchase you made.
- Set transaction alerts in your banking app so a charge reaches your phone as it happens.
Warning signs at checkout
- The shop asks for your CVV2 code by email, chat, or text message. No real store does this.
- The price is far below the market rate for the item.
- The site has no phone number, no postal address, and no returns policy.
- The checkout page asks for your PIN or your online banking password.
- The order confirmation arrives from a free email account.
If your card data leaks
- Call the number on the back of your card and ask the issuer to freeze the account.
- Request a replacement card with a new number and a new security code.
- Change the password on your bank account and any shopping account that stored the card.
- File a report with your national fraud or cybercrime reporting centre.
- Check your credit file for accounts or enquiries you do not recognise.