Invalid CVV/CVC

An "Invalid CVV/CVC" decline means the security code submitted with the transaction doesn't match the issuer's record for that card. Because the CVV/CVC is printed only on the physical card and not stored in magnetic stripe or chip data, a mismatch is a strong signal that the card details were guessed, scraped, or entered from memory rather than read directly off a genuine card.

Decline code by card network

Decline code by card network
Card networkCodeNetwork's wording
Visa82Invalid CVV
Mastercard82Invalid CVC2

Common causes

What merchants should do

How to prevent this

Because CVV values aren’t transmitted in chip, contactless, or magnetic stripe data, a mismatch on a card-not-present transaction carries more weight than a comparable mismatch might in other contexts, making it a key input to most e-commerce fraud-scoring models.

Frequently asked questions

Does an invalid CVV decline always mean fraud?

Not always — a legitimate customer can simply mistype the code. However, because CVV isn't stored in card data used for skimming or breaches, a wrong CVV is a meaningful fraud indicator, especially when paired with other risk signals.

Should merchants let customers retry the CVV field repeatedly?

No. Unlimited retries on the same order can be exploited by fraudsters running automated card-testing or CVV-guessing scripts. Limit attempts and flag repeated failures for review.