Selling CVV data on the darknet means offering stolen card numbers, expiration dates, and security codes to buyers on hidden marketplaces, paid for in cryptocurrency. In the United States it is a federal crime under access device fraud (18 U.S.C. § 1029), wire fraud (18 U.S.C. § 1343), and aggravated identity theft (18 U.S.C. § 1028A). Sentences run from probation to 20 years in prison, plus restitution to banks and forfeiture of the crypto earned.

more on this topic

The sections below explain what a CVV listing holds, how the marketplaces operate, why the data goes stale fast, and how card issuers shut the trade down.

sell cvv data to trusted buyers

What data does a CVV listing include?

CVV stands for card verification value, the three or four digit code printed on a payment card. When a seller lists "CVV data," the listing holds enough detail to charge that card in a card-not-present transaction.

related article

  • PAN: the full card number and expiration date
  • CVV2 or CVC2: the code that proves the buyer holds the physical card
  • Cardholder details: name, billing address, ZIP code, and often the bank name
  • Fullz: a bundle that adds date of birth, SSN, or account logins

Sellers sort listings by issuing bank, country, and card brand, because a card from a bank with weak fraud checks draws higher bids. Fullz cost more than bare numbers since the extra fields help a buyer pass address verification.

related article

How do darknet card markets work?

Darknet card markets run on Tor and copy the layout of a normal retail site: vendor profiles, buyer reviews, escrow, and dispute pages. Payment arrives in bitcoin or a privacy coin, and escrow holds the funds until the buyer confirms the card charges.

Supply comes from skimming devices on gas pumps and ATMs, point-of-sale malware, phishing pages, and breaches at merchants and processors. The vendor on the marketplace often did not steal the data. Card records move from breach to broker to reseller before anyone lists them.

Law enforcement has closed several of these sites. AlphaBay and Hansa were seized in 2017. Joker's Stash, a card shop that ran for years, went offline in 2021.

Is selling CVV data a federal crime in the US?

Yes. Federal law treats a card number as an "access device," and trafficking in access devices is a felony even when the seller never uses the card.

  • 18 U.S.C. § 1029 (access device fraud): up to 10 years for a first offense, 15 for a second, 20 for a third
  • 18 U.S.C. § 1028A (aggravated identity theft): a mandatory 2 year term that stacks on top of other sentences
  • 18 U.S.C. § 1343 (wire fraud): up to 20 years when the internet or interstate wires carry the scheme
  • 18 U.S.C. § 1028 and § 1341: extra counts for identity documents and mail fraud

Courts also order restitution to banks and cardholders, and prosecutors seize wallets, servers, and domain names tied to the operation. Charges stack, so one listing can produce several counts.

What happens to people who get caught?

The Department of Justice has charged card traffickers in large sweeps. The Infraud Organization case in 2018 named 36 defendants. Operation DisrupTor in 2020 led to 179 arrests across several countries.

Investigators trace sellers through blockchain analysis, seized market servers that hold chat logs and vendor accounts, and cooperating witnesses. Undercover buys on a market build a payment trail that runs straight back to a wallet.

Why stolen card data loses value fast

Issuers reissue a card as soon as fraud appears, which kills every listing tied to that number. A stolen card can go from valid to dead in a matter of days.

Banks also watch traffic patterns. A card with no online history that charges a $900 electronics order from a new device draws a decline or a step-up authentication prompt. Chargebacks then reverse the sale for the merchant or money mule who cashed out.

How do card networks detect stolen CVVs?

  • CVV mismatch at authorization, which fails the charge
  • Address Verification Service mismatches on ZIP and street number
  • Velocity checks on IP address, device fingerprint, and card BIN range
  • 3-D Secure step-up, which sends the transaction back to the bank for approval
  • Cardholder disputes, which trigger reissue and a fraud report to the issuer

The PCI Security Standards Council bars merchants from storing the CVV once a transaction is authorized. That rule exists to keep the code out of databases attackers can breach.

Frequently asked questions

Can someone sell CVV data without getting caught?

No method makes it safe. A hidden marketplace still runs on a fixed internet address that investigators can seize, and crypto payments leave a permanent ledger. Sellers in past cases were identified years after a market closed, when seized databases were analyzed.

How much does stolen card data sell for?

Public reporting puts most single card listings in the low single digit dollar range, with fullz bundles in the tens of dollars. Those prices reflect a market where plenty of listings are already dead or fake. A buyer who pays for a CVV has no legal recourse when the card declines.

Is it ever legal to handle card verification values?

Yes, in a narrow setting. Payment processors and issuers handle CVV data as part of authorization, under PCI DSS controls. Merchants may transmit the code with a transaction but cannot store it afterward. Trading that data outside the payment chain is a crime.

What should a cardholder do after fraud?

Contact the issuing bank, which will freeze the card and send a new number. Report the identity theft at IdentityTheft.gov, then place a fraud alert or credit freeze with the three credit bureaus. A police report helps if the bank disputes the claim or the thief opened new accounts in your name.

What the trade means for ordinary cardholders

Card data theft is a volume business, and the result for most people is a reissued card and a few hours of paperwork. Banks absorb the loss under zero liability policies, then pass the cost back through merchant fees. The seller carries the legal risk, and the buyer carries the risk of a dead card. Neither side of the darknet CVV trade can enforce a deal.