Skip to content

Card Skimming

Card skimming is the copying of payment card data by an illegal card reader attached to a machine that reads cards, often alongside a hidden camera that records the PIN being entered. The card is copied rather than stolen, so the victim still has it and nothing looks wrong until the charges appear.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • The defining feature is that nothing is taken. The card stays in the cardholder's pocket, which is why skimming is almost never noticed at the time.
  • Copying the card is only half of it. Without the PIN the data is far less useful, and the Federal Trade Commission names two ways criminals get it: hidden cameras placed by the skimmer, and phishing the cardholder for it.
  • The targets include unattended machines and ordinary shop terminals. The FTC has warned about skimmers at fuel pumps and about scammers who "sneak illegal card skimmers onto payment terminals in stores."
  • A federal financial regulator treats it as a reportable security incident. NCUA's cyber-incident rule uses "card skimming at a credit union's ATM" as one of its examples.
  • The chip and the magnetic stripe are different things to a card network. The Federal Reserve treats them as separate card authentication methods that an issuer's fraud controls must address separately.

Definition

Card skimming is the theft of payment card data by means of a device that reads and stores the information encoded on a card when it is inserted into or swiped through a machine. The Federal Trade Commission's description is compact: "Skimmers are illegal card readers attached to payment terminals. These card readers grab data off a credit or debit card's magnetic stripe without your knowledge." The device is fitted to something the cardholder is already using: the card reader on an automated teller machine, a fuel pump, or a point-of-sale terminal in a shop. Because the card itself is copied rather than taken, the cardholder walks away with it and has no reason to think anything has happened.

Card data alone is worth less than card data plus a personal identification number, so where a PIN is needed the criminal has to obtain that separately. The FTC names two routes, writing about skimmers fitted to store terminals: scammers "might try to phish you, using texts or calls to get you to share your PIN, or set up hidden cameras by the card skimmers to record you entering your code." What follows is straightforward: "Once they have your information, the scammers create duplicate cards."

The phrase is used by federal financial regulators as a named category of incident rather than as slang. The National Credit Union Administration's cyber-incident notification rule adopted, as one of its examples of a reportable incident, "member information compromised as a result of card skimming at a credit union's ATM." The Department of Agriculture's Food and Nutrition Service uses the same phrase for state reporting on stolen food assistance benefits.

Advanced Explanation

Where the devices go, and why those places. The FTC's own warnings name three settings. Fuel pumps: its advice to drivers is to "make sure the gas pump panel is closed and doesn't show signs of tampering," noting that "many stations now put security seals over the cabinet panel" whose label reads "void" if the panel has been opened. That is a warning about a device fitted behind the panel, where a customer cannot see it. Store terminals: the FTC describes scammers who "sneak illegal card skimmers onto payment terminals in stores." And automated teller machines, where the National Credit Union Administration's reportable-incident example is "member information compromised as a result of card skimming at a credit union's ATM."

The fuel-pump problem has been treated as a hardware-design question as well as a crime. A 2019 Weights and Measures proposal reported in the Federal Register would bring credit and debit card skimmers within the scope of NIST Handbook 44 and require card readers used with fuel dispensers to "be designed and constructed to restrict access and tampering by unauthorized persons" and to carry "an event counter that records the date and time of access." The premise of both requirements is that the vulnerable part of a pump is the cabinet somebody can open.

The PIN is the second half, and it is the half that turns a copy into cash. A copied card number can be used for transactions that do not require a PIN. A copied card number together with the PIN can be used at an ATM to take money directly out of a deposit account. That is why the FTC treats capturing the code as a separate step with its own methods, a hidden camera aimed at the keypad or a phishing message or call asking for the number outright, and it is why shielding the keypad while entering a PIN is worth the two seconds: a camera cannot record what it cannot see, even where the reader has already been compromised. At the pump, the FTC's suggestion is more direct still: "If you use a debit card at the pump, run it as a credit card instead of entering a PIN."

