CVV Brute Force Attack: How It Works and How It's Stopped

A CVV brute force attack is an attempt to guess the 3- or 4-digit card security code by sending repeated guesses to a payment form. The attacker already holds the card number and expiry date and needs the CVV to complete a purchase. Issuers and payment processors block most of these attempts by capping how many CVV guesses one card can take.

read more

The card number and the CVV come from different places. A card number follows a published format, so a leaked number is easy to reuse. The CVV is generated by the issuer with a secret key and the merchant must not store it after authorization. That gap is what brute force tries to close.

brute force cvv attacks

How CVV Guessing Plays Out on a Checkout Page

Card-not-present fraud often starts with stolen data bought in bulk. Those records tend to include the full card number and expiration date but no security code. Attackers point the records at an automated checkout and let a script submit one guess after another.

Brute Force CVV Testing: A Comprehensive Guide

The math is the reason attempt limits exist. Three digits give 1,000 possible values and four digits give 10,000. A script could cover that range in seconds if the merchant kept no counter on failed tries.

brute force cvv attack

Why the CVV Carries So Much Weight

A card number alone is not enough for a card-not-present charge with most merchants and issuers. The CVV check ties the transaction to something printed on the physical card, which is data a thief who only copied a database never saw.

This is also why online retail absorbs most of this activity. The merchant never handles the card, so the security code check is the main verification step left.

How Merchants and Issuers Stop CVV Brute Force Attacks

Attempt Limits Tied to the Card

The strongest control counts failures on the card itself, not on the session. After a small number of CVV mismatches, the issuer or gateway blocks further tries on that card. Without a per-card counter, an attacker rotates IP addresses and keeps guessing.

Address Verification and ZIP Checks

AVS compares the billing address or ZIP code with issuer records. A guessed CVV paired with a mismatched address raises the fraud score and sends the order to manual review.

3-D Secure and Issuer Authentication

3-D Secure moves the check to the issuer with a password, an app approval, or a one-time code. A stolen card number plus a lucky CVV guess still fails when the real cardholder never approves the prompt.

Device, Velocity, and Network Signals

Fraud tools score the device fingerprint, the IP address, the shipping address, and the time between attempts. Many cards tried from one device is a pattern no genuine shopper creates.

Decline History That Follows the Card

Repeated CVV mismatch declines land in the issuer's fraud data. Issuers use that record to block the card, and many reissue it before the cardholder notices anything.

Warning Signs on Your Own Checkout

What Cardholders Can Do

FAQ

Is a CVV brute force attack the same as a BIN attack?

No. A BIN attack generates many card numbers that share a bank identification number and tests them against a gateway. A CVV brute force attack starts with one known card number and guesses the security code on that card.

Can a stolen card number be used without the CVV?

Some card-not-present channels do not ask for the code, and stored-credential transactions can skip it after an initial setup. Physical terminals verify the chip or stripe data instead. Merchants that require the CVV see far fewer of these charges.

What happens after repeated failed CVV attempts on a real card?

The issuer or gateway stops accepting tries and may flag the card for review. Cardholders are not liable for confirmed fraudulent charges under US card network rules, but the card is often reissued.

Legal Risk for Anyone Running These Attacks

Guessing card security codes to obtain goods or money is fraud. In the US, federal law covers access device fraud under 18 U.S.C. 1029 and unauthorized computer access under 18 U.S.C. 1030, and state laws add their own charges. Penalties include prison time and restitution.

Merchants carry a different risk: fines and lost processing rights if they store CVV data or ignore fraud signals. The PCI DSS forbids keeping the security code after authorization for any reason.

More

More

Read our complete guide: Buy CVV Cheap: Pricing, Risks, and What First-Time Buyers Need to Know