A CVV2 is the three-digit code printed on the back of a Visa, Mastercard or Discover card, and the four-digit code on the front of an American Express card. Real gift and greeting card stores ask for it at checkout to confirm you hold the physical card. Sites that call themselves a "CVV2 shop" sell stolen card data, and buying from them is a crime.
What is a CVV2 code?
CVV2 stands for Card Verification Value 2. Banks print it on the card but do not encode it in the magnetic stripe or the chip, so a card reader never sees it.
The code exists for card-not-present payments: online orders, phone orders and mail orders. A thief who copies a card number from a receipt or a database still fails at checkout without the CVV2.
Card networks use different names for the same idea. Visa calls it CVV2, Mastercard uses CVC2, American Express uses CID, and Discover uses Card Identification Data. The check works the same way on all four.
Why do gift and greeting card shops ask for the CVV2?
A gift shop that ships to an address never sees the card, so there is no signature and no chip to verify. The CVV2 is the cheapest fraud check available at that point in the order.
Card network rules require most online merchants to collect it. The check also shifts liability: if a shop skips it and the order turns out to be fraudulent, the chargeback often lands on the merchant.
For a normal purchase this is routine. Type the digits, finish the order, move on. The trouble starts when people look for shortcuts around it.
What is a "CVV2 shop"?
The phrase describes sites and dark web markets that sell card numbers with their matching security codes. Listings often bundle the cardholder name, billing address, expiry date and the bank's customer service number.
Buying or selling that data is a crime in the United States, the United Kingdom, Canada and across the EU. It counts as fraud and, depending on how the data was taken, as unauthorized access to computer systems.
There is a practical trap as well. Many cards sold this way are blocked, cancelled or invented, and the buyer has no way to complain because the deal itself is illegal. The money is gone either way.
How do you pay safely for cards and gifts online?
Buy from shops you can identify
A real greeting card retailer lists a business address, a phone number, a returns policy and a privacy notice. If a site is new, sells cards at prices that do not add up, and shows no contact details, close the tab.
Check the checkout, not the homepage
A padlock and HTTPS matter most on the page where you type card data. On a genuine store, checkout sits on the same domain as the rest of the site. A payment form that jumps to an odd domain is a red flag.
Use a virtual card number
Many banks let you create a one-time or merchant-locked card number in their app. It carries its own CVV2, so a leak from one shop does not expose your main card.
Keep the code out of messages
Never send a CVV2 by email, text or chat, and never read it out to someone who phoned you. A genuine retailer has no reason to ask for it outside its own checkout page.
How do you protect your CVV2 after you type it?
- Turn off browser autofill for card fields on shared or work computers.
- Do not photograph your card or keep card photos in cloud galleries.
- Cover the code with your thumb in shops and when someone stands behind you.
- Read your statement each month and dispute charges you do not recognize.
- Skip the saved-card option on sites you use once.
Card network rules bar merchants from storing the CVV2 once a payment is authorized, and PCI DSS sets that requirement. A shop that keeps your code in a database is out of compliance.
What is a safe alternative to a CVV2 shop?
If the goal is a gift someone can spend, buy a retail gift card from the retailer or a supermarket. Gift cards hold no cardholder data, so a lost code costs you the balance, not your bank account.
For online gift shopping, pay through a service you already trust, such as your own bank's checkout or a mainstream wallet. When the payment provider holds the card details, the small shop never sees your number.
What should you do if a CVV2 shop uses your card?
Call your bank or card issuer the day you spot the charge and ask them to block the card. US law caps your liability for unauthorized card charges, and similar protections exist in the UK and the EU.
Then file a report. In the United States, IdentityTheft.gov handles identity theft reports and builds a recovery plan. In the UK, Action Fraud takes reports of card fraud. A report helps if the bank asks for proof.
Change the passwords on any account that stored the card, starting with the shop that leaked it and your email account.
Frequently asked questions
Is the CVV2 the same as my PIN?
No. The PIN authorizes a transaction at an ATM or terminal with the card present. The CVV2 is printed on the card and used for remote payments.
Does the CVV2 change?
It stays the same until the card is replaced. When your bank issues a new card, the code changes with it. Virtual card numbers can rotate with each use.
Can a shop save my CVV2 for next time?
No. Card network rules and PCI DSS forbid storing the code after authorization. If a site claims it saved your CVV2, treat that as a warning sign.
Are CVV2 shops legal anywhere?
No country allows the sale of card data taken without the cardholder's consent. A site that sells these listings as a "service" is describing fraud.