A CVV dump is a batch of stolen payment card records sold or traded online, and each record pairs a card number and expiry date with the card's security code (the CVV, CVC, or CVV2). The security code is the piece that lets a thief charge a card on a website where no physical card appears. That is why dumps sell for more than card numbers alone.
What data sits inside a CVV dump?
A dump holds many cards at once. Sellers bundle hundreds or thousands of records and sort them by country, card brand, or bank.
- Card number and expiry date
- CVV, CVC, or CVV2 security code
- Cardholder name, billing address, and ZIP code on the fuller records
- Bank name, card type (credit or debit), and country of issue
- Magnetic stripe track data on cards skimmed at a terminal
Records with a full address fetch the highest prices because they pass address verification checks on some checkouts. Many listings also note the bank and card type, which makes the records simple to sort.
Why does the security code matter more than the card number?
Online checkouts ask for the code to prove the buyer holds the physical card. A stolen card number without that code fails many checkouts at the first step. With the code attached, an order can pass a basic check, though 3-D Secure challenges, address checks, and velocity limits still block plenty of attempts.
How do CVV dumps affect greeting card and gift shops?
Card and gift shops sit in a risky spot. Orders are small, ship fast, and go to addresses that are easy to change, which makes the sector a common target for card-not-present fraud.
Fraud rings test stolen cards on low-cost items first. A $6 greeting card or a $25 gift box is a cheap way to confirm a card still works before a larger order follows.
Chargebacks land on the merchant. The shop loses the goods, the shipping cost, and a chargeback fee, and repeat fraud can push processing rates up or put a merchant account at risk.
Gift card draining is a related problem
Tampered gift cards are a separate scam that hits gift shops hard. A thief copies the card number and PIN from a rack, then waits for a customer to load value onto it. The balance vanishes before the recipient ever spends it.
How do you know if your card turned up in a dump?
- A small charge you do not recognize, often a few cents or a few dollars
- A card replacement you did not request
- A breach notice from a store where you shopped
- A fraud alert from your bank or a monitoring service
- Orders or shipping confirmations you never placed
Banks spot these patterns first because they see the test charges. The tiny charge is a probe, and a larger charge tends to follow within days.
What should you do if your card is exposed?
- Call the number on the back of your card and ask for a freeze or a new card number.
- Dispute every charge you do not recognize, in writing if the bank asks.
- Change the password on your bank and shopping accounts, and turn on two-factor sign-in.
- Check your other cards and accounts for the same pattern.
- Report the theft at IdentityTheft.gov and, if money was lost, file a complaint with the FBI's IC3.
Act on the same day you notice it. Card networks limit your liability when you report fraud fast, and slow reports can leave you covering part of the loss.
How can you shop for gifts without feeding the problem?
- Use a virtual card number from your bank for online gift orders.
- Keep one card for online use and leave the rest at home.
- Turn on transaction alerts for every charge over a small amount.
- Skip saving card details in store accounts.
- Buy gift cards from behind the counter or a locked case, and check that the PIN strip is intact.
- Check a shop's return policy and contact details before you enter card data on a new site.
None of these steps is perfect on its own. Stacked together they shrink the window a thief has to work with.
Is buying or selling a CVV dump legal?
No. Selling, buying, or using stolen card data is a crime in the United States and in most other countries, covered by laws on identity theft, access device fraud, and wire fraud. Penalties include prison time and fines, and a single record can support charges.
Possession with intent to use is enough in many jurisdictions. There is no legal market for this data, whatever a seller claims.
Common questions about CVV dumps
Are CVV, CVC, and CVV2 the same thing?
They are the same security code under different brand names. Visa prints CVV2, Mastercard prints CVC2, and American Express uses a four-digit CID on the front of the card.
Does a CVV dump include a card PIN?
PINs are not printed on cards, so they are not part of a standard dump. Skimmed stripe data is the exception, and that data can be used to clone a card for use at a terminal.
Can a dump be stopped before it is used?
Not at the dump stage, because the data is already out. Freezing the card, issuing a new number, and watching your statements is what limits the damage.
Why do gift shops get targeted?
Low order values, fast shipping, and gift card inventory create easy paths to convert stolen card data into cash. That mix draws fraud attempts to the sector year round, and it spikes during holidays.