The CVV is a three- or four-digit code printed on your card that proves you physically hold it
The CVV (Card Verification Value) is a security code printed on the back of most credit cards — three digits for Visa, Mastercard, and Discover, four digits for American Express (which prints it on the front). When you enter it during an online or phone purchase, you are telling the merchant and the card issuer that you have the physical card in your hand, not just the card number.
The code is not stored in the card's magnetic stripe or chip. It exists only on the card itself and in the card issuer's records. This means a thief who steals your card number from a data breach cannot use it online without also having the card or knowing the CVV — and knowing the CVV requires either seeing the card or guessing, which most systems block after a few wrong tries.
The CVV is one layer in a larger security system. It does not protect you from fraud if someone steals the physical card, and it does not prevent in-person theft. But it does stop a common type of online fraud: using a stolen card number to buy things without ever touching the card.
Key Takeaways
- The CVV is a three- or four-digit code on your card that proves you physically possess it when you shop online or by phone.
- Merchants and card issuers use the CVV to block purchases made with stolen card numbers alone, without access to the physical card.
- The CVV is not stored in your card's chip or magnetic stripe, so data breaches of merchant databases do not expose it.
- You should never share your CVV with anyone except a merchant during a legitimate purchase, and legitimate companies will never ask for it via email or phone.
How the CVV protects you during online and phone purchases
When you buy something online, you enter your card number, expiration date, and CVV. The merchant sends all three to the card issuer or a payment processor. The issuer checks whether the CVV matches the one on file for that card number. If it does, the transaction moves forward. If it does not, the purchase is declined.
This check happens in seconds and is invisible to you. Its purpose is straightforward: to confirm that the person making the purchase has the card itself, not just the card number. A criminal who obtained your card number from a hacked retailer database or a phishing email cannot complete the purchase without the CVV, because they do not have the card and cannot see the code.
The CVV also protects you from a specific type of fraud called card-not-present fraud. In-person purchases at a store or gas pump do not require a CVV because the card is physically present and the merchant can verify it. But online and phone purchases do, because the merchant cannot see the card. The CVV bridges that gap.
Why the CVV is not stored where hackers can easily find it
Card networks and payment laws require that merchants and payment processors do not store the CVV after a transaction is complete. This is not a suggestion — it is a rule enforced by Visa, Mastercard, Discover, and American Express, and violations can result in fines or loss of the ability to process cards.
The CVV is also not encoded in the magnetic stripe on the back of your card or in the chip. It is printed on the card surface only. This means that if a hacker steals card data from a retailer's database, they get the card number and expiration date, but not the CVV. If they steal data from a gas pump or ATM skimmer, they may get the magnetic stripe data, but again, not the CVV.
This separation is intentional. The card number and expiration date are things merchants need to store to process refunds, handle disputes, and keep records. The CVV is not. By keeping it off the card's magnetic stripe and out of merchant databases, the card networks may support that a single data breach does not expose everything a criminal needs to commit fraud.
What the CVV does not protect you from
The CVV does not protect you if someone steals your physical card. A thief with your card in hand can use it in a store, at a gas pump, or online — they have the card and the CVV, so all security checks pass. Your protection in that case comes from fraud monitoring and your card issuer's zero-liability policy, which means you are not responsible for unauthorized charges if you report them promptly.
The CVV also does not protect you from phishing or social engineering. If a scammer tricks you into giving them your card number, expiration date, and CVV over the phone or email, they have everything they need. Legitimate companies — your bank, your card issuer, retailers you trust — will never ask for your CVV via email, text, or unsolicited phone call. If someone asks, it is a scam.
The CVV is also not a substitute for other security measures. It works alongside fraud monitoring, encryption, and your card issuer's ability to spot unusual spending patterns. If your card issuer detects a purchase that does not match your normal behavior — buying airline tickets in another country when you are home, for example — they may decline it or call you to confirm, regardless of whether the CVV was entered correctly.
