CVV Web Verification: How Online Card Checks Work

CVV web verification is the check a payment processor runs when a shopper enters the 3- or 4-digit security code printed on a card. The merchant sends the card number, expiry date, and code to the issuer inside the authorization request, and the issuer returns a match, no-match, or unavailable result. It is a fraud screen for card-not-present transactions, not proof that the person typing the numbers is the cardholder.

cvv check web

What does the issuer actually check?

Visa calls the printed code CVV2, Mastercard calls it CVC2, and American Express uses a 4-digit CID. All three are generated from the card number, the expiry date, and a secret issuer key, so the issuer can recalculate the value and compare it.

cvv web verification

The code is printed on the plastic and encoded nowhere in the magnetic stripe or chip. That design is intentional: someone who skims or clones a card obtains the account number but not the printed verification value.

read more

Can a merchant store CVV data?

No. PCI DSS classifies the CVV as sensitive authentication data and prohibits retaining it after authorization, even in encrypted form. Merchants that keep it face fines, loss of card acceptance, and liability in a breach.

CVV Web Check: A Guide to Safely Verify CVV Codes

That rule explains why legitimate checkout pages never offer to memorize your code. Any site advertising a stored CVV database is describing data it is not permitted to hold.

CVV vs CVV2 vs CVC: what is the difference?

Is buying or selling CVV data legal?

No. A card verification value belongs to the account holder, and trafficking in stolen card data is criminal fraud. In the United States, 18 U.S.C. Section 1029 covers trafficking in access devices, and most states add separate charges.

Sellers of CVVs are also unreliable by design. Buyers routinely receive dead numbers, values lifted from breached databases that were already drained, or lists recycled across multiple buyers. The same channels often deliver malware that harvests the buyer's own credentials and banking logins.

How do legitimate merchants reduce card-not-present fraud?

  1. Tokenization replaces the account number with a surrogate value that has no use outside one merchant.
  2. EMV 3D Secure adds an issuer-side authentication step before the charge is approved.
  3. Address Verification Service compares the billing address and postal code to the issuer's records.
  4. Velocity and device checks flag mismatched geolocation, newly created accounts, and repeated declines.
  5. Machine learning models score each order against the account's own history and network-wide patterns.

Frequently asked questions

Does CVV verification stop all fraud?

No. A stolen card number paired with a stolen code can still pass verification. Issuers layer 3D Secure, address checks, and behavioral scoring on top of the code match to raise the overall cost of fraud.

What is the difference between CVV verification and 3D Secure?

CVV verification is a silent data match that happens behind the scenes during authorization. 3D Secure is an active challenge in which the issuer asks the shopper for a password, one-time code, or biometric confirmation.

What should I do if my card number is stolen?

Contact the issuer right away so the card can be blocked and replaced with a new number and code. Then review recent transactions, dispute unauthorized charges, and report confirmed identity theft to the Federal Trade Commission.

Why do some sites advertise CVV verification tools?

Those tools usually run small test charges, known as carding, to see whether an account is still active. Using them is fraud even when the test amount is later reversed or refunded.

More

Read our complete guide: Buy CVV Cheap: Pricing, Risks, and What First-Time Buyers Need to Know