Short answer
There is no legitimate way to sell CVV numbers. A CVV is a card security code that belongs to the cardholder and the issuing bank. Selling, buying, sharing, or storing it after a transaction is fraud under card network rules and criminal law in the United States, the United Kingdom, Canada, the EU, and most other markets. If someone asked you to sell CVV data, or offered to sell it to you, treat it as a crime in progress and report it.
What a CVV actually is
The card verification value is the three digit code printed on the back of most Visa, Mastercard, and Discover cards, or the four digit code on the front of American Express cards. It exists to prove the person paying holds the physical card. Card networks classify it as sensitive authentication data. It is not a product, not a marketing asset, and not something a business can own.
What the CVV is used for
The code confirms a card is present during a card not present sale, such as an online order for a birthday card and a gift box. The issuer checks the code, approves or declines the payment, and the code should then be discarded.
Why selling CVV data is illegal
- Card network rules: the PCI Data Security Standard prohibits storing sensitive authentication data, including the CVV, after authorization. Selling it is a far more serious breach of the same rule.
- Criminal law: trafficking in payment card data is prosecuted as fraud, identity theft, and unauthorized access to a computer system. Penalties include prison time and heavy fines.
- Business consequences: a merchant caught trading card data can lose the right to accept cards, face chargeback penalties, and be dropped by its acquirer.
What merchants may do with a CVV
- Collect it once, on a secure checkout page, to verify the payment.
- Pass it to the payment processor for a single authorization.
- Keep a record that a CVV check happened, such as an approval or decline result.
- Never print it on a receipt, log it, email it, or store it in a database.
If someone offers to sell you CVV data
- Do not reply to the message or send any payment.
- Save the message, sender address, and any account details.
- Report it to the FBI Internet Crime Complaint Center through its online form.
- Notify your payment processor or acquirer the same day.
- Warn your staff so nobody clicks a related offer.
Steps to keep a greeting card or gift shop compliant
- Use a hosted payment page or tokenized checkout so raw card data never reaches your own server.
- Configure your gateway to reject any saved field for the CVV.
- Complete the PCI DSS self assessment questionnaire that matches your sales volume each year.
- Train everyone who handles orders to never write a CVV on paper or in a note field.
- Review payment logs and staff access quarterly, and remove accounts for former employees.
Compliant checkout protects your customers, your reputation, and your ability to keep selling cards and gifts online.