Answer: Selling CVV codes is a crime in the United States and in most other countries. A CVV is a 3-digit or 4-digit security code printed on a payment card. The code is not a product. People who trade it deal in stolen payment data, and U.S. law treats the sale as trafficking in access devices under 18 U.S.C. 1029. Penalties include fines and prison terms. A greeting card or gift shop that accepts cards has a different job: use the code for one authorization, never store it, and screen orders for fraud.
What CVV Means
CVV stands for card verification value. Visa uses the term CVV2. Mastercard uses CVC2. American Express uses CID. The code sits on the card itself. Visa, Mastercard, and Discover print 3 digits on the back. American Express prints 4 digits on the front.
The code exists for card-not-present sales. A phone order, a mail order, or a web order cannot check a chip or a signature. The CVV gives the seller one more data point that the buyer holds the physical card. Banks call this a sensitive authentication data element.
Why Selling CVV Data Is Illegal
Payment card numbers, expiration dates, and CVV codes are access devices under federal law. Buying, selling, transferring, or possessing them with intent to defraud falls under 18 U.S.C. 1029. A first offense carries a fine and up to 10 years in prison. Cases with two or more access devices or with losses over 1,000 dollars carry longer terms.
Card networks also void the transaction. A merchant who buys card data from a third party has no authorization from the cardholder. The charge will be reversed, and the merchant account can be closed. Banks file chargeback reports, and processors list the business in the MATCH terminated merchant file.
CVV Rules for Greeting Card and Gift Sellers
PCI DSS Requirement 3.2 covers sensitive authentication data. After authorization, a merchant cannot store the full magnetic stripe, the CAV, CVC, CVV, CVV2, CVC2, or the PIN block. The rules apply to a one-person gift shop with a card reader and to a large online store.
- Send the CVV in the authorization request, then drop it.
- Do not write the code on a paper order form, a packing slip, or a receipt.
- Do not keep the code in a database, a spreadsheet, a note app, or an email inbox.
- Print receipts with the last four digits of the card number. The full card number on a printed receipt violates PCI DSS.
- Keep paper order forms in a locked drawer, and shred them when the order ships.
How Card Fraud Reaches Small Shops
Gift card orders draw fraud because the value ships as a code, and the buyer never needs a physical address. Warning signs include several cards tried on one order, small test charges, rush shipping on a large gift order, and email addresses that do not match the cardholder name.
Address Verification Service and CVV checks cut risk but do not remove it. A valid CVV means the code matched at the time of the request. It does not prove the buyer is the cardholder.
Reporting and Verification
Report card fraud to the FTC through its online complaint form and to the issuing bank. Keep order records for chargeback replies. Check PCI DSS requirements at the PCI Security Standards Council site, and confirm current penalties under 18 U.S.C. 1029 before you rely on any summary, including this one. Laws change, and this page is not legal advice.