There’s a document circulating on underground forums right now with a title that sounds like a Reddit post written by someone very angry at online shopping: “The Underground Guide to Legit CC Shops: Cutting Through the Bullshit.”
It wasn’t written for you. It was written for people who buy stolen credit card data for a living, and it reads exactly like a consumer protection guide โ except the product being protected against scams is your credit card number.
Researchers at Flare found the guide and walked through its contents in a report published through BleepingComputer. What they found is something security analysts have suspected for years but rarely get documented this clearly: the underground market for stolen financial data has grown into a structured, process-driven economy with its own due diligence standards, reputation systems, and quality control benchmarks. It’s not a chaotic bazaar of random criminals anymore. It’s closer to an industry.
And 2026 has handed us the receipts. Credit card fraud losses are projected to hit $43 billion this year. Three platforms, Findsome, UltimateShop, and Brian’s Club, now control roughly 100% of the examined carding market between them. A single fake-shop network called DoppelCart, discovered this week by German cybersecurity firm Nebty, is running over 119,000 fraudulent domains to steal card data from unsuspecting shoppers.
Your card is the product. Here’s how the system works.
Quick answer: Dark web carding shops buy and sell stolen credit card data in three main forms: CVVs (card details for online fraud), Dumps (magnetic stripe data for cloning physical cards), and Fullz (complete identity profiles). Underground guides now teach buyers how to vet these shops like a procurement process, checking domain age, mirror sites, community reputation, and data freshness before spending a dollar. The whole system is more structured than most people realize, and your card’s journey from stolen to sold follows a well-worn path.
What Gets Sold: CVVs, Dumps, and Fullz
Three main product types run through these markets, and the differences matter.

CVVs: Despite the name, this isn’t just the three-digit number on the back of your card. In carding terminology, a “CVV” is the full package: card number, expiry date, cardholder name, CVV2 code, and usually the billing address and phone number too. CVVs are used for card-not-present fraud, the kind that happens when someone uses your card to buy things online without ever touching the physical card.
Dumps are different. These are raw magnetic stripe records, the data encoded on the black stripe on the back of your physical card. With dumps, a criminal can clone an exact copy of your card onto a blank and use it at ATMs or in-store terminals. If your card has ever been skimmed at a gas pump or compromised at a point-of-sale terminal, the dump is what got captured. This is why supply chain attacks targeting point-of-sale systems are so dangerous, the stolen data goes straight into a dump format that can be monetized within hours.
Fullz are the most complete and most expensive product. A Fullz record combines card data with rich personal information: date of birth, Social Security number, address history, and sometimes account login credentials too. Fullz are the raw material for identity theft that goes well beyond a single fraudulent purchase. They enable account takeovers, new credit line applications, and tax refund fraud. The card theft is just the entry point; the identity damage extends much further.
According to Rapid7’s analysis, Visa cards make up about 60.4% of all cards listed in examined carding markets, followed by Mastercard at 32.3%, American Express at 4.3%, and Discover at 3%. That distribution closely tracks US card usage rather than global market share, which tells you where most of the stolen data originates.
The Guide: Treating Fraud Like a Procurement Process
The document Flare found isn’t a how-to guide for stealing cards. It’s a how-to guide for buying stolen cards. That distinction is significant, because it reveals something about how sophisticated this market has become.
The guide’s core argument is that most carding shops are either scams, law enforcement honeypots, or poorly run operations selling low-quality data. Finding a reliable supplier is the hard part, not finding a shop. Any forum user can find a shop in thirty seconds. The guide teaches buyers how to tell the real operations from the garbage.
The opening premise sets the tone: legitimacy isn’t defined by how polished a shop looks or how many testimonials it shows. It’s defined by survivability. A shop that’s been operating for two years despite law enforcement pressure, despite competing criminal groups trying to take it down, despite the general instability of the underground economy. That shop has proven something. It’s kept real data flowing to real buyers without getting shut down, exit-scammed, or taken over.
This is a natural selection argument applied to criminal markets, and it’s surprisingly sound logic. The market punishes bad operators quickly, because buyers share information, warn each other on forums, and move to competitors who deliver. The shops that survive are the ones that consistently deliver working cards.
How They Actually Vet a Shop
The technical checklist in the guide reads like something a cautious B2B procurement officer would recognize, just pointed at an illegal marketplace instead of a SaaS vendor.
Domain age is the first check. A carding shop registered last month is immediately suspect. Old domains suggest established operations. You can’t fake two years of online history. WHOIS privacy settings and SSL certificate configuration are evaluated for signs of professionalism or tell-tale shortcuts. The guide flags that legitimate operations almost always use privacy-protected registration and properly configured HTTPS.

