What Does "Sell CVV Online" Mean?

Selling CVV online means offering stolen card data for sale over the internet, often on hidden forums, invite-only chat groups, and dark web markets. The CVV is the 3- or 4-digit code printed on a credit or debit card, and sellers pair it with the card number, expiration date, cardholder name, and billing address. In the United States this is a federal crime under 18 U.S.C. § 1029, which covers fraud and related activity involving access devices.

People who type "sell cvv online" into a search bar are looking at a felony market, not a legitimate service. This guide explains what the term covers, how the trade is policed, and how cardholders and merchants shut it down. It does not explain how to buy or sell stolen card data.

What Data Gets Bundled With a CVV?

Card data almost never sells on its own. Sellers group it into packages that buyers call "fullz," a slang term for a bundle of stolen personal records.

  • Card number, expiration date, and CVV or CVC code
  • Cardholder name, billing address, and phone number
  • Sometimes a Social Security number, date of birth, or online banking login
  • Sometimes the email address and password tied to the account

A bundle with more fields carries a higher price because it answers more verification questions. Verification is also where most of these schemes fail. Banks score each card-not-present transaction against device data, shipping history, and purchase patterns, and a mismatch triggers a decline or a manual review.

How Do Card Networks Block Stolen Card Data?

Payment networks and issuers have layered defenses that make stolen card numbers hard to cash out.

  • EMV chip technology stopped cloned cards at physical terminals, which pushed fraud toward online channels.
  • Tokenization swaps the real card number for a merchant-specific token, so a stolen number fails at checkout.
  • 3-D Secure and similar step-up checks ask the buyer to verify the purchase with the bank.
  • Risk models score thousands of signals per transaction in milliseconds.
  • Real-time alerts let cardholders approve or block charges from a phone.

Chargeback liability works against sellers too. When a cardholder disputes a charge, the merchant or the payment processor takes the loss, and investigators can trace where the payout went.

What Are the Federal Penalties for Selling CVV Data?

Trafficking in card data carries prison time, fines, and court-ordered restitution. Sentences depend on the number of cards, the dollar loss, and whether the case also involves identity theft.

  • Trafficking offenses under 18 U.S.C. § 1029 carry up to 15 years in prison plus fines.
  • Aggravated identity theft under 18 U.S.C. § 1028A adds a mandatory 2-year term that runs after the main sentence.
  • Wire fraud, money laundering, and conspiracy counts stack on top of the access device charge.
  • Courts order repayment to issuers, merchants, and victims, and can seize equipment and proceeds.

State prosecutors file their own identity theft and computer crime charges. A conviction leaves a federal record that blocks many jobs, licenses, and loan applications.

Where Does Stolen Card Data Come From?

Card and personal data reaches criminal markets through a handful of repeat paths.

  1. Phishing pages and text messages that copy a bank login screen.
  2. Malware on point-of-sale systems and online checkout pages.
  3. Data breaches at retailers, hotels, and payment processors.
  4. Skimming devices on gas pumps and ATMs.
  5. Social engineering calls that talk a victim into reading a one-time code.

Verizon's annual Data Breach Investigations Report keeps phishing and the use of stolen credentials among the top ways attackers reach payment systems. Each of those paths leaves log records that federal agents use during an investigation.

How Do Investigators Trace Carding Operations?

Cases often start with a fraud report from a bank or a merchant and grow through financial records. Agents follow the payout trail, which may run through prepaid cards, crypto exchanges, and shell accounts. Undercover purchases and cooperating witnesses fill in the rest.

International cooperation matters because servers, sellers, and buyers sit in different countries. Europol, the FBI, and national police run joint takedowns that seize domains and servers.

How Do You Protect Card Data?

Consumers and merchants each hold part of the defense.

For cardholders

  • Freeze your credit file with Equifax, Experian, and TransUnion.
  • Turn on transaction alerts and review statements each month.
  • Use a mobile wallet or a virtual card number for online shops.
  • Report a lost card and any charge you do not recognize within days.

For merchants

  • Follow the PCI DSS standard, including patching and network segmentation.
  • Store no card data unless there is a business need, and never keep the CVV after authorization.
  • Turn on 3-D Secure and address verification at checkout.
  • Train staff to spot phishing and card-testing attacks on the storefront.

Where Do You Report Card Fraud?

Reports feed the cases that shut down carding operations.

  • FBI Internet Crime Complaint Center at ic3.gov
  • FTC at IdentityTheft.gov for identity theft recovery plans
  • Your card issuer, using the number on the back of the card
  • Local police for skimming and physical theft cases

FAQ

Is selling CVV data legal in any U.S. state?

No. Every state criminalizes identity theft and card fraud, and federal law covers the sale itself.

What does "fullz" mean?

It is slang for a bundle of stolen personal and financial records sold as one package.

Can a CVV alone complete a purchase?

Almost never at major retailers. Online checkouts ask for the billing address and other checks, and banks decline most mismatched attempts.

What happens to people who sell card data?

They face arrest, asset seizure, prison terms, restitution, and a permanent criminal record.