The chip changed where the technique works, without ending it. The magnetic stripe and the chip are treated as two different ways of authenticating a card. The Federal Reserve's fraud-prevention guidance for debit card issuers tells them to consider whether their policies are effective "for each method used to authenticate the card (e.g., a chip or a code embedded in the magnetic stripe) and the cardholder (e.g., a signature or a PIN), and for different sales channels." Both FTC warnings describe the skimmer as reading "the magnetic stripe," which is the part of the card a simple reader can copy in a form another device can reproduce. The practical consequence is that the technique depends on a stripe still being read somewhere in the transaction.

How it is normally discovered, which is late. The cardholder has the card, so there is no moment of loss to notice. The FTC puts the consequence in one sentence: "You won't know your information has been stolen until you get your statement or an overdraft notice." What appears is a pattern on the account rather than an event: transactions in a place the cardholder has not been, sometimes beginning with a small transaction that tests whether the data works. Reviewing statements or alerts is therefore doing more work here than with a lost card, and the interval between the copy and its use can be long, because, as the FTC notes, "criminals sell the stolen data or use it to buy things online."

What this is not. It is not phishing, which obtains credentials by persuading a person to hand them over; the two often feed the same downstream crime and the technique is different. It is not account takeover, where the criminal gains control of the account itself and changes the contact details of record; a skimmed card produces unauthorized transactions on an account the victim still controls. And it is not identity theft in the sense of new accounts opened in someone's name, which has its own remedies. Each of those is covered separately.

The rules that decide who bears the loss are not on this page, and that is deliberate. A skimmed debit card produces unauthorized electronic fund transfers, and the federal rule that governs them sets a liability ceiling that turns on how quickly the cardholder reports after learning of the loss, with a separate outer limit measured from the statement. Those tiers, the two clocks and the error-resolution timetable are set out in full on the debit card and bank statement pages, and a skimmed credit card is governed by a different and more generous regime described on the credit card page. Reading the right one matters more than anything on this page, because the numbers differ and the clocks start in different places.

How to Remember

Nothing was stolen, so nothing looks stolen. A skimmer copies the card and leaves it with you, which is why the first sign is almost always a transaction rather than a missing card.

Used in a Sentence

“The three withdrawals came from a city she had never visited, and the bank traced them to card skimming at a fuel pump she had used the week before.”

How It Works

  1. An illegal card reader is attached to a machine that reads cards. An ATM, a fuel pump — often behind the cabinet panel — or a payment terminal in a shop.

  2. A way of capturing the PIN is added where one is needed. The FTC names a hidden camera positioned by the skimmer to record the code being entered, or a phishing text or call asking the cardholder for it.

  3. The cardholder uses the machine normally. The transaction completes, the card is returned, and nothing about the experience is unusual.

  4. The captured data is retrieved or transmitted, then either used directly or sold on, which is why the delay before the first fraudulent transaction can be substantial.

  5. The loss appears on the account as transactions the cardholder cannot account for, and is reported to the bank or issuer. Which rules then decide the outcome depends on whether the card was a debit card or a credit card.

A hypothetical, showing the pattern rather than the liability. Óscar uses an ATM whose card reader carries an illegal reader fitted over it and a hidden camera aimed at the keypad. He completes his withdrawal, takes his card, and nothing seems wrong.

Eleven days later a transaction of $1.00 appears on his account. That is the test: the small amount confirms the copied data works and attracts no attention. Over the following two days three ATM withdrawals follow, of $500, $500 and $400, so the total taken is $1 + $500 + $500 + $400 = $1,401.

Two things about that sequence are the useful part. The whole loss happened after the card had been used normally and while it was still in his wallet, so there was nothing to notice at the time. And the tell was available eleven days before the money went, in the form of a $1.00 transaction he did not make, which is precisely the size of item people ignore. What Óscar can recover depends on the rules for the card type he holds and on how quickly he reports; the debit card, bank statement and credit card pages set those out. All figures are hypothetical.

Pros and Cons

Card skimming has no upside, so what follows is what reduces exposure and what those measures do not reach.

