What a CVV attack signature is

A CVV attack signature is a pattern in card authorization traffic that points to CVV guessing. The CVV is a 3 digit code on Visa, Mastercard, and Discover cards and a 4 digit code on American Express. Issuers check it on card-not-present transactions. An attacker submits many codes against one card number, or one code across many card numbers, until an authorization approves. The signature is the footprint left in authorization logs: timing, decline codes, amounts, and shared identifiers.

The term describes evidence, not a person. A single CVV mismatch is a normal event. Repeated mismatches from one source are not.

Signals fraud systems look for

  • CVV mismatch decline codes repeat on the same card number.
  • Attempt counts per card number exceed a set limit inside 24 hours. Most issuers allow 3 to 5 tries before a block.
  • One device fingerprint or IP address sends authorizations across many BIN ranges.
  • Transaction amounts sit below a test floor, often under 1.00 USD.
  • AVS results stay constant while CVV results change.
  • Time between attempts drops below human speed, often under 2 seconds.
  • Decline rate per merchant ID rises above the network baseline.
  • Authorization requests arrive in sequential or near-sequential card number order.

CVV attack vs BIN attack

A BIN attack varies the card number and keeps cardholder data fixed. A CVV attack varies the verification code and keeps the card number fixed. Both produce enumeration traffic. Detection differs. BIN attacks appear as many PANs from one source. CVV attacks appear as repeat attempts on one PAN.

Response codes that mark the pattern

  • N7 marks a CVV2 or CVC2 mismatch on Visa and Mastercard traffic.
  • Code 05 marks a general decline and carries no CVV detail.
  • Code 51 marks insufficient funds and can hide a failed CVV check.
  • Stripe returns cvv_check values of pass, fail, unavailable, or unchecked inside the authorization response.

Issuers send these codes in ISO 8583 field 39. Acquirers and gateways store them with the request timestamp and the device data attached to the order.

Controls that break the signature

  • Cap CVV retries per card number and per device per day.
  • Require AVS and CVV together for high-risk BINs.
  • Route suspect traffic to 3-D Secure step-up instead of a hard decline.
  • Rate limit by IP, device, email, and shipping address, not by IP alone.
  • Block authorization requests that arrive faster than a set interval.
  • Tokenize stored card numbers so the CVV never reaches a database.

PCI DSS Requirement 3.2.2 prohibits storage of sensitive authentication data, including the CVV, after authorization. A system that keeps CVV values in logs cannot verify them later and adds breach exposure.

What a signature cannot show

Traffic patterns do not identify intent. Shared IP addresses, corporate proxies, and gift card programs produce overlap with attack traffic. A decline spike can also follow an issuer outage or a gateway bug. Analysts confirm a CVV attack by matching decline code, attempt count, timing, and shared identifiers across at least two data sources. No public source states a single universal threshold for attempt counts. Networks set thresholds per program and revise them.