A "cvv2 shop" is a website that claims to sell CVV2 codes, the three- or four-digit security numbers printed on payment cards. No legal business sells those codes. Real greeting card and gift stores only ask you to type your own CVV2 into their checkout page to confirm the card is in your hand.
The phrase turns up in two places: fraud forums, where stolen card data gets traded, and search results from shoppers who saw "CVV2" on a payment form and wondered what it meant. This guide covers both. It explains what the code is, why shops ask for it, and how to spot a site that wants to steal it.
What is a CVV2 code?
CVV2 stands for Card Verification Value 2. It is a short number printed on a payment card but not encoded on the magnetic stripe or the chip.
Banks use it as proof that the person typing a card number holds the physical card. The code sits on the card itself, so a thief who copies a card number from a receipt or a database still cannot finish a purchase without it.
Each card network gives the code a different name:
- Visa calls it CVV2.
- Mastercard calls it CVC2, short for Card Validation Code 2.
- American Express calls it CID, the Card Identification Number, and prints four digits on the front.
- Discover calls it a Card Security Code.
Where do you find the CVV2 on your card?
Visa, Mastercard, and Discover
Turn the card over and look at the signature strip. You will see a long string of digits, and the final three are the CVV2. On some newer cards the three digits sit in a separate box to the right of the strip.
American Express
Amex prints its four-digit code on the front, above and to the right of the card number. It is not on the back.
Why do gift shops ask for a CVV2 at checkout?
Online orders are "card not present" transactions. A shop cannot check your signature or your ID, so it asks for the CVV2 as a low-cost extra check.
A correct CVV2 does not prove you own the card. It raises the cost of fraud, because a criminal needs the card number and the printed code.
Merchants are not allowed to store the CVV2 once a transaction is approved. PCI DSS, the payment card industry's security standard, treats the code as sensitive authentication data and bans keeping it.
What about 3-D Secure?
Many banks add a second step called 3-D Secure, the system behind Visa Secure and Mastercard Identity Check. That step sends a code to your phone or asks for a password in your banking app. It complements the CVV2 rather than replacing it.
CVV, CVV2, CVC, CID: what is the difference?
CVV and CVC describe the same idea, and the number 2 marks the version used for online orders. The original CVV is encoded on the magnetic stripe and read by a terminal when you swipe or insert a card.
You never type the stripe version. If a website asks for a "CVV1" or a magnetic stripe code, it is not a normal checkout page.
What happens if you buy card data from a CVV2 shop?
Buying or selling stolen card data is a crime in most countries, including the United States, the UK, Canada, Australia, and across the EU. A buyer can face fraud or stolen property charges, even when the card belongs to a stranger.
The sites themselves are unreliable. Many sell expired numbers, invented numbers, or data copied from old breaches. Some take the payment and vanish. Others log the details you type and reuse them later.
There is no refund and no support line. A buyer who gets cheated has no way to report the loss without admitting to a crime.
How to spot a shop that trades in card data
Most fake stores follow the same pattern. Watch for these signals:
- Prices in cryptocurrency only, with no card or bank option.
- Gift cards or vouchers sold below face value with "instant delivery".
- Requests for your CVV2 by email, chat, or phone.
- No company name, address, or terms of service.
- Checkout pages with no padlock and no HTTPS.
- No proper receipt or order confirmation.
How to protect your own CVV2 when you shop
- Type the code only on a checkout page that starts with https and shows a padlock.
- Never send a CVV2 by email, text, or social media message. No real shop needs that.
- Use a virtual card number from your bank for one-off gift orders. The code changes and the card expires fast.
- Check your statement after every online order and report anything you do not recognize.
- Freeze the card in your banking app if you think the number leaked.
Frequently asked questions
Is buying CVV2 data legal?
No. Selling or buying payment card data falls under fraud and identity theft laws in the US, UK, Canada, Australia, and the EU. Penalties range from fines to prison time.
Can a merchant store my CVV2?
No. PCI DSS forbids storing the CVV2 after authorization, even in encrypted form. If a shop says it keeps the code "for your convenience", that is a warning sign.
What if a greeting card site asks for my CVV2 by email?
Refuse and shop elsewhere. A written request for your security code means the site is careless or fraudulent.
Does a CVV2 shop ever sell real gift cards?
Some discount gift card sites are legitimate resellers, but they sell card numbers and balances, not CVV2 codes. A site that advertises "CVV2" or "fullz" is trading in stolen payment data.
Key takeaways
- A CVV2 is the three-digit code on the back of most cards, and four digits on the front of an Amex.
- Legitimate gift and card shops ask for it at checkout and never store it.
- "CVV2 shop" sites sell stolen card data, which is illegal to buy or sell.
- Protect your code with HTTPS checkout pages, virtual cards, and regular statement checks.