Sell CVV: Why Card Security Codes Cannot Be Bought or Sold

Selling CVV data is illegal in the United States and in nearly every country that issues payment cards. A CVV is a security code that proves a card is present during a purchase, and card network rules forbid merchants from keeping it once the transaction ends. Any listing that offers CVVs for sale is trading stolen payment credentials, which brings criminal charges, fines, and civil liability.

What is a CVV?

A CVV, or card verification value, is a short code that the card issuer generates along with the card number. It confirms that the person paying holds the real card, not just a copied number. The code is not meant to be stored by the business that accepts it.

Because the code ties a payment to a physical card, a stolen card number on its own often fails at checkout.

Why is CVV data banned from storage?

PCI DSS, the payment card industry data security standard, classifies the CVV as sensitive authentication data. Requirement 3 states that merchants must not store it after authorization, even when a customer asks them to keep it on file. That rule removes any lawful path to a CVV marketplace.

What counts as sensitive authentication data

If a merchant cannot store these values, then anyone offering them in bulk obtained them through skimming, phishing, malware, or a data breach. Those are the sources behind every CVV listing that exists.

What are the penalties for selling card data?

In the United States, trading payment card data falls under access device fraud, wire fraud, and identity theft statutes. Convictions can bring prison time, fines, and court-ordered restitution to the banks and cardholders who lost money. State prosecutors can add their own charges on top of federal ones.

Civil exposure runs in parallel. Banks and processors can sue for the full value of fraudulent charges, and a person named in a card fraud case can face judgments that outlast any prison term.

How does CVV fraud hit greeting card and gift shops?

Gift and greeting card businesses sit in a risky spot because their products are easy to resell. A thief who buys gift cards with a stolen card number and a matching CVV can move that value within minutes, before the chargeback arrives.

The shop eats the loss. The cardholder disputes the charge, the money is pulled back, and the inventory is gone. Repeat incidents lead to chargeback fees, higher processing rates, and in severe cases a terminated merchant account.

Steps to protect a gift shop from card fraud

  1. Never write down, log, or email a customer CVV. Delete it once the order is authorized.
  2. Use a PCI-validated payment processor so card data never touches your own systems.
  3. Turn on address verification and CVV checks for every online order.
  4. Flag rush orders, bulk gift card buys, and shipping addresses that differ from the billing address.
  5. Train staff to question large gift card purchases paid for with a card that does not match the buyer.
  6. Reconcile chargebacks against orders each month to spot patterns early.

What should a shop owner do if they find CVV listings?

Report the listing rather than engaging with it. The Federal Trade Commission collects identity theft and payment fraud reports at IdentityTheft.gov, and the FBI runs a complaint line for internet crime. A card issuer's fraud department also wants to know, because it can block the affected accounts.

If your own store suffered a breach, contact your processor and acquiring bank first. They can guide the required notification steps and help you close the gap that leaked data.

Frequently asked questions

Is selling CVV data ever legal?

No. There is no licensed market for card verification values in any country that follows the major card network rules. Card data belongs to the issuer and the cardholder, not to whoever holds a copy.

Can a merchant store a CVV with the customer's permission?

No. PCI DSS bans post-authorization storage of sensitive authentication data regardless of consent. Keeping the code on file puts the business out of compliance and creates a target for attackers.

What is the difference between CVV and CVV2?

CVV1 is encoded in the magnetic stripe and read by a terminal during a card-present sale. CVV2 is the printed code on the card, used when the card is not physically swiped. Card rules cover both as sensitive authentication data.

What should I do if my own card data was exposed?

Call the number on the back of your card and ask for a replacement with a new number and code. Then file a report so the fraud is on record. Review statements for small test charges, which often come before a large one.

The bottom line

Selling CVV data is a payment fraud offense, not a business opportunity. Legitimate card processing depends on the opposite rule: capture the code, verify the order, and let it go. Shops that follow that rule keep their merchant accounts, their inventory, and their customers.

Read our complete guide: Wedding Invitation Cards: Styles, Wording, and Etiquette Explained