Short answer
No. Selling CVV data online is a federal crime in the United States. A card verification value is an access device under 18 U.S.C. § 1029. Selling, buying, or passing one without the cardholder's consent is trafficking in an unauthorized access device. There is no licensed broker, no legal marketplace, and no safe method. Both the seller and the buyer commit a crime.
What a CVV is
The CVV is a short code printed on a payment card. Visa, Mastercard, and Discover use a 3-digit code on the back. American Express uses a 4-digit code on the front. The code exists to prove the person entering the card number holds the physical card. Card issuers treat the CVV as sensitive authentication data, separate from the account number.
Real CVV Selling or Scam? The Honest Answer
Federal law
18 U.S.C. § 1029 covers fraud and related activity in connection with access devices. Subsection (a)(3) bans trafficking in counterfeit access devices. Subsection (a)(2) bans trafficking in unauthorized access devices. A stolen CVV paired with a card number falls under both. Prosecutors add 18 U.S.C. § 1028A for aggravated identity theft when the data belongs to a real person, and 18 U.S.C. § 1343 for wire fraud when the sale crosses state lines or uses the internet. Conspiracy charges under 18 U.S.C. § 371 apply to group operations.
how to tell if selling cvv online is legit
Penalties
- Up to 10 years in federal prison for a first offense under § 1029, and up to 15 years for a later offense.
- Fines up to $250,000 for an individual under 18 U.S.C. § 3571.
- A mandatory 2-year sentence for aggravated identity theft under § 1028A. That term runs consecutive to any other sentence.
- Restitution to banks and cardholders for losses tied to each card.
Sentences stack. A single case can produce charges under § 1029, § 1028A, § 1343, and § 371 at the same time.
Selling CVV Online: Real or Fake?
Why card networks detect it
Issuers run authorization checks on every transaction. A card used in two distant locations within a short window triggers a block. Banks share fraud data through industry groups. Federal agents buy from carding forums during investigations, then trace payments through crypto exchanges and mail records. Payment processors file suspicious activity reports with the Treasury Department's Financial Crimes Enforcement Network.
Storage rules
PCI DSS, the payment card industry data security standard, bars merchants and processors from storing the CVV after a transaction is authorized. A database full of CVV codes is by definition out of compliance and of unknown origin. Merchants that store the code lose their ability to process cards.
What is legal
Merchants accept card payments through a bank or a licensed payment processor. Those accounts handle authorization, settlement, and chargebacks. Card data stays with the processor. No legal business model involves trading card codes between private parties. If a person wants to work in payments, the paths are merchant services, fraud analysis, or compliance, all of which require an employer and a background check.