Where to find your CVV and how to protect it
For Visa, Mastercard, and Discover, the CVV is a three-digit code on the back of your card, usually printed to the right of the signature strip. For American Express, it is a four-digit code on the front of the card, above the card number on the right side. Some cards also print a partial card number near the CVV to help you identify which card you are using.
Treat your CVV the way you treat your card number: do not write it down, do not photograph it, and do not share it except during a legitimate purchase with a merchant you trust. If you shop online regularly, consider using a digital wallet like Apple Pay, Google Pay, or your card issuer's mobile app. These services store your card information securely and do not require you to enter your CVV for every purchase.
If you believe your card number has been compromised — for example, because a retailer you shopped at announced a data breach — contact your card issuer and ask them to issue a new card with a new CVV. You are not liable for fraudulent charges, but replacing the card stops a thief from using the old number and CVV together.
How CVV checks work differently across card networks
All four major card networks — Visa, Mastercard, Discover, and American Express — use a CVV, but the implementation varies slightly. Visa calls theirs CVV2, Mastercard calls theirs CVC2, Discover calls theirs CID, and American Express calls theirs CID as well. The function is identical: a code that proves you have the card.
The main difference is the number of digits. Visa, Mastercard, and Discover use three digits. American Express uses four. This is because American Express cards are issued directly by American Express (they are not a network like Visa), and they use a different card design. The four-digit code on an American Express card is harder to guess than a three-digit code, though both are protected by systems that block repeated failed attempts.
Some merchants and payment processors also use a process called CVV matching, where they check not just whether the CVV is correct, but also whether the billing address and ZIP code match the card issuer's records. This adds another layer of verification and reduces the chance that a stolen card number will be used successfully, even if the CVV is somehow obtained.
What to do if your CVV is exposed or you suspect fraud
If you believe your CVV has been exposed — for example, because you gave it to a scammer or a website you do not trust — contact your card issuer when ready. You do not need to wait for fraudulent charges to appear. Tell them you suspect your card information has been compromised and ask them to issue a new card with a new CVV.
Your card issuer will cancel the old card and send you a new one, usually within 7 to 10 business days. In the meantime, you can still use the old card for in-person purchases if you have it, or you can use a digital wallet if your issuer supports it. Once the new card arrives, destroy the old one by cutting it in half or shredding it.
If fraudulent charges do appear on your statement, report them to your card issuer as soon as you notice them. Under federal law, you are not liable for unauthorized charges if you report them within 60 days of the statement date. Most card issuers have zero-liability policies that go further and protect you even if you report later, but do not rely on that — report fraud promptly.
Frequently Asked Questions
Can someone use my card number without the CVV?
Not for online or phone purchases — the CVV is required. However, they can use it in person at a store or gas pump, because those transactions do not require a CVV. They can also use it if they have access to your card issuer's system or if they target a merchant that does not properly verify the CVV. This is why monitoring your statement and reporting fraud quickly matters.
Is it safe to give my CVV to a website?
Yes, if the website is legitimate and uses encryption. Look for "https://" in the address bar and a padlock icon, which indicate the connection is find. Never enter your CVV on a website that does not use encryption, and never enter it on a website you do not trust. If you are unsure, call the company directly using a phone number from their official website or bill.
What if I forget my CVV?
Look at the back of your card — it is printed there. If you do not have your card with you, you can call your card issuer and they can confirm it over the phone after verifying your identity. Do not search for it online or ask someone else to look it up for you.
Do I need to enter my CVV every time I shop online?
Most of the time, yes. However, if you save your card to a website or use a digital wallet, you may not need to enter it again for future purchases. The website or wallet stores your card information securely and handles the CVV verification behind the scenes. This is safer than entering your CVV repeatedly.
Can a data breach expose my CVV?
Not if the merchant or payment processor followed the rules. Card networks prohibit storing the CVV after a transaction, so a breach of a retailer's database should not include it. However, if a merchant broke the rules and stored the CVV anyway, a breach could expose it. This is rare but possible, which is why monitoring your statement and considering a new card after a major breach is wise.
