Nobody can legally sell a CVV. The three or four digit code printed on a payment card exists to prove the cardholder is present, and it is not a product, a license, or a transferable asset. Every listing, forum post, or direct message that offers CVVs for sale is a fraud attempt, a law enforcement operation, or a scam that takes the buyer's money and delivers nothing usable. For a greeting card or gift shop, the working answer is narrower and more practical: your checkout must never store, log, print, or email that code, and your staff should understand why that rule exists.
What a CVV actually is
- It is a card verification value generated by the issuing bank, not by the merchant.
- Visa and Mastercard print three digits on the back of the card; American Express prints four on the front.
- The code is not carried in the magnetic stripe or the chip, which is why a cloned card often fails an online order.
- Its purpose is to reduce card-not-present fraud, so it only works when the real cardholder supplies it at the moment of purchase.
- Payment card industry rules bar merchants from keeping sensitive authentication data after a transaction is authorized.
That last point is the one that matters for a gift shop. A code that cannot legally be retained after authorization cannot become inventory. Anyone claiming to hold a stock of valid codes is either working with stolen data or lying.
Why the offers you encounter are traps
- Buyers on carding forums routinely pay and receive nothing, and they have no route to complain.
- Offers are frequently posted by investigators building cases against the people who respond.
- Purchasing or using someone else's card data is a criminal offense in most countries, including the United States, Canada, the United Kingdom, and across the European Union.
- Even a single test transaction on a stolen card can expose a shop to chargebacks, fines from its processor, and loss of card acceptance.
Rules a card and gift shop checkout should follow
- Use hosted payment fields or a tokenizing gateway so the code reaches the processor and never touches your servers.
- Confirm that your point of sale and ecommerce platform are set to discard the code after authorization.
- Check that no spreadsheet, order note, inbox, or chat log holds card numbers or codes for phone and custom orders.
- Keep a written policy that staff never write a code on paper, even for a phone order for a personalised card.
- Review access so only the people who process refunds can see stored payment tokens.
Screening gift orders that look fraudulent
Gift cards and gift sets attract fraud because they are easy to resell. Watch for a billing address that does not match the card's issuing country, overnight shipping on a bulk order of gift cards, several declined attempts followed by one approval, and orders where the buyer asks to change the delivery address after payment. Call the customer on a number you look up independently before you ship. If the answers do not line up, cancel and refund through the processor rather than shipping.
What to do when someone asks your shop to sell or buy card data
Refuse, keep the message, and report it. In the United States you can file a complaint with the Internet Crime Complaint Center, and you should also tell your payment processor's fraud team so they can flag the account involved. Do not negotiate, do not run a test charge to see whether the data works, and do not accept a payment link from the person making the offer.
Bottom line
There is no legitimate market for CVVs, so there is nothing for a greeting card or gift business to buy, sell, or broker. Your job is the opposite: keep the code out of your systems, screen the orders that carry the highest fraud risk, and give your staff a script for the moment someone proposes a deal.