I can't write a guide on how to sell CVV numbers to a buyer. A CVV is a security value tied to a specific payment card, and transferring it for money — whether it came from a breach, a skimmer, a phishing page, or a bulk dump — is credit card fraud, not a grey-market business. There is no "legit buyer" category for stolen card data in the United States. Below is what the law actually covers, plus the real card-industry work that pays people who understand this data.
Why the request has no legal version
Card-not-present fraud depends on three pieces of information moving together: the card number, the expiration date, and the CVV. That combination is what authorizes a charge when no physical card is present. Selling it is the sale of an access device, and US federal law treats trafficking in access devices as a standalone crime, separate from whatever theft produced the data.
- The CVV exists to prove the cardholder is holding the physical card. Selling it defeats the only control that separates a cardholder from anyone with a copy of the number.
- Buyers in these markets are usually running card testing, reshipping, or cash-out operations. Payment disputes, chargebacks, and account closures follow the data.
- There is no escrow, arbitration, or consumer protection in that market. Participants are defrauding each other as often as they defraud merchants.
What US law covers
18 U.S.C. § 1029 addresses fraud and related activity in connection with access devices. It criminalizes producing, trafficking in, and using unauthorized access devices, and it applies to card numbers, account credentials, and the security values attached to them. Statutory maximums run from 10 to 15 years depending on the specific subsection, the number of devices involved, and the value of the loss. State laws add their own charges, and civil liability to issuers and merchants is separate from any criminal case.
Practical point: prosecutors do not need to prove you used a card. Offering card data for sale is enough.
Legitimate roles that use the same knowledge
People who understand how CVV checks, authorization flows, and card testing work are genuinely in demand — on the defending side.
- Fraud and risk analyst. Rules and models that flag card-testing patterns, velocity anomalies, and mismatched billing data before charges settle.
- Chargeback and disputes specialist. Works with issuers on representment and reason codes.
- Payments engineer. Builds tokenization, 3-D Secure flows, and authorization logic for processors and merchants.
- PCI compliance and security assessment. Audits whether a merchant stores sensitive authentication data it should never hold.
- Trust and safety at a platform. Investigates accounts moving stolen payment methods through marketplaces.
If you handle card data as a merchant
The PCI Data Security Standard prohibits storing sensitive authentication data — the full track data, the CVV, and the PIN block — after authorization, even in encrypted form. Merchants that need repeat billing use network tokens or a processor vault, not a stored CVV. If you are building checkout, the correct flow is to pass the CVV to your processor for a single authorization and never persist it. That single rule removes most of the exposure that makes dumps valuable in the first place.
If you are being recruited into this
Offers to "cash out" cards, run test charges, or reship goods are the entry point for a federal case that names everyone in the chain. Report solicitation to the FBI's Internet Crime Complaint Center or the FTC, and to your bank's fraud line if your own card data is involved.