Short answer

A "CVV shop" is a storefront that resells card verification values and matching card details taken from other people's accounts. Writing a buying guide for that would mean writing instructions for payment card fraud, so I'm not going to produce one. What I can do is explain the term plainly and point to the legitimate routes that exist for the situations people usually arrive from.

What a CVV actually is

The card verification value is the three or four digit code printed on a payment card, separate from the account number and the expiration date. It exists to prove the physical card was present when a transaction is made remotely. Card networks and the PCI Data Security Standard treat it as sensitive authentication data: merchants are not permitted to store it after authorization, precisely because it is the piece that makes a stolen card number usable online.

Why buying one is a criminal act, not a workaround

  • In the United States, trafficking in stolen account numbers and access devices falls under federal access device fraud statutes, and prosecutions do not require the buyer to have physically stolen anything.
  • Shops selling this data are themselves frequently scams. Buyers hand over cryptocurrency and receive nothing, or receive data that has already been burned and is flagged by every risk engine.
  • Buyers who do receive working data leave a payment trail tied to their own wallet, device, and network, which is what investigators use to build a case.

Legitimate situations people confuse with this search

You think your own card was compromised

Call the number on the back of the card and ask for the fraud line. Under US federal law your liability for unauthorized charges is capped, and issuers generally remove them. Then file a report so there is a paper trail if the same data is used again.

You are a merchant losing disputes

The answer is not to source card data; it is to bring your checkout into PCI DSS scope, enable the address and CVV verification tools your processor offers, and stop storing sensitive authentication data at all.

You are researching fraud for a legitimate reason

Academic and industry researchers get this data through sanctioned channels and closed fraud intelligence programs, not open shops. That path exists and it is documented.

Where to go instead

Report card and identity fraud to the FTC, and report internet-enabled card fraud to the FBI's Internet Crime Complaint Center. If you are a merchant, the PCI Security Standards Council publishes the requirements that govern CVV handling.