Selling CVVs Is Illegal: What Gift Shops Need to Know

Selling CVVs is a crime, not a business. A CVV is the three or four digit security code printed on a payment card, and no legal marketplace exists where anyone can buy or sell that data. If you run a greeting card or gift shop and someone offers you a CVV list, a fullz pack, or a batch of card numbers to run through your terminal, that offer is a fraud pitch. Accepting it turns your storefront into a link in a carding chain, and the chargebacks, frozen merchant account, and possible criminal exposure land on you.

The short answer

You cannot sell CVVs, and you cannot legally buy them. The only people who hold CVV data legitimately are the cardholder, the issuing bank, and the payment processor handling an active authorization. Anyone else offering that data for sale is selling stolen records or running a scam against the buyer. Both sides of that transaction are illegal in most jurisdictions, including the United States, the United Kingdom, Canada, and the EU.

What a CVV is and why it matters in a card-not-present sale

The CVV exists to prove the person typing a card number physically holds the card. In a face-to-face sale at a gift shop counter, a chip read or tap confirms the card is present. In an online order, over the phone, or on a marketplace listing, the CVV stands in for that physical check. Because the code is short and never printed on receipts, a thief who lifts a card number from a breached database still cannot complete an online purchase without it. That is exactly why stolen CVV data carries a price on criminal forums and why merchants are the ones who absorb the loss when it is used.

Why greeting card and gift shops attract card testing

Stores selling low-priced items with instant digital delivery are attractive to criminals for a simple reason: a small charge is unlikely to trigger a cardholder alert. Gift cards are especially exposed because they convert a stolen card number into a transferable balance within minutes. A typical pattern looks like this:

For a small shop, a run of these orders can wipe out a month of margin, and repeated fraud can cost you your ability to accept cards at all.

What payment rules require from merchants

Under the PCI Data Security Standard, the CVV is classified as sensitive authentication data. You may pass it to your processor to authorize a transaction, and you must not store it afterward in any form, including in a database, a notes field, a paper order pad, or a screenshot. That rule is not bureaucratic housekeeping. If your shop stores CVVs and your systems are breached, the stored codes are the most valuable thing a thief can take, and you become the source of the fraud rather than its victim.

Protections for shop owners

Protections for shoppers

How to recognize a fraud pitch

Watch for unsolicited messages promising bulk card data, guaranteed approval rates, or a percentage cut for running transactions through your account. Legitimate payment processors never recruit merchants this way, and no honest supplier needs your merchant account to move someone else's money. The language around selling CVVs is a marker of fraud, whether it arrives as a forum post, a direct message, or a stranger offering to "help" with your holiday rush.

Bottom line

There is no safe or legal way to sell CVVs, and no legitimate supplier will ever ask a greeting card or gift shop to do it. The practical work for a real store is narrower and more useful: keep card data out of your own systems, verify every remote order, watch small charges closely, and report anything that looks like card testing. That protects your customers, your margins, and your ability to keep taking payments through the busiest gift-giving weeks of the year.

Read our complete guide: Wedding Invitation Cards: Styles, Wording, and Etiquette Explained