Buying a CVV from an online shop is card fraud, not a shortcut to cash. In the US, trafficking in stolen card numbers and verification codes falls under 18 U.S.C. § 1029 and carries fines plus up to 10 years in prison for a first offense. Every shop that sells itself as a place to buy CVV data is either moving stolen numbers or taking money from people it will never pay.

What a CVV shop sells

A CVV is the three-digit code on the back of most Visa, Mastercard, and Discover cards, or the four-digit code on the front of an American Express card. It exists to prove that the person typing the card number holds the physical card.

A CVV shop pairs that code with a card number, a cardholder name, an expiry date, and sometimes a billing address. The raw data comes from skimmers on gas pumps, phishing pages, fake checkout sites, and merchant breaches.

  • Card plus CVV: the minimum needed for a card-not-present charge.
  • Fullz: card data bundled with a Social Security number, date of birth, and address.
  • Dumps: magnetic stripe data used to clone a plastic card.

None of those listings come from a lawful source. Card networks do not license cardholder data for resale to third parties, and no bank authorizes a stranger to spend from an account.

Is buying a CVV illegal?

Yes. Buying card data that belongs to someone else is a federal crime in the United States. Section 1029 covers the sale, transfer, and use of unauthorized access devices, a category that includes stolen card numbers and verification codes.

State prosecutors add their own charges, often identity theft and larceny. Other countries treat the conduct the same way. The UK Fraud Act 2006 and comparable statutes across the EU and Canada cover the same acts.

  • Up to 10 years in federal prison for a first offense under § 1029.
  • Restitution to banks and cardholders, ordered at sentencing.
  • Forfeiture of computers, phones, and crypto wallets tied to the case.
  • Immigration consequences for non-citizens, since fraud can count as an aggravated felony.

Banks trace these purchases through payment rails and blockchain records. Investigators also seize shop databases, which hold buyer logs, wallet addresses, and chat histories.

Why most buyers lose money

The people who run CVV shops know their customers cannot file a complaint, so cheating them costs nothing.

  1. The shop takes crypto and never delivers the data.
  2. The cards arrive dead. Issuers kill compromised numbers within hours of a fraud alert, so purchased lists go stale fast.
  3. Checker tools charge a fee and report every card as live to keep buyers paying.
  4. The seller keeps your wallet address and returns later with a blackmail demand.

Losses run both ways. Buyers lose the money they spent, and they still face charges when the shop's records land in a case file.

What merchants should do instead

Businesses that need to accept card payments or handle card data have legal options. A PCI DSS Level 1 processor such as Stripe, Adyen, Square, or Braintree handles the card data for you and takes on most of the compliance burden.

Tokenization replaces the card number with a reference value that your systems can store and reuse. The real number never touches your database, so a breach exposes tokens instead of live cards.

PCI DSS Requirement 3.2 bans storage of sensitive authentication data after authorization. That covers the CVV, the full magnetic stripe, and the PIN block. Keeping them puts you out of compliance and makes your company the first target when a network investigates a breach.

Developers who need test data should use the sandbox card numbers that processors publish. Those numbers belong to nobody, charge nothing, and work in test environments.

How to protect your own card's CVV

  • Never read the code to someone who calls you. Banks do not ask for it.
  • Use virtual card numbers for subscriptions. Many issuers issue a fresh number per merchant.
  • Cover the code with your thumb when you photograph a card.
  • Review statements each month and dispute charges you do not recognize.

Frequently asked questions

Can you be arrested for buying a CVV?

Yes. Prosecutors charge buyers along with sellers, and shop logs often serve as the evidence. A first offense can mean years in prison, plus restitution and a criminal record that follows you through job and loan checks.

Are CVV shops on Telegram and dark web markets real?

Some hold stolen data and most take payment then vanish. Either way, the purchase is a crime, and the data is unusable without committing more offenses such as wire fraud or identity theft.

Does a VPN make buying a CVV safe?

No. A VPN hides your IP address, not the crypto payment, the shop's logs, or the delivery trail. Investigators work backward from the funds, and those records survive long after a VPN session ends.

Is it legal to give my own card's CVV to a merchant?

Yes. Sharing the code with a merchant you chose, for a purchase you authorized, is normal and legal. Selling access to a card account to a stranger for cash breaks card network rules and can count as fraud or money laundering.

What is a test card number?

A published fake number from a payment processor's sandbox. It links to no bank account, charges no one, and exists so developers can test checkout flows without touching real card data.

The bottom line

No legal version of a CVV shop exists. If a search for cv shop buy cvv brought you here, the honest answer is that the money goes to criminals and the risk stays with you. Anyone whose card data leaked should call the issuer, freeze the account, and file a report at IdentityTheft.gov.