Sell CVV Online: What It Means and Why It Is Illegal

Short answer

No legitimate company sells CVV numbers online. A CVV is the 3 digit code printed on the back of a Visa, Mastercard, or Discover card, or the 4 digit code on the front of an American Express card. It exists to prove that the person paying holds the physical card. Selling, buying, or trading CVV numbers is card fraud in every U.S. state and in most other countries.

What a CVV is

CVV stands for Card Verification Value. Visa uses the term CVV2 for the 3 digit code. Mastercard uses CVC2. American Express uses CID. The code is not stored in the magnetic stripe or the chip. A merchant that asks for it during a card-not-present order is checking that the buyer has the card in hand.

Card networks treat the CVV as sensitive authentication data. It is not the same as the card number, the expiry date, or the cardholder name.

What the law says

In the United States, 18 U.S.C. Section 1029 covers fraud and related activity in connection with access devices. A payment card number and its CVV fall under that definition. Penalties reach 15 years in prison and fines for a first offense, and higher for repeat offenses or for trafficking in the data.

Other jurisdictions carry similar rules. The UK Fraud Act 2006 covers possession of articles for use in fraud, which includes card data. EU member states criminalise card data trafficking under national law that implements the Directive on attacks against information systems.

Why listings that offer to sell CVV online appear

Two cases are common. The first is stolen card data traded on closed forums, often after a breach at a retailer or processor. The second is an advance-fee scam. The seller collects payment and delivers nothing. Both leave the buyer with no recourse and with a record that banks and card networks can flag.

Banks run fraud models that score card-not-present transactions on the CVV check result, device data, and velocity. A decline on the CVV check is one of the strongest signals of a stolen number.

What gift and card merchants must do

Shops that sell greeting cards and gifts online take card payments through a payment processor. PCI DSS Requirement 3.2 prohibits storing sensitive authentication data, including the CVV, after authorization. The processor handles the card data and returns a token. The merchant keeps the token, the order, and the shipping address.

Any merchant that stores a CVV after authorization is out of compliance and carries liability for the breach that follows.

Reporting

Cardholders can report a fraudulent charge to the number on the back of the card. Offers to sell card data can be reported to the Federal Trade Commission and to the FBI Internet Crime Complaint Center. Both agencies publish consumer guidance on card fraud and gift card scams.

Read our complete guide: Wedding Invitation Cards: Styles, Wording, and Etiquette Explained