Mirror domains and backup access points are treated as a trust signal. The guide notes that established shops rarely rely on a single domain, because they know their infrastructure will be disrupted. Having multiple mirrors and backup onion addresses shows operational planning. A shop with only one URL is either new or not expecting to last.
Support infrastructure is another criterion. Does the shop have a working ticket system? Is there escrow available for disputed purchases? These are genuine customer service features, and their presence indicates a shop built for repeat business rather than a quick exit. The guide compares functional support systems to those of legitimate e-commerce platforms โ accurately, because the shops that survive have effectively copied legitimate business practices.
Pricing model transparency and real-time inventory matter too. A shop showing card counts that never change is likely selling old data โ and old card data is worthless because the cards will have been cancelled. Real inventory fluctuates constantly as new cards come in and sold cards are removed.
Community Trust Over On-Site Reviews
This is the part of the guide that reveals the most about how the underground actually functions.
The guide dismisses on-site testimonials as meaningless. Anyone running a shop can write their own five-star reviews. The guide specifically calls out coordinated endorsement campaigns, multiple glowing reviews from brand-new accounts posted within a short window, as a clear red flag.
Instead, buyers are directed to closed or invite-only forums to find genuine discussion. The logic is straightforward: forum communities have long memories and reputations to protect. A user who vouches for a scam shop gets called out. A shop that consistently delivers gets discussed favorably in threads that accumulate over months or years. That historical record is what the guide calls real social proof.
This is why dark web forums remain central to the carding economy even as Telegram channels have become the primary communication channel for faster coordination. Forums carry institutional memory that ephemeral Telegram groups don’t. The guide essentially teaches buyers to read the archives.
This dynamic mirrors exactly what we covered in the AudiA6 laundering takedown, criminal operations depend on underground reputation infrastructure just as much as legitimate businesses depend on reviews and references. Removing trusted services disrupts the whole ecosystem, not just one operator.
The OPSEC Layer: Monero, VMs, and Geographic Proxies
Beyond vetting shops, the guide covers operational security for buyers, like how to make purchases without leaving a traceable trail.
The cryptocurrency recommendation is strongly Monero over Bitcoin. This reflects a real awareness of blockchain analysis capabilities. Bitcoin transactions are permanently public and increasingly traceable through chain analysis tools used by law enforcement and firms like Chainalysis. Monero was designed specifically to obscure transaction amounts, sender addresses, and recipient addresses. The guide warns against buying directly from regulated exchanges โ even purchasing Monero on a KYC-compliant exchange before using it in a transaction creates a paper trail connecting a real identity to an illicit purchase.
The proxy guidance emphasizes geographic matching. When using a stolen US card, the buyer is advised to use a US IP address, because many fraud detection systems flag purchases where the apparent location of the buyer doesn’t match the card’s home country. Residential proxies are preferred over data center proxies because they appear to be real consumer internet connections rather than server traffic.
Virtual machines and dedicated, compartmentalized devices are recommended for the purchasing environment itself. The goal is to ensure that even if one transaction is flagged and investigated, it doesn’t lead investigators to a device that contains evidence of other transactions.
This level of operational discipline would have been unusual for low-level criminals five years ago. The guide’s existence and apparent circulation suggest these practices have trickled down well beyond sophisticated actors.
The Two-Tier Market: Scale vs. Exclusivity
The guide draws a distinction between two types of operations that has real implications for understanding where stolen card data ends up.
Large automated platforms work like Amazon for card data. They have search and filter functions, search by card type, BIN range, country of issue, price tier. They support instant purchasing, bulk orders, and often include card-checking tools that let a buyer verify whether a card is still valid before completing a transaction. These platforms handle enormous volume and serve buyers who need scale. Findsome, with 57.6% of the examined market, is the dominant example of this model.
Boutique vendor groups are the opposite. Access is invitation-only. The data is more expensive. The claim is higher quality and fresher sourcing. These operations run through private Telegram channels or restricted forum sections, and rely on long-term buyer relationships rather than anonymous transactions. They’re harder to infiltrate and harder to shut down because they have no public storefront.
The guide’s endorsement of a specific shop called CardingHub, by name, with screenshots, is flagged by Flare as a sign that the guide’s author may have had a commercial interest in promoting certain platforms.
This is common in the underground: informational content frequently doubles as affiliate marketing, and guides that appear to be objective reviews are sometimes paid promotions. The underlying methodology in the guide remains valid even if the specific recommendations are biased.
The Carders Are Being Scammed Too
Here’s the part that doesn’t get covered enough, and it’s genuinely fascinating: the people trying to buy stolen credit cards frequently get scammed themselves.

Group-IB’s research identified three major networks of fake carding shops, named UniFake, JokerMantey, and SPAGETTI, that exist purely to defraud carders. These sites copy the branding of legitimate carding shops, advertise on the same forums, and sell either stolen data that doesn’t work or nothing at all. SPAGETTI alone operated more than 3,000 domain names cloned from real carding platforms.
The guide found by Flare exists in large part because this problem is so widespread that experienced actors felt the need to educate newer ones on how not to get conned. The carder supply chain has its own fraud problem.
This week’s DoppelCart discovery runs the same scam from the other direction. Rather than fake carding shops selling to criminals, DoppelCart’s 119,000 fake e-commerce domains steal card data from ordinary shoppers by impersonating 44,182 real brands. You think you’re buying from a legitimate retailer. The checkout page sends your card details to a command-and-control server in real time. Your card ends up in the same underground ecosystem this guide describes.
The operation is so large it surpasses the previous record-holder, BogusBazaar, which ran 75,000 sites and recorded an estimated 850,000 fraudulent transactions. If you’ve never heard of the brands SodaStream, Daniel Wellington, or Velasca, you’ve now heard of DoppelCart, because those are among the 44,000 brands it impersonates.
What Your Card’s Journey Actually Looks Like
A card gets stolen through one of several channels: an infostealer infection on your device that captures credentials and payment data as you type, a phishing page that mimics a banking portal, a point-of-sale skimmer at a physical terminal, or a large breach at a merchant, processor, or data aggregator. That last category is increasingly common, the 153 million driver’s license exposure we covered recently shows how a single vendor breach can produce identification data that gets paired with financial data from separate leaks to build Fullz.
The stolen data moves to a carding shop, either directly if the thief operates their own shop or through a middleman broker who buys data in bulk and sells it retail. The guide’s vetting process plays out here: buyers assess the shop’s reputation, check the freshness of the BINs, and look for evidence that the data actually works before committing significant funds.
The buyer uses the card for CNP (card-not-present) fraud online, cash-out through gift card purchases, or resells the data to someone further down the chain. Cards found to be valid get exploited quickly; the window between theft and discovery by a bank’s fraud system is typically measured in hours to a few days for actively monitored accounts.
Fraud losses from this cycle are projected at $43 billion for 2026. That’s not evenly distributed: most of it falls on merchants who accept fraudulent transactions, with banks and card networks absorbing the remainder through chargebacks. Individual cardholders with zero-liability protection from Visa and Mastercard are usually made whole, but the process is disruptive, and the downstream costs eventually fold into fees and rates across the system.
What You Can Actually Do
The underground guide documents a mature, resilient system that’s adapted to law enforcement pressure and internal fraud. That’s honest context, not defeatism โ there are still things that work.
Turn on transaction alerts for every card you own. Real-time alerts for purchases above a threshold (set it to $1 or $5) catch unauthorized use within minutes rather than days. Early detection is the difference between a single unauthorized charge and a depleted account.
Use virtual card numbers for online purchases wherever possible. Capital One’s Eno, Citi’s Virtual Account Numbers, and Privacy.com all generate single-use or merchant-locked card numbers that expose nothing reusable if captured. Your real card number never touches the merchant.
Review your statements weekly, not monthly. Many fraudulent test charges are small, $1 or $2, specifically designed to avoid triggering thresholds. Monthly reviews miss these probe charges before larger unauthorized withdrawals follow.
Check your credit regularly. If Fullz including your SSN are circulating, new account fraud is the next risk. Monitoring your credit at AnnualCreditReport.com and freezing your credit at all three bureaus costs nothing and blocks the highest-impact misuse of your information. Our guide on what to do when your data is on the dark web walks through this in detail.
Report unauthorized charges immediately to your card issuer. Zero-liability protection is real, but it requires reporting. The FTC’s fraud reporting portal is also the correct place to document identity theft formally if the misuse goes beyond a single fraudulent charge.
Frequently Asked Questions
What is a carding shop?
An online marketplace, usually on the dark web, that sells stolen credit card data. Shops offer CVVs for online fraud, dumps for cloning physical cards, and fullz for full identity theft.
How do carders decide which shop to trust?
According to the guide Flare found, they check domain age, mirror domains, community forum reputation (not on-site reviews), data freshness, support systems, and how long a shop has survived law enforcement and criminal competition.
Why do carders prefer Monero over Bitcoin?
Because Monero is designed to obscure transaction details, amounts, senders, and recipients, making blockchain analysis much harder. Bitcoin transactions are permanently public and increasingly traceable.
What is DoppelCart?
A network of over 119,000 fake e-commerce websites that steal payment card data from shoppers by impersonating 44,182 real brands. Discovered by German firm Nebty and reported this week as the largest fake-shop cluster ever documented.
What should I do if my card information is stolen?
Report it to your card issuer immediately. Turn on transaction alerts going forward. If Fullz data is involved, freeze your credit at Equifax, Experian, and TransUnion and report to the FTC at reportfraud.ftc.gov.