Stolen CVV data is traded on hidden, Tor-based carding forums and invite-only marketplaces, and every one of those venues is illegal to operate, use, or profit from. There is no lawful place to sell a CVV that does not belong to you. Asking where to sell CVV on the dark web is effectively asking how to commit payment card fraud, which is a federal crime in the United States and a serious offense in most other countries.

What a CVV actually is

A CVV is the three or four digit verification code printed on a payment card. It exists to prove that whoever is using the card number physically has the card in hand. When a criminal operation obtains a card number, expiration date, and CVV together, it has what the industry calls full card data, which is far more valuable than a number alone because it can be used for card-not-present transactions.

That is also why the code is treated as sensitive financial data under the same laws that cover account numbers and passwords.

Why there is no legal place to sell CVV data

Card data belongs to the person named on the account and to the issuing bank. Transferring it without authorization is theft, and selling it is trafficking in stolen financial credentials. The marketplaces that host this trade are not anonymous safe havens. They are criminal enterprises that law enforcement agencies investigate, infiltrate, and seize.

  • Sellers are typically charged with access device fraud, identity theft, or conspiracy.
  • Buyers face the same exposure, since purchasing stolen card data is also a crime.
  • Marketplace operators face additional charges for running a criminal operation and, often, money laundering.
  • Participants frequently rob each other, since there is no court or contract to enforce a deal between criminals.

How card data reaches underground markets

CVV data usually does not leak by accident. It is harvested through methods that security researchers and banks track closely:

  • Phishing pages and fake checkout screens that capture card details directly.
  • Skimming devices and malicious scripts placed on point-of-sale terminals or compromised websites.
  • Data breaches at merchants, processors, or service providers.
  • Social engineering calls that convince a cardholder or employee to read out card details.

Each of these methods leaves a trail. Investigations often begin with a single victim report and expand through payment network records, IP logs, and seized devices.

What the law says

In the United States, 18 U.S.C. § 1029 criminalizes the production, sale, and use of counterfeit or unauthorized access devices, a category that includes stolen card numbers and CVVs. Depending on the specific provision, a conviction can carry a statutory maximum of 10 or 15 years in prison plus fines. When a stolen identity is used during the offense, 18 U.S.C. § 1028A can add a mandatory consecutive sentence on top of the underlying fraud charge.

State prosecutors also bring charges for theft, forgery, and identity fraud. A single card sale can trigger cases in multiple jurisdictions.

How these marketplaces get shut down

Carding markets are priority targets for the FBI, the U.S. Secret Service, the Department of Justice, and their international partners. Typical tactics include undercover purchases, server seizures, domain takedowns, and arrests of administrators who are then used to map out buyers and sellers. Takedowns tend to arrive without warning, which is one reason participants in these forums constantly migrate and distrust each other.

If someone offers to sell you CVV data

Buying is not a shortcut or a victimless transaction. It funds organized crime, and the seller is often running a scam that takes your payment and delivers nothing. The safe and lawful response is to refuse and report it.

  • Report the solicitation to the FBI's Internet Crime Complaint Center.
  • Forward phishing messages to the impersonated bank or retailer.
  • Do not send money, gift cards, or cryptocurrency to anyone making this offer.

Protecting your own card data

  • Use virtual or single-merchant card numbers for online purchases when your bank offers them.
  • Turn on transaction alerts so unusual charges surface within minutes.
  • Check statements and your credit report on a regular schedule.
  • Shop only on sites with a verified checkout, and avoid saving card details in browsers you do not control.
  • Cover the keypad at terminals and never read card details aloud to an unsolicited caller.

If your card data was exposed

  1. Call the issuer using the number on the back of your card and request a freeze or replacement.
  2. Dispute unauthorized charges in writing and keep copies of everything.
  3. Place a fraud alert or credit freeze with the major credit bureaus.
  4. File a report with the FTC and, for financial loss, with the IC3.

Acting quickly limits your liability and gives investigators the records they need to trace the stolen data back to whoever tried to sell it.