Understanding CVV Dumps and How to Avoid Them
Learn what CVV dumps are, how they are used, and essential steps to protect yourself from falling victim to this type of cybercrime.
Redeem your gift cards at any of our Merchants
Onyx Gift Cards is a Grenadian company designed to introduce, market and manage gift cards systems in Grenada for retailers and corporations. We are enthusiastic about the effect and influence we will have on the local market. We intend to expand our systems regionally with a range of product offerings and services.
Gift cards are the preferred way of giving and receiving gifts. They carry a monetary value that can be redeemed for gifts at your favorite store.
Onyx GiftCards are “Open Gift Cards” which means that they can be redeemed at multiple merchant locations. They are standard credit card size, can fit into the average wallet and made of PVC plastic. Onyx GiftCards are Barcoded for security and safety for the consumer and bear a disclaimer at the back.
Onyx Giftcards can be bought with a branded Card backer which is black in colour and is designed to fit the card. There is an area to write a brief message to the recipient as well.
A CVV dump seller is a person who trades stolen card data. The dump is a record that holds a card number, an expiration date, a cardholder name, and a CVV code. Sellers list records on closed forums and in encrypted chat channels. Buyers pay in cryptocurrency. The trade is fraud. In the United States it is a federal crime under 18 U.S.C. 1029. A conviction can bring 15 years in prison. This page does not list sellers and does not name marketplaces.
The CVV is the card verification value. It is 3 digits on the back of a Visa or Mastercard and 4 digits on the front of an American Express card. A full record often carries more than the code.
Four sources supply most of the market: breaches of retailer and payment processor systems, skimmers placed on gas pumps and ATMs, phishing pages that copy a checkout screen, and malware on point-of-sale terminals. The FBI logs these cases through the Internet Crime Complaint Center.
18 U.S.C. 1029 covers the sale, transfer, and possession of card data with intent to defraud. Subsections carry terms of 10 or 15 years. 18 U.S.C. 1028A adds a 2-year mandatory term, served after the first sentence, when the offense uses another person's identity. Restitution and asset forfeiture follow the sentence. State laws add charges for identity theft and larceny. A buyer who holds the file is as exposed as the seller.
Issuers block a card after the first failed authorization. Card networks flag the account number and the merchant. A buyer who pays before delivery reports no file, a truncated file, or a card that was closed weeks earlier. Forum disputes go to a moderator who holds the escrow, and the moderator takes a cut. Chargeback rules do not help, because the buyer has no lawful claim to the funds.
The FTC received about 1.04 million identity theft reports in 2023. IC3 logged $12.5 billion in reported cybercrime losses that year. The Nilson Report projected $165.1 billion in U.S. card fraud losses from 2021 through 2030. Banks absorb part of the loss and pass the rest to customers through fees. Cardholders spend hours on calls and wait days for a replacement card.
Call the card issuer first and close the account. File a report with the FTC and with the FBI Internet Crime Complaint Center. Send a complaint to the Consumer Financial Protection Bureau for a dispute with a bank. File a police report when identity theft is involved, and keep the report number for the credit bureaus.