What Is a CVV Dump?
A CVV dump is a record of stolen payment card data taken from a card's magnetic stripe or chip and traded through underground fraud markets. The word "dump" refers to the raw data copied off the card, while CVV is the card verification value tied to that account. Buying, selling, or using one is a federal crime in the United States and a criminal offense in most other countries.
This guide explains what the data contains, how it gets used, and what cardholders and merchants can do about it.
What Data Does a CVV Dump Contain?
Contents vary by source. Data skimmed at a fuel pump looks different from data pulled out of a merchant database breach.
- Primary account number (the 15 or 16 digit card number)
- Expiration date
- CVV or CVC value
- Cardholder name, when available
- Track 1 or Track 2 data encoded on the stripe
- Bank identification number (BIN), which identifies the issuing bank
- Billing ZIP code or address, in more complete records
Track Data vs. Fullz
Track data is the string of characters encoded on the magnetic stripe, and it is what a cloning device needs to write a working copy of a card. "Fullz" is slang for a wider record that adds the cardholder's name, address, phone number, and sometimes a Social Security number or date of birth. Both types get traded in the same channels, and neither gives a buyer any legal right to use the account.
How Stolen Card Data Turns Into Fraud
Card-Not-Present Fraud
Someone places an online or phone order using the stolen number, expiration date, and CVV. The merchant never sees a physical card and cannot check a signature, which is why card-not-present fraud is the most common use of leaked card data. Orders often ship to a drop address and get resold before the chargeback lands.
Card Cloning
Track data gets written onto a blank magnetic stripe card with a writer device, producing a physical copy. That copy works at terminals and ATMs that still read the stripe. Chip-enabled terminals block this attack because the chip cryptogram cannot be copied from a stripe read.
Where Does the Data Come From?
- Skimming devices attached to gas pumps, ATMs, and self-checkout lanes
- Point-of-sale malware that captures card data in memory
- Breaches at merchants, hotels, and payment processors
- Phishing pages and fake checkout screens
- Data from older breaches that gets resold and repackaged
Stolen data does not age well. Banks cancel exposed card numbers, which is why fraud markets sell freshly stolen records at higher prices than older ones.
Is Buying or Selling a CVV Dump Legal?
No. Trading stolen card data violates federal law and state law, and prosecutors treat it as a serious offense.
- Access device fraud under 18 U.S.C. § 1029 covers producing, selling, or using stolen card credentials
- Identity theft statutes under 18 U.S.C. § 1028 apply when someone's personal data is used without consent
- Wire fraud and money laundering charges often follow when payments move across state or national lines
- State laws add their own penalties, and sentences can stack across charges
Penalties include prison time, fines, and restitution to the banks and merchants that absorb the losses. Banks also pursue civil claims against people who cash out stolen funds.
How Cardholders Protect Themselves
- Use the chip or contactless tap instead of swiping whenever a terminal allows it
- Review statements and set transaction alerts in your banking app
- Use virtual card numbers for online subscriptions and unfamiliar sites
- Pull on the card reader before you use a pump or ATM, and wiggle the slot to check for added hardware
- Choose ATMs inside bank branches when possible
- Freeze your credit with all three bureaus if you suspect wider identity theft
How Merchants Reduce Risk
- Follow PCI DSS requirements for storing, processing, and transmitting card data
- Tokenize card numbers so your systems never hold the real value
- Require the CVV and verify the billing address on every card-not-present order
- Enable 3-D Secure or an equivalent authentication step at checkout
- Watch for velocity patterns, such as many orders on one card in a short window
- Match shipping address to billing address for high-value items
What to Do If Your Card Data Leaks
- Call the number on the back of your card and ask for a replacement card with a new number.
- Dispute every charge you did not make. The Fair Credit Billing Act limits your liability for unauthorized credit card charges.
- Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion.
- Report the incident at IdentityTheft.gov, which builds a recovery plan and an official record.
- File a police report if the fraud involves a large sum or a stolen identity.
Frequently Asked Questions
What is the difference between a CVV and a CVV dump?
The CVV is a three or four digit security code printed on a single card. A dump is a bundle of stolen card records copied from many cards, sold as a batch. One is a security feature; the other is stolen property.
Do CVV dumps work for online purchases?
Most fail. Merchants that require the printed CVV, check the billing address, and run 3-D Secure block orders placed with leaked data. Cloned cards also fail at chip-enabled terminals, since the terminal generates a fresh cryptogram the copied stripe cannot produce.
How much does stolen card data sell for?
Prices move with the market and depend on the issuing bank, the cardholder's country, and whether the account has a high available balance. Values change as banks tighten controls and as new breaches flood the supply.
Can you tell if your card data is being sold?
You cannot monitor fraud markets yourself, and there is no consumer tool that reports it. The practical signal is your account activity: unexpected charges, a card that gets declined, or a breach notice from a company you buy from.
Is using a CVV dump ever legal?
No. There is no lawful use for stolen card credentials, even if the buyer never keeps the goods. Possession with intent to use is enough for a charge under federal access device law.
The Bottom Line
A CVV dump is stolen financial data, and the market around it exists because card fraud still pays. Chip technology, tokenization, and address verification have closed many of the old gaps, but skimming and database breaches keep the supply alive. The best defense for cardholders is fast detection, and for merchants it is keeping card data out of their systems in the first place.