About credit card security codes

When you place an order online or order takeout by phone, you’re often asked for your credit card’s 3-digit CVV/CVC/security code. For AMEX cards, it’s the 4-digit CID on the front of the card. So what exactly are the CVV and CVC?

CVV (Card Verification Value), CVC (Card Validation Code), and CID (Card Identification Code) are essentially the same thing: an anti-fraud security code for your credit card used to help verify that the person using the card is the cardholder.

Where is the security code?

For Visa, Mastercard, Discover, JCB, and UnionPay credit cards, the security code is generally on the back of the card. The 3-digit number on the right side of the signature panel is the security code you’re looking for.

For AMEX credit cards, the security code is on the front of the card. The 4-digit number at the upper right of the card number is the AMEX security code.

How is the security code generated?

Simply put, after the credit card is produced, the bank randomly generates a 3-digit or 4-digit number and prints it on the back (CVV) or front (CID) of the card with a laser.

In other words, this number is tied directly to that specific card. If your card is lost and the bank sends you a replacement, the CVV will definitely be different. The card number and expiration date, however, may remain the same if the card was only damaged and not lost or stolen. Only you and the bank’s systems have your CVV information.

The CVV has absolutely nothing to do with your card number, expiration date, address, whether you’re good-looking, how much money you have, or how many houses you own.

Why is there a security code?

The purpose of the security code is simple: to help prevent fraud in online purchases and to verify the cardholder’s identity. First, it helps to understand how banks classify transactions. Generally, there are two types:

  • Card Present: When you use your card at a physical store, the POS terminal reads your credit card information from the magnetic stripe and sends it through the payment network (VISAMASTERAMEXDISCOVER) to the issuing bank for verification and settlement. This is called a Card Present transaction, or an in-person transaction. In addition to reading your card number and name, the POS terminal also reads the security code stored in the magnetic stripe (technically CVV1). When the bank sees CVV1, it knows this is an in-person transaction. For a debit card, entering the PIN also tells the bank it’s an in-person transaction.
  • Card not Present: When the card is not physically presented, such as for online shopping, phone orders, or ordering takeout through an APP, this is generally called a card not present transaction. In this case, to verify identity, you usually need to enter the security code in addition to the card number and expiration date. Technically, this is CVV2. Once the data is sent to the bank, seeing CVV2 tells the bank this is a card not present transaction.

Looking a bit deeper, the main reason banks distinguish between card present and card not present transactions is risk control. In general, card present transactions have slightly lower fraud-control standards because the transaction is being completed in person, often in public and sometimes on camera. For card not present transactions, the standards are usually stricter because fraud is much more likely over the phone or online.

So if the card number and expiration date are already being verified, why is a security code still needed? Because most merchants, for convenience, store your credit card number and expiration date so you don’t have to enter them next time you shop. Those two pieces of information are generally stored in the merchant’s database. If that database is compromised, the information may be stolen as well.

That’s where the security code becomes important. You’ve probably noticed that even if your card number and expiration date are already filled in, you still have to manually enter the security code (CVV) to complete checkout.

That’s because merchants do not store, and are not allowed to store, your security code. The code is transmitted to the bank in real time during checkout, verified, and then not retained by the merchant.

After all, many merchant systems are outsourced and often have plenty of security vulnerabilities. This most critical verification data shouldn’t just be left lying around. Mobile wallets are a little different: Apple and Android both support direct payment with fingerprint authentication, likely because they use dedicated encrypted chips internally to store the CVV.

Are there any exceptions?

For the vast majority of purchases, merchants require you to enter the security code in real time. But there is one notable exception:

Amazon.

When you add a card on Amazon, you don’t need to enter the security code. You also don’t need it at checkout, and even changing the shipping address does not require entering the security code.

Does Amazon have some kind of special superpower? Of course not. This is simply one of the ways Amazon reduces friction and encourages fast purchases.

Many people have probably had the painful experience of getting all the way to the last step of online checkout only to realize the card they wanted to use isn’t with them, so they can’t enter the security code. Amazon basically says: no security code needed, just spend.

So how does Amazon handle risk control? As one of the biggest online bosses, Amazon relies on its own risk-control team. They use information such as your IP, browser cookie, and shipping address to determine whether it’s really you placing the order.

What if a card really is used fraudulently? Amazon may have decided that even if some fraud slips through and they have to absorb the loss, that loss is still smaller than the additional revenue generated by making shopping easier for customers.

What if someone finds out your security code?

So what should you do if someone learns your security code?

In most cases, there’s no need to panic. If someone only knows your security code but does not know your card number, expiration date, address, and other required information, it’s generally not useful. Online transactions require all of that information, and for in-person transactions just knowing the information isn’t enough to use the physical card. But if all of that information has been exposed, contact your bank right away and request a replacement card.

There’s one thing here that still feels a bit unresolved. Earlier, I used takeout ordering as an example. When we order food by phone, aren’t we giving all of our card information to the merchant? And since they likely know the delivery address, which may also be the billing address, doesn’t that create a real risk that someone at the restaurant could misuse the information for fraudulent charges? I’m curious how everyone thinks about this.

ymlulu’s note: There’s no perfect solution. Nowadays, some airlines, when you buy tickets by phone, transfer you to a dedicated payment department at the payment step. An automated voice system then asks you to enter your card number, CVV, and other information using your phone keypad, so no third person is involved between you and the bank. Some merchants, such as saks, may also transfer you to a dedicated payment department when placing an order, where specialized staff handle payment information. Perhaps those staff members are simply considered more trustworthy. In any case, I still recommend avoiding phone orders whenever possible. If you can use an APP or the website instead, that’s usually best.

I also recommend using a third-party App to monitor your credit card transactions in real time. For example, 101 has recommended: