Selling CVVs is a crime, not a business. A CVV is the three or four digit security code printed on a payment card, and no legal marketplace exists where anyone can buy or sell that data. If you run a greeting card or gift shop and someone offers you a CVV list, a fullz pack, or a batch of card numbers to run through your terminal, that offer is a fraud pitch. Accepting it turns your storefront into a link in a carding chain, and the chargebacks, frozen merchant account, and possible criminal exposure land on you.
The short answer
You cannot sell CVVs, and you cannot legally buy them. The only people who hold CVV data legitimately are the cardholder, the issuing bank, and the payment processor handling an active authorization. Anyone else offering that data for sale is selling stolen records or running a scam against the buyer. Both sides of that transaction are illegal in most jurisdictions, including the United States, the United Kingdom, Canada, and the EU.
What a CVV is and why it matters in a card-not-present sale
The CVV exists to prove the person typing a card number physically holds the card. In a face-to-face sale at a gift shop counter, a chip read or tap confirms the card is present. In an online order, over the phone, or on a marketplace listing, the CVV stands in for that physical check. Because the code is short and never printed on receipts, a thief who lifts a card number from a breached database still cannot complete an online purchase without it. That is exactly why stolen CVV data carries a price on criminal forums and why merchants are the ones who absorb the loss when it is used.
Why greeting card and gift shops attract card testing
Stores selling low-priced items with instant digital delivery are attractive to criminals for a simple reason: a small charge is unlikely to trigger a cardholder alert. Gift cards are especially exposed because they convert a stolen card number into a transferable balance within minutes. A typical pattern looks like this:
- Small test purchases on inexpensive items such as a single card or a gift tag, used to confirm a stolen card still works.
- A rapid follow-up order for gift cards or high-value gift sets.
- Immediate resale of the gift card code on a secondary market before the real cardholder notices the charge.
- A chargeback weeks later, after the goods or codes are gone.
For a small shop, a run of these orders can wipe out a month of margin, and repeated fraud can cost you your ability to accept cards at all.
What payment rules require from merchants
Under the PCI Data Security Standard, the CVV is classified as sensitive authentication data. You may pass it to your processor to authorize a transaction, and you must not store it afterward in any form, including in a database, a notes field, a paper order pad, or a screenshot. That rule is not bureaucratic housekeeping. If your shop stores CVVs and your systems are breached, the stored codes are the most valuable thing a thief can take, and you become the source of the fraud rather than its victim.
Protections for shop owners
- Use a processor that tokenizes card data so raw numbers never touch your own systems.
- Never write card numbers or security codes on order slips, packing notes, or a spreadsheet.
- Require the CVV and a full billing address match on every phone and online order.
- Set velocity limits so several small orders from one address or device get flagged.
- Delay digital gift card delivery by a short hold period on first-time buyers.
- Train seasonal staff to recognize pressure tactics, split payments, and buyers who offer to pay extra for speed.
Protections for shoppers
- Treat any message offering to sell card data as a scam aimed at you, not an opportunity.
- Check statements for small unfamiliar charges, since test charges often come before a large one.
- Report suspected card fraud to your bank immediately, then to the relevant consumer protection agency.
- Buy gift cards only from the retailer or a reputable seller, and keep the receipt with the card.
How to recognize a fraud pitch
Watch for unsolicited messages promising bulk card data, guaranteed approval rates, or a percentage cut for running transactions through your account. Legitimate payment processors never recruit merchants this way, and no honest supplier needs your merchant account to move someone else's money. The language around selling CVVs is a marker of fraud, whether it arrives as a forum post, a direct message, or a stranger offering to "help" with your holiday rush.
Bottom line
There is no safe or legal way to sell CVVs, and no legitimate supplier will ever ask a greeting card or gift shop to do it. The practical work for a real store is narrower and more useful: keep card data out of your own systems, verify every remote order, watch small charges closely, and report anything that looks like card testing. That protects your customers, your margins, and your ability to keep taking payments through the busiest gift-giving weeks of the year.