Selling CVV numbers online is a criminal offence
There is no legal marketplace, broker or platform for selling CVV numbers. A CVV is the three or four digit security code printed on a payment card, and it exists for one purpose: to prove that the person paying is physically holding the card. Trading those codes means trading stolen payment credentials. That is payment card fraud in the United States, the United Kingdom, the EU, Canada, Australia and nearly everywhere else. Anyone hunting for a place to sell CVVs is looking for a felony, not a business model.
This page answers the question directly, then explains the term, the legal exposure, and the steps a legitimate gift or greeting card retailer takes to keep customer card data safe.
What a CVV actually is
Card networks introduced the code so that a stolen card number alone would not be enough to complete a purchase. Visa calls it CVV2, Mastercard calls it CVC2, American Express prints a four digit code on the front. The code is not stored on the magnetic stripe or the chip, and PCI DSS rules forbid merchants from storing it after authorisation. That single design decision is why the code is valuable to a fraudster and why every legitimate processor treats it as radioactive.
Why the underground trade harms everyone in the chain
- Cardholders lose money, time and, in repeat cases, access to credit.
- Merchants absorb chargebacks, fees and higher processing rates.
- Small gift and stationery shops can lose their payment processing account entirely after a fraud spike.
- Buyers in these forums are frequently defrauded themselves, since the sellers are criminals trading with criminals.
Legal exposure you should understand
Prosecutors do not treat card data trafficking as a minor offence. Depending on the jurisdiction, charges can include access device fraud, wire fraud, identity theft, unauthorised use of a payment card, and money laundering when funds move through accounts. Penalties routinely include prison time, restitution to the issuing banks, and permanent bans from holding merchant accounts. Cross-border cases are handled through mutual legal assistance treaties, so moving servers offshore does not create protection.
What a greeting card or gift shop should do instead
If you sell cards, flowers, hampers or giftware, your real job is protecting the card data your customers hand you. Work through these steps in order.
- Use a PCI DSS compliant payment processor and let it handle card capture on its own hosted page or terminal.
- Never write down, photograph or store the CVV anywhere in your order system, on paper, or in a notes app.
- Keep your point of sale software patched and confirm it is listed on the processor's approved hardware list.
- Train every staff member, including seasonal help, to verify signatures or PIN entry and to report unusual bulk orders.
- Review your transaction reports weekly and flag orders that mix several cards with mismatched billing addresses.
- Report suspected card fraud to your acquirer immediately, then file a report with your national fraud bureau.
Legitimate gift retailing grows through taste, service and repeat customers. Stolen card data destroys all three, and the people who profit from it are not building anything you want to be part of.