What reduces exposure

  • Shielding the keypad while entering a PIN. It costs nothing and a hidden camera cannot record what it cannot see, even where the reader has already been compromised.
  • Giving the reader a brief check before inserting a card. The FTC's own test is whether it "look[s] different than other readers at the station," and whether it is "loose, off-center, or do parts of it wiggle" when handled.
  • At a fuel pump, checking that the cabinet panel is closed and that any security seal over it has not been broken. The FTC notes that an opened panel makes such a label read "void."
  • Running a debit card as a credit card at the pump rather than entering a PIN, which is the FTC's own suggestion and keeps the code out of reach.
  • Turning on transaction alerts, since the loss is discovered by noticing a transaction rather than by noticing a missing card.
  • Paying attention to a very small unexplained transaction, which can be the test that precedes the real withdrawals.

What those measures do not reach

  • A device fitted behind a fuel pump's cabinet panel is not visible to a customer at all, which is why the seal rather than the reader is the thing to look at there.
  • Nothing about the transaction itself signals a problem, so the technique defeats attentiveness at the moment it happens.
  • Discovery is delayed by design. The FTC's own formulation is that you will not know until the statement or an overdraft notice arrives.
  • Shielding the keypad protects the PIN and does nothing about the card data itself, which is enough for transactions that require no PIN.
  • A phished PIN defeats the same measure from a different direction, since nothing about the machine is involved at all.
  • A copied card can be used far from where it was skimmed, because the FTC records that criminals "sell the stolen data or use it to buy things online."

People Also Asked

Answers to the most frequently asked questions.

How is card skimming different from phishing?
By how the data is obtained. Skimming copies the card physically, through a device fitted to a machine the cardholder uses, with no interaction and nothing for the victim to fall for. Phishing obtains credentials by persuading a person to enter or disclose them, usually through a message impersonating a trusted organization. They frequently feed the same downstream crime, and the difference matters because there is nothing a cardholder could have declined to do in a skimming case.
Does a chip card stop skimming?
It changes where the technique works rather than ending it. The chip and the magnetic stripe are treated as different card authentication methods — the Federal Reserve tells debit card issuers to assess their fraud controls for "each method used to authenticate the card (e.g., a chip or a code embedded in the magnetic stripe)" — and skimming attaches to the stripe. That is why the technique has concentrated at unattended fuel pumps and older machines where a stripe is still read.
Why do I still have my card if it was skimmed?
Because nothing was taken. A skimmer reads and stores the data encoded on the card and the card stays with the cardholder, which is what makes the technique effective: there is no loss to report and no moment at which anything appears wrong. The Federal Trade Commission states the consequence plainly: "You won't know your information has been stolen until you get your statement or an overdraft notice." The delay can be substantial, because criminals may "sell the stolen data" rather than use it themselves.
What should I do if I think my card was skimmed?
Tell the bank or card issuer immediately, because the deadlines that decide the outcome start running from events you may not be tracking. Which rules apply depends on the card: a debit card produces unauthorized electronic fund transfers with a liability ceiling that rises with delay, while a credit card is governed by a separate and more generous regime. Those are set out on the debit card, bank statement and credit card pages, and the fraud page covers where else to report it.
Can I tell whether a machine has a skimmer on it?
Sometimes, and not reliably. The Federal Trade Commission's own checks are whether the reader looks different from the others at the same location, and whether it is "loose, off-center" or has parts that "wiggle" when handled; at a fuel pump it also advises checking that the cabinet panel is closed and that the security seal over it has not been voided. But a device fitted behind that panel is invisible to a customer, and a PIN obtained by a phishing text involves no hardware at all. That is why the durable defenses are behavioral rather than inspectional: shield the keypad, avoid entering a PIN where a credit run is available, and watch the account.

Sources

AdviceOnly maintains high editorial standards to improve the quality and accuracy of our educational content. Content is written with the assistance of artificial intelligence tools following a rigorous quality assurance process, and periodically reviewed by credentialed and experienced human financial advisors. References used include government data, academic papers, interviews with industry experts, and reputable primary sources. You can learn more about our efforts to produce accurate content in our editorial policy.

  1. Federal Trade Commission. "Watch out for card skimming at the gas pump."
  2. Federal Trade Commission. "Protect your SNAP benefits from illegal card skimmers."
  3. Code of Federal Regulations. "12 CFR Part 1005 — Electronic Fund Transfers (Regulation E)."

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor