CVV enumeration is the automated, unlawful practice of submitting large batches of payment card numbers with guessed three or four digit security codes to find combinations an issuer will approve. It is a form of carding fraud, not a research method, and every major card network treats the traffic pattern as an attack signature. The sections below explain what the activity is, why it fails in practice, how banks detect it, and what the legal exposure looks like in the United States.

What is CVV enumeration?

CVV enumeration, sometimes called a card enumeration attack or BIN attack, is an attempt to validate stolen or randomly generated card numbers by brute forcing the card verification value. Because the CVV is only three or four digits, an attacker assumes that enough attempts against enough card numbers will eventually produce approvals.

The defining feature is volume. A single card gets a handful of tries, while thousands of cards get a few tries each, which is what separates enumeration from ordinary failed checkouts.

Why does CVV enumeration usually fail?

Payment systems were rebuilt around this exact pattern over the past decade, and the defenses are layered rather than optional.

  • Rate limits and velocity checks. Issuers and gateways cap authorization attempts per card, per merchant, and per IP address within short windows.
  • The CVV cannot be stored. PCI DSS prohibits retaining the verification code after authorization, so a leaked database rarely contains it.
  • Address and ZIP verification. AVS checks compare billing data, and mismatches trigger declines before the CVV even matters.
  • 3D Secure authentication. Step-up challenges push the cardholder into an authentication step that a script cannot complete.
  • Machine learning scoring. Networks score authorization traffic in real time and flag low value, high volume patterns instantly.

The practical result is that most enumeration traffic produces declines, and the declined attempts are what generate the evidence trail.

How do banks and processors detect card enumeration?

Detection relies on behavioral signals rather than on any single transaction. A burst of small authorizations across many cards from one merchant account, a decline rate far above normal, or sequential card numbers appearing in the same hour are all strong indicators.

Once a pattern is confirmed, the response is usually immediate. Gateway accounts are frozen, IP ranges are blocked, and the incident is reported to the card networks, which can pass the case to law enforcement.

What are the legal penalties for carding in the US?

Access device fraud is prosecuted under 18 U.S.C. Section 1029, which covers producing, selling, and using counterfeit or unauthorized payment cards. Penalties scale with the value of the fraud and prior offenses, and sentences of ten years or more are common in aggravated cases.

Related charges frequently stack on top of that count. Wire fraud, identity theft, money laundering, and conspiracy charges often accompany a single carding operation, and each carries its own exposure.

How can merchants and cardholders reduce risk?

Merchants should enforce attempt limits per card and per session, require 3D Secure on high risk orders, and monitor decline ratios daily. Cardholders should review statements for small test charges, since those often precede a larger fraudulent purchase.

Enabling transaction alerts and freezing a card through the issuer app remains the fastest way to stop an active attack.

Is buying CVV or fullz data legal?

No. Purchasing, selling, or possessing stolen card data is a federal crime in the United States regardless of whether the buyer intends to use it. Buyers also become targets, because carding markets are heavily monitored by law enforcement and by the criminal groups that run them.

Does CVV enumeration ever succeed at scale?

Not against modern issuers. Approval rates on enumerated traffic are extremely low, and the accounts and infrastructure behind the attempts are typically identified within hours. The cost of the fraud falls on merchants, issuers, and cardholders, which is why the networks invest heavily in blocking it.