Nobody legitimate sells CVVs online. The phrase describes the trade in stolen payment card numbers and verification codes, and it is illegal in every market where a greeting card or gift shop operates. If you sell cards, stationery, or gift items and you searched this term, the answer that matters to you is defensive: the same criminal ecosystem that buys and sells card data is the ecosystem that runs carding attacks against small online checkouts, and gift shops with low-value orders and instant digital delivery sit near the top of the target list. Treat the topic as a fraud-prevention problem, not a sales channel.
What the phrase actually describes
A CVV is the three or four digit verification value printed on a payment card. In criminal slang, a CVV is shorthand for a full set of card details, and selling one means handing over data lifted from a cardholder who did not consent. The trade happens on closed forums and invite-only marketplaces, it is prosecuted as fraud and identity theft, and the operators of those markets are routinely the subject of law enforcement action. No payment processor, no bank, and no gift retailer participates in it. Any storefront that advertises CVVs for sale is either a scam aimed at other criminals or a front for stealing payment details from whoever pays.
Why gift and greeting card shops attract carding
Carding works best where orders are small, delivery is fast, and disputes are rare. A personalised greeting card or a mid-priced gift hamper fits that profile. A stolen card number can be tested with a five dollar order, and if it clears, the attacker escalates. Digital gift cards are worse, because the value leaves your inventory within seconds and there is nothing to ship, track, or intercept.
- Low order values keep fraud under manual review thresholds at many processors.
- Instant digital fulfilment removes the shipping delay that gives merchants time to catch a bad order.
- Seasonal peaks, such as Valentine's Day and December, bury odd patterns in a flood of normal traffic.
- Gift card balances can be resold before a chargeback ever lands.
Warning signs on your own checkout
Most carding attacks announce themselves in the data before they announce themselves in a chargeback report. Watch for a burst of orders sharing one device fingerprint but many card numbers, repeated declines followed by a success on the same account, billing and shipping addresses in different countries, and email addresses built from random character strings. Gift card orders that ask for immediate delivery to a third-party address deserve a second look every time.
Fraud controls worth comparing
No single control stops carding. The practical approach is layering two or three, chosen to match your order volume and how much friction your customers will tolerate.
Address verification and CVV checks
Your processor compares the billing address and the card verification value supplied at checkout against the issuer's records.
- Pros: cheap or included with your processing plan, invisible to honest customers, catches crude attacks.
- Cons: address data goes stale, some issuers do not return a match, and a determined attacker can buy matching data.
3-D Secure authentication
The cardholder confirms the purchase with their bank, usually through an app or a one-time code.
- Pros: shifts liability for fraud chargebacks to the issuer in most cases, strongly deters bulk card testing.
- Cons: adds a step that some buyers abandon, and the flow varies by bank and country.
Velocity limits and manual review
You cap how many orders a card, address, or device can place in a window, and you hold anything above the cap for a human to check.
- Pros: catches card testing directly, needs no new vendor, and adapts to your own order history.
- Cons: costs staff time at peak, and a badly set threshold will hold genuine repeat buyers.
Digital gift card delivery rules
Delay the code, require the buyer's email to match the purchaser, or restrict instant delivery to verified accounts.
- Pros: removes the attacker's fastest path to value.
- Cons: slows a product customers expect to arrive instantly, so it needs clear messaging at checkout.
The customer-facing side: gift card scams
Your buyers are also targets. A common scam tells someone to pay a debt or a fake fine with gift card codes read out over the phone. Once the code is shared, the balance is gone. Train anyone on your counter or support desk to recognise the pattern, and put a short note near gift card displays telling customers that no government agency, utility, or employer asks for payment in gift card codes. If a customer reports it, point them to their local police and the national fraud reporting body for their country. Speed matters, because a code that has not yet been redeemed can sometimes be frozen.
Recommendation by situation
If you are a shopper who landed here looking to buy card data, there is no safe or legal version of that transaction. If you run a greeting card or gift shop, start with velocity limits and a digital gift card delay, then add 3-D Secure once you have measured how much checkout friction your customers accept. If you are a customer who was told to pay with gift card codes, contact the issuer and the police before you contact anyone who asked you for the codes.