CVV Brute Force: What It Is and How Merchants Stop It

CVV brute force is an attempt to guess a card's three or four digit verification code by submitting many authorization requests to the same payment form. It is a card-not-present fraud technique, and it depends on weak rate limiting at checkout rather than on defeating encryption. Because a verification code holds only a few thousand possible values, a payment page that allows unlimited retries can be probed until a code matches.

What the term CVV brute force means

Card verification values go by several names: CVV2 for Visa, CVC2 for Mastercard, CID for American Express, and CVV for Discover. Each is printed on the card but never encoded in the magnetic stripe or the chip, which is what makes it useful for confirming that someone physically holds the card during a card-not-present transaction.

A brute force attempt against that check means a fraudster who already has a card number and expiration date keeps resubmitting the same order with different three or four digit codes. Some operations also rotate IP addresses, devices, or merchant sites so that failures spread across many checkouts instead of tripping a single counter.

Why CVV brute force usually fails

Modern payment systems are built to make repeated guessing unproductive. Several controls work against it at the same time:

Warning signs a checkout is being probed

Fraud teams watch for patterns rather than single transactions. Common indicators include:

How merchants reduce the risk

Defenses work best in layers, because any single control can be worked around:

  1. Rate limit authorization attempts per IP address, device, account, and card number.
  2. Add a challenge, such as a CAPTCHA or a short delay, after the first few failures.
  3. Require 3-D Secure for high-risk orders, card-not-present categories, or first-time buyers.
  4. Route suspicious traffic to manual review instead of auto-approving it.
  5. Block or step up traffic from known proxy and hosting provider ranges.
  6. Monitor decline codes in real time and alert on bursts of verification failures.
  7. Tokenize stored card data so repeat customers do not need to re-enter a code.
  8. Keep access and transaction logs as required by PCI DSS, and restrict who can read them.

Why buying or selling CVV data is a crime

Trafficking in card credentials is not a gray area in the United States. Federal law covering access device fraud, including 18 U.S.C. 1029, addresses the sale, transfer, and possession of card numbers and verification values obtained without authorization, and penalties can include fines and prison time. Card network rules and the PCI Data Security Standard point the same direction: sensitive authentication data, which includes the CVV, must not be stored after a transaction is authorized. A merchant that keeps that data to resell or reuse it is both out of compliance and exposed to criminal liability.

What cardholders can do

Frequently asked questions

Is CVV brute force the same as carding?

It is one method used in carding. Carding is the broader practice of testing and using stolen card data, while CVV brute force describes the specific step of guessing the verification code at checkout.

Can a merchant store the CVV to verify it later?

No. PCI DSS prohibits storing sensitive authentication data after authorization, so the code is checked once and then discarded.

Does a successful CVV check guarantee the order is safe?

No. A correct code proves the buyer has the card details, but it does not prove the buyer is the cardholder. Pair verification with address checks, 3-D Secure, and velocity rules.

More

Read our complete guide: Buy CVV Cheap: Pricing, Risks, and What First-Time Buyers Need to Know