Selling CVV data is a criminal act of payment card fraud, not a legitimate online business. The CVV is the three or four digit security code printed on a payment card, and it exists to prove the physical card is in the buyer's hand. Any forum, marketplace, or message that claims to "sell CVV" is trading stolen financial data, and greeting card and gift merchants are among the businesses most often hit by orders placed with that data.
What does "sell CVV" actually mean?
The phrase describes offers to hand over card numbers together with their verification codes, often bundled with a cardholder name and an expiry date. Sellers usually claim the data came from skimming devices, phishing pages, or a breached retailer database. Buyers then use those codes for card-not-present purchases, which is why a small online gift shop or a greeting card storefront can appear in the same criminal conversation.
Is selling CVV data legal?
No. In the United States and most other countries, buying, selling, or holding stolen payment card credentials violates fraud and identity theft law. The Federal Trade Commission treats the trade in stolen card data as identity theft, and the FBI's Internet Crime Complaint Center records these cases as cyber-enabled financial crime. Consequences can include prison time, fines, and restitution to victims.
Why is a CVV so valuable to a fraudster?
A card number alone is weak, because most issuers require the verification code before an online order is approved. A matching CVV raises the odds that an order clears on the first attempt, before the shop or the bank notices anything wrong. That is why criminals bundle the code with the number instead of selling either piece on its own.
How do greeting card and gift merchants prevent CVV fraud?
Legitimate shops follow the PCI Data Security Standard, which prohibits storing the CVV once a transaction is authorized, and they add layered checks on top of it. Common controls include:
- Address Verification Service and CVV checks at checkout
- Tokenization, so real card numbers never rest on the shop's servers
- Velocity limits and manual review of unusual gift card or bulk gift orders
- Staff training on phishing, phone scams, and social engineering
- 3-D Secure authentication for high value or high risk baskets
How can shoppers protect their own card data?
Most card theft starts with a small lapse, so a few habits matter more than any single tool. Useful steps include:
- Type a CVV only into a checkout page that loads over HTTPS and looks familiar
- Shield the code when handing a card to a cashier or reading it aloud on a call
- Ignore anyone who offers to buy your card details, since that can make you a suspect
- Read statements each month, because small test charges often come before larger ones
What should you do if your card data is misused?
Contact your card issuer right away, since consumer protection law limits your liability for unauthorized charges when you report them promptly. File a report at IdentityTheft.gov for identity theft, and send online fraud complaints to the FBI's Internet Crime Complaint Center. If you run a gift or greeting card shop and suspect a breach, tell your payment processor and acquiring bank the same day.