Selling CVV data is illegal, and no legitimate business does it. If you run a greeting card or gift shop and you keep running into the phrase sell cvv in searches, spam email, or chat messages, the short answer is this: the CVV is the three or four digit security code printed on a payment card, and trading those codes is payment card fraud. Honest merchants protect the CVV, never store it, and never pass it on.
What the term means
CVV stands for card verification value. It exists so that a business can confirm the person paying actually holds the physical card. Because the code is not printed on the magnetic stripe or encoded in the chip, it is one of the few pieces of card data a thief cannot simply copy from a skimmer or a leaked database. That is exactly why criminals want it, and why offers to buy or sell it should be treated as a crime rather than a business opportunity.
Why gift shops are targeted
Greeting cards, gift baskets, plush toys, and personalised mugs are attractive to fraudsters for a few practical reasons:
- Orders are small enough to avoid triggering manual review.
- Items are easy to resell or ship onward.
- Buyers often send gifts to a third party, so a billing address that does not match the delivery address looks normal.
- Seasonal peaks mean more transactions and less time to check each one.
Those same traits make card-not-present fraud a real cost for a small retailer, because a fraudulent order usually ends in a chargeback plus lost stock and shipping.
Signs an order deserves a second look
- Rush shipping requested on a high-value basket with no explanation.
- Several orders placed minutes apart with slightly different names or addresses.
- Repeated failed authorisation attempts followed by a successful one.
- Email addresses that look randomly generated, or free throwaway domains.
- Requests to change the delivery address after payment.
Protecting your shop
The practical safeguards are well established. Require the CVV on every card-not-present transaction, and enable 3-D Secure or an equivalent authentication step where your payment provider supports it. Turn on address verification and set rules for mismatches. Never write the security code on a paper order form, and never store it in your order system or email inbox. Keep your checkout on a PCI DSS compliant payment processor so card data passes through a provider rather than sitting on your own server. Review your fraud rules each season, because gift shops see very different order patterns in December than in July.
If fraud slips through
Refund or void the order, document everything you have, and respond to the chargeback with the evidence your processor asks for. Report the incident to your acquirer and, where money or data was lost, to the relevant authorities. In the United States, internet-facilitated card fraud can be reported through the FBI's Internet Crime Complaint Center, and the Federal Trade Commission publishes guidance on identity theft and on safeguarding customer information.
The bottom line
There is no legitimate version of selling CVV data. For a shop that sells cards and gifts, the CVV is a security feature to be validated in the moment and then discarded, not an asset to trade. Treat every offer connected to it as a red flag, and put your effort into checkout security, staff training, and clear policies instead.