What a CVV attack alert means

A CVV attack alert is a notice from a bank, card network, or payment processor. It says someone tried to use your card number with the 3-digit or 4-digit security code printed on the card. The attempt happened without the physical card. No charge may show on your statement.

read more

The alert is a signal, not a receipt. It means a merchant asked the issuer to check the card number, the expiration date, and the code. The issuer declined the check, or let it pass and flagged the pattern.

cvv breach alert

What triggers the alert

  • Several merchants receive the same card number and code in a short window.
  • The billing address does not match the address on file. This is an AVS mismatch.
  • Orders come from an IP address far from the cardholder's home.
  • Test charges of $1 or less run before a large charge.
  • The card number shows up in a batch tied to a known breach.

CVV, CVV2, CVC2, and CID

The 3-digit code on the back of Visa, Mastercard, and Discover cards is CVV2 or CVC2. American Express prints a 4-digit CID on the front. The code sits outside the magnetic stripe and the EMV chip, so a skimmer at a gas pump does not get it. PCI DSS prohibits merchants from storing the code after a transaction is authorized. A breach that exposes the card number alone does not hand an attacker the code.

cvv attack warning

Steps to take in the first hour

  1. Open the bank app and read the pending charges.
  2. Call the number on the back of the card. Do not call a number from the alert text.
  3. Ask the agent to lock the card and open a fraud case. Write down the case number.
  4. Change the password on the card account and on any account that shares that password.
  5. File a report at IdentityTheft.gov if the issuer confirms fraud.

What not to do

  • Do not reply to the text with the code or your PIN.
  • Do not open links in the alert. Banks send alerts to the app or a short code that asks for no credentials.
  • Do not pay a verification fee. No US issuer charges one.

Liability limits

Under the Fair Credit Billing Act, liability for unauthorized credit card charges caps at $50. You must dispute the charge in writing within 60 days of the statement date. Debit cards fall under Regulation E: $50 if you report within 2 business days, $500 if you report within 60 days, and no cap after that.

CVV Security Breach Alert: What You Need to Know

Prevention

  • Turn on transaction alerts for every charge.
  • Use a digital wallet. Apple Pay, Google Pay, and Samsung Pay send a token, not the card number or the code.
  • Use a virtual card number for online merchants. Set a spend limit and a single-merchant lock.
  • Freeze the card in the bank app when it is not in use.
  • Keep the card in sight at a restaurant.

Reissue or monitor

If the issuer confirms the code was used, ask for a new card number and a new code. A reissue takes 5 to 10 business days in the US. If the attempt was declined, the issuer may keep the card open and watch the account. Ask which path the bank chose and note the date.