Selling CVV numbers online is payment card fraud, not a business. A CVV is the short security code printed on a payment card, and anyone offering to sell CVV data online is trading card details that do not belong to them. The activity is criminal in every market that has card fraud law, and the offers people find in search results are usually bait designed to take money, personal data, or both.
What a CVV actually is
A CVV, sometimes written CVV2 or CVC, is a three or four digit code printed on the front or back of a card. It exists to prove that the person paying has the physical card in hand. Card networks require it for most online and phone orders, which is why stolen codes carry value to criminals and why merchants are told never to store them after a transaction is approved.
Why "sell CVV online" listings are usually traps
There is no legitimate marketplace for card security codes. Cards are issued by banks, and the only party allowed to use a code is the cardholder. What looks like a storefront for selling CVV data tends to fall into a few shapes:
- Bait pages that collect payment and deliver nothing.
- Channels run by fraud rings that resell the same code to many buyers.
- Setups that harvest the buyer's own identity and banking details.
- Monitoring pages used by investigators to trace participants.
Buying or selling these codes exposes a person to criminal liability, and a buyer has no recourse when the data turns out to be worthless. There is no customer service line for a stolen card number.
How stolen card data reaches greeting card and gift shops
Gift shops, card stores, and small ecommerce boutiques are attractive targets because they often sell low-value items, ship fast, and run lean fraud checks. A fraud ring will test a batch of stolen codes on a small order first, then push larger orders through the same store once a card clears. The chargeback lands on the merchant, not on the criminal.
Signs of card testing at checkout
- Several orders placed in minutes from the same device or IP range.
- Billing and shipping addresses that do not match, especially across countries.
- Repeated declined attempts followed by one approval.
- Orders for the cheapest item in the catalog with overnight shipping.
- Email addresses with random strings and no order history.
Practical steps for gift retailers
- Enable the card verification and address verification checks your processor offers.
- Require the CVV on every card-not-present order and never store it afterward.
- Set velocity limits on orders per card, per address, and per hour.
- Flag first-time buyers who choose expedited shipping on a small basket.
- Keep your checkout on a current payment platform that meets PCI DSS requirements.
- Review declined attempts weekly so patterns surface before chargebacks do.
If your shop is targeted
Document the orders, refund or void anything you have not shipped, and report the activity to your payment processor and to the FBI Internet Crime Complaint Center. If customer accounts were exposed, tell those customers what happened and what to watch for on their statements. Small merchants who report quickly tend to resolve disputes with their processor faster than those who wait.
Why this term shows up in retail searches
Store owners reading about chargebacks, fraud filters, and payment security often run into phrases like sell cvv online while researching the problem. Knowing that the phrase describes a crime, not a service, helps a shop owner recognize the risk for what it is and focus on the real defenses: verification checks, order monitoring, and a payment setup that keeps card codes out of your own systems.