What a CVV brute force attack is

A CVV brute force attack is an attempt to guess the three-digit card verification value on a payment card by sending many different guesses until one is accepted. The card number and expiration date are already in hand. Only the last three digits are unknown, so the attacker automates submissions across a small search space. It is a form of card testing, and it is the quickest way to get a card number killed.

That is the short answer. The longer version is that the technique barely works anymore, and when it does work it leaves a trail that ends in a fraud case.

Why the math is misleading

Three digits gives you 1,000 possible values. On paper that looks small. In practice the CVV is never checked by itself.

  • Issuers verify the CVV together with the card number, expiration date, and often the billing address and ZIP code.
  • Each failed CVV check is logged against the card and against the merchant.
  • A single card that produces repeated mismatches gets shut off before the attacker reaches the right value.
  • Many issuers require step-up authentication such as a one-time code for the transaction to complete at all.

So the search space is not 1,000 guesses. It is two or three attempts before the card is blocked and the merchant is flagged.

How the networks shut it down

Card networks publish rules that cap how many verification attempts a merchant can make on one card, and processors enforce velocity limits on top of those rules. A merchant that fires hundreds of small authorization requests in a few minutes trips those limits fast. The result is usually a declined batch, a frozen merchant account, and a fraud report to the acquirer.

Sensitive authentication data, which includes the CVV, also cannot be stored after a transaction is authorized under PCI DSS. That means an attacker who wants to brute force a CVV has to do it live, one transaction at a time, which is exactly the behavior fraud monitoring is built to catch.

What fraud teams look for

When I read through card testing cases, the pattern is predictable. Lots of low-value authorizations. A high decline rate in a short window. Many different card numbers hitting one merchant or one checkout page. Billing addresses that do not match the issuing bank's records. Traffic from a datacenter IP range instead of a residential connection.

Any one of those signals gets a second look. Three or four together usually end the merchant relationship and start a law enforcement referral.

The US legal picture

Guess-and-check on card verification values falls under 18 U.S.C. Section 1029, which covers fraud and related activity in connection with access devices. Trafficking in card numbers, producing counterfeit access devices, and using them to obtain money all carry felony exposure, with penalties that reach 10 to 15 years per count plus restitution. Attempted guessing does not get a lighter treatment because the guesses failed. The attempt itself is the offense.

State laws add their own charges, and payment processors pursue civil recovery separately.

Why "fresh CVV" lists do not change the outcome

Lists sold as fresh or high validity are almost always recycled data, and a large share of the cards are already closed. A buyer running brute force attempts against that data gets a stream of declines, burns the usable cards in the batch within minutes, and pays for the privilege. There is no version of this where the math works out.

Quick answers

Can a CVV be brute forced?

Not at any useful scale. Attempt limits, velocity checks, and step-up authentication stop the process after a couple of tries.

Is card testing the same thing?

Card testing is the broader practice. CVV guessing is one method inside it, and the easiest one for a fraud system to detect.

What happens to the card after repeated failures?

The issuer blocks it, the merchant loses processing rights, and the activity is documented for investigators.