CVV fraud indicators are the observable signs that a card-not-present transaction may be using a stolen card number, a mismatched security code, or a taken-over account. The strongest indicators rarely appear alone. One CVV mismatch can be a typo. A CVV mismatch paired with a billing address mismatch, a new device, and overnight shipping to a different address forms a pattern that points to fraud.
What a CVV Check Does and Does Not Prove
The CVV is a 3-digit value on the back of most cards and 4 digits on American Express. It is not stored in the magnetic stripe or chip data. When a merchant submits it with an authorization request, the issuer returns one of three results: match, no match, or not processed. A no-match result means whoever entered the order did not have the physical card and did not have the issuer's record of the code.
A match proves less than it appears to. Data from a breach, a skimmer, or a compromised merchant can include the CVV along with the full card number, so a match does not establish that the cardholder authorized the purchase.
Transaction-Level Indicators
- CVV response of no match or not processed, especially repeated across attempts.
- AVS mismatch on the billing street number or ZIP code while the CVV matches.
- Several card numbers submitted for one order or within one session.
- An order value far above the customer's normal range on a new account.
- Multiple declines on one card followed by an approval on another.
Card-Testing Indicators
Fraud rings test stolen numbers before using them for large purchases. Watch for many authorization attempts under a few dollars in a short window, card numbers that arrive in sequence or fit a generated pattern, and a high decline rate from one device or IP address followed by a single approval.
Device and Session Indicators
- One device fingerprint tied to many card numbers or many accounts.
- IP geolocation far from the billing address, or traffic through a proxy, VPN, or Tor exit node.
- A new account that places a high-value order within minutes of creation.
- Browser language, time zone, and shipping country that do not match the card's issuing country.
Fulfillment and Behavioral Indicators
- Expedited shipping to an address that differs from the billing address.
- Delivery to a freight forwarder, parcel locker, or vacant property.
- Orders for resalable goods: electronics, gift cards, luxury items, or digital codes.
- A customer who supplies contact details that do not match the cardholder record.
Review Steps for a Suspected Order
- Place the order on hold and stop fulfillment until the review closes.
- Pull the CVV and AVS response codes from the authorization record and compare them to the order data.
- Call the customer at a number already on file from a prior order, not a number supplied in the suspect order.
- Request a step-up authentication challenge through the issuer's 3-D Secure service.
- Record the response codes, the contact attempt, and the outcome in the order notes.
- If the order is confirmed fraudulent, report it to your acquirer and add the device, address, and card fingerprint to your block list.
Steps for Consumers After a Suspected Compromise
- Freeze the card in the issuer's app or call the number on the back of the card.
- Review statements and transaction alerts for charges you do not recognize, including small test amounts.
- Report the fraud to the card issuer and request a replacement card with a new number.
- File a report with the FTC and, if money was lost, with your local police.