Short answer
A CVV2 shop does not exist as a legitimate business. CVV2 is the three or four digit security code printed on a payment card, and no real company sells those numbers. Sites advertising a "CVV2 shop" are fraud operations selling stolen card data or running advance-fee scams. If you sell greeting cards, gift baskets, or personalized presents online, your job is narrower and legal: verify the code on card-not-present orders, never store it, and know what to do when a check fails.
What CVV2 actually is
CVV2 is a value printed on the card itself, separate from the card number and the magnetic stripe data. Visa, Mastercard, and Discover place three digits on the back. American Express places four digits on the front. The code exists to prove that whoever is typing the card number has the physical card in hand or a copy of it. Because it is not encoded on the stripe, a criminal who skims a card at a terminal does not automatically obtain it.
Card networks require the code for most card-not-present transactions. Gift shops take a large share of orders by phone, web form, and message app, which puts them squarely in card-not-present territory.
Why "CVV2 shop" offers are fraud
Anyone offering to sell CVV2 numbers is offering stolen property. The pitch usually takes one of three shapes: a marketplace selling card data, a tool that claims to generate valid codes, or a "checker" service that tests cards for a fee. All three are illegal to use, and the first two are commonly bait for payment scams. Buyers send cryptocurrency or gift card codes and receive nothing.
If a customer asks your shop to process an order using card data they bought elsewhere, that is a fraud attempt. Decline the order.
How to handle CVV2 on gift orders
- Collect the code in a secure payment field on every card-not-present order.
- Send the code directly to your payment processor for verification.
- Confirm the authorization response before you personalize, print, or wrap anything.
- Delete the code from your order record as soon as the transaction settles.
- Keep only the authorization result, the last four digits, and the approval reference.
When a CVV2 check fails
- Do not retry the same card more than twice. Repeated attempts look like card testing.
- Ask the customer to confirm the code and the billing address on file with their bank.
- Offer an alternative payment method such as a bank transfer or a payment link.
- Hold the order until payment clears, especially for custom printed cards.
- Log the failed attempt and the order details for your records.
Protecting your shop
- Never write a CVV2 number on a paper order form, a packing slip, or a sticky note.
- Never ask a customer to send the code by email, text, or chat message.
- Keep your checkout on a processor that is validated against the PCI Data Security Standard.
- Train seasonal staff on what they may and may not record during the holiday rush.
- Watch for bursts of small orders from one IP address. Card testers often start with low-value items.
If your own card is exposed
Call the number on the back of your card, report the exposure, and request a replacement. Review recent statements for charges you do not recognize, and file a report with the Federal Trade Commission if money was taken. A new card number and a new CVV2 are issued together, so the old code stops working.