What information is needed from every CVV buyer comes down to five data points: the card number, the expiration date, the CVV security code, the cardholder name, and the billing address on file with the card issuer. A legitimate merchant collects those items at checkout, passes them to a payment processor for authorization, and does not keep the security code afterward. Outside of a real card-not-present purchase, buying or selling CVV data is a federal crime in the United States, so the only lawful way to answer this question is from the merchant and processor side of a genuine transaction.

essential things to know before buying cvv online

The five fields every card-not-present checkout requires

Card-not-present (CNP) covers any sale where the card is not physically swiped or tapped: online stores, phone orders, subscription billing, and in-app purchases. Each of those channels asks the buyer for the same core set of details.

more on this topic

  • Card number (PAN). The 15 or 16 digit primary account number that identifies the issuer and the account.
  • Expiration date. Month and year, used to confirm the card is still active.
  • CVV, CVC, or CVV2. The three digit code on the back of most cards, or the four digit code on the front of American Express cards. It proves the buyer physically holds the card.
  • Cardholder name. The name embossed or printed on the card, matched against the billing record.
  • Billing address. Street number, ZIP code, and sometimes the full address, used for Address Verification Service (AVS) checks.

Many processors also ask for the buyer's email address or phone number so a receipt and fraud alert can be delivered. That contact data is for communication, not for authorization.

What to Know About CVV Validity and Checking Before Buying

Why the CVV is the one field that is never stored

The CVV exists to be checked once and discarded. PCI DSS Requirement 3.2 classifies the CVV, the full magnetic stripe data, and the PIN block as sensitive authentication data, and it prohibits retaining any of it after authorization, even in encrypted form. That is why a support agent can confirm a payment went through but cannot read the security code back to you. If a website or a chat contact offers to share or archive CVV values, the practice itself is a compliance violation and a strong signal of a fraudulent operation.

cvv dumps buying guide for first time buyers

Address and identity checks that run behind the scenes

The buyer supplies five fields, but the processor evaluates several more signals before approving the charge.

Address Verification Service (AVS)

AVS compares the numeric portion of the billing address the buyer typed against what the issuer has on file, then returns a match, partial match, or no-match code. Merchants use that code, not a hard yes or no, to decide whether to ship.

CVV response codes

The issuer returns a separate response for the security code: match, no match, or not processed. A CVV mismatch on an otherwise clean order usually triggers a manual review or a decline.

3-D Secure step-up

For higher-risk orders, the issuer may require an extra authentication step, such as a one-time code or a banking app approval. This shifts liability for certain fraud chargebacks from the merchant to the issuer.

Velocity, device, and geolocation checks

Processors and fraud engines also look at how many orders came from one card or IP address in a short window, whether the billing and shipping countries diverge, and whether the device fingerprint matches earlier good orders.

What a buyer should never be asked to provide

  • The card PIN, which is only for ATM and in-person debit use.
  • A Social Security number or a copy of a government ID, unless a regulated lender or bank is legally required to collect it.
  • A photograph of the front and back of the card, sent by email, text, or chat.
  • The CVV over the phone or in an email thread, where it can be logged in plain text.
  • Bank login credentials, which no legitimate merchant ever needs.

Red flags around anyone selling card data

Listings that promise bulk card numbers, ask for payment in gift cards or untraceable crypto, or require you to install a third-party messaging app are describing a criminal marketplace, not a payment service. Buyers who knowingly use stolen card data to obtain goods or services can be charged alongside the sellers, and victims can pursue civil claims as well. If you encounter such a listing, report it to the Internet Crime Complaint Center or the Federal Trade Commission rather than engaging with it.

Legal status in the United States

18 U.S.C. § 1029 covers fraud and related activity in connection with access devices, including trafficking in card numbers and security codes. Penalties can include heavy fines and prison time, and they scale with the number of accounts involved. Knowing what information is needed from every CVV buyer is useful for merchants building a compliant checkout, for fraud analysts reviewing orders, and for shoppers who want to recognize a scam. It is not a legitimate basis for acquiring someone else's card credentials.

Merchant checklist for collecting buyer details

  1. Collect only the five authorization fields plus a receipt contact.
  2. Transmit the data over an encrypted connection through a PCI-validated payment gateway.
  3. Never write the CVV to a database, log file, or support ticket.
  4. Review AVS and CVV response codes together, not in isolation.
  5. Apply 3-D Secure or manual review when the risk score is elevated.
  6. Store only a processor token for repeat billing, never the raw card number.