CVV fraud rules are the card network, processor, and issuer requirements that govern how the 3 or 4 digit card verification value is captured, verified, and protected, and who absorbs the loss when a card-not-present transaction turns out to be fraudulent. They combine PCI DSS data-storage prohibitions, Visa and Mastercard verification mandates, and issuer fraud-scoring models that together decide whether an online charge is approved. Understanding these rules is the fastest way to see why a stolen CVV rarely works on its own.

What are CVV fraud rules?

CVV fraud rules are a layered set of obligations, not a single law. Payment card brands write the operating rules, the PCI Security Standards Council sets data-protection standards, and issuing banks apply their own risk models on top. A merchant, gateway, or processor that ignores any layer can lose the right to process card payments.

The core principle is simple: the verification value is a check on possession of the physical card, so it must never be stored, logged, or reused after a single authorization.

What are the three types of CVV?

  • CVV1 / CVC1 is encoded in the magnetic stripe and read only when a card is swiped.
  • CVV2 / CVC2 / CID is the 3 digit code on the back of Visa, Mastercard, and Discover cards, or the 4 digit code on the front of American Express cards.
  • iCVV / dynamic CVV is generated by the chip or by a token service for each transaction, so it changes every time.

Online merchants can only request the printed value. Because that value is static, issuers treat a correct CVV2 match as one signal among many rather than proof of identity.

What PCI DSS rules apply to CVV data?

PCI DSS Requirement 3.2 prohibits storing sensitive authentication data after authorization, and that includes the full track data, the card verification code, and the personal identification number block. The rule applies even when the data is encrypted, which is why call recordings, chat logs, and order notes are common audit failures.

Requirement 3.3 requires masking the primary account number when it is displayed, and Requirement 4.2 requires strong encryption for card data in transit. Together these rules shrink the window in which a CVV can be captured before it disappears from the merchant environment.

How do network rules and liability shift work?

Visa and Mastercard define verification result codes that travel with every authorization request, and a merchant that fails to request CVV verification may lose chargeback rights on a card-not-present dispute. Fraud liability generally shifts to the issuer when the transaction is authenticated with 3-D Secure or a chip read, and stays with the merchant when it is not.

This is why checkout systems often require both the CVV and the billing address: address verification service results and CVV results are matched against issuer records before approval.

How do issuers detect CVV fraud?

Issuers score every authorization in milliseconds using signals such as transaction velocity, device fingerprint, IP geolocation, merchant category, and the gap between card issue date and first use. A correct CVV on a high-risk combination of those signals will still be declined or sent to a step-up authentication challenge.

Machine learning models also flag patterns that human rules miss, such as hundreds of low-value test charges across many merchants made with sequential card numbers.

What should cardholders do if a CVV is exposed?

  1. Report the card as compromised to the issuer as soon as possible and request a replacement number.
  2. Review statements for small test charges, since fraudsters often validate a card before a large purchase.
  3. Dispute unauthorized charges in writing within the timeframe set by the Fair Credit Billing Act.
  4. Enable transaction alerts and use tokenized digital wallets so the real CVV is never typed into a website.

Cardholders are generally liable for no more than 50 dollars for unauthorized use, and many issuers waive even that amount.