Why I declined this request

The brief asks for an informational guide about credit card check utilities for a site whose stated niche is selling CVV data. A CVV is the three or four digit verification code printed on a payment card. That code is not a product. It is part of a payment credential. Card checking utilities exist to test card numbers against payment gateways, including numbers the operator does not own. A guide that supports that market would help people commit payment card fraud, so I did not write it.

related article

What follows is factual background on the tools, the law, and the honest checks that merchants run.

Credit Card Testing Service Guide

What a card checking utility does

A checking tool sends a card number, expiry date, and verification code to a payment endpoint and reads the response. Some run a zero dollar authorization. Some run a small charge and then void it. The goal is to sort live accounts from dead ones. Legitimate cardholder verification does not need this step, because the merchant already holds a merchant account and the customer already holds the card.

credit card validation tool

Legal exposure in the United States

18 U.S.C. § 1029 covers fraud and related activity in connection with access devices. Trafficking in unauthorized access devices, including card account numbers, carries a statutory maximum of 10 years for a first offense. The maximum rises to 15 years when the offense involves 15 or more devices within a one year period or when the value obtained exceeds $1,000. Sentences depend on the amount of loss, the number of victims, and prior record.

read more

Card network rules add a second layer. PCI DSS Requirement 3 prohibits storage of sensitive authentication data, including the full track data, the card verification code, and the PIN block, after authorization. A database of CVV values is out of compliance by design, not by accident.

Checks merchants actually run

  • Luhn checksum on the card number, which catches typos and random digits.
  • Address Verification Service, which compares the billing street number and ZIP code to issuer records.
  • CVV verification at the moment of authorization. The merchant sees a pass or fail result and never stores the code.
  • 3-D Secure, which routes the cardholder to the issuer for a challenge.
  • Velocity and device rules inside a fraud engine, which flag repeated declines from one address.

Every item on that list runs inside a payment gateway under a merchant agreement. None of them requires buying card data from a third party.

Numbers I cannot give you

I have no reliable figure for the size of the stolen card market, the share of checks that succeed, or the price per record. Published estimates vary by an order of magnitude and depend on definitions. I will not invent one.

Topics I can write about

PCI DSS scope reduction, chargeback ratios, gateway decline codes, tokenization, fraud scoring, and payment authorization flow. Those subjects serve merchants and processors. They do not serve the purchase of CVV data.