Where the devices go, and why those places. The FTC's own warnings name three settings. Fuel pumps: its advice to drivers is to "make sure the gas pump panel is closed and doesn't show signs of tampering," noting that "many stations now put security seals over the cabinet panel" whose label reads "void" if the panel has been opened. That is a warning about a device fitted behind the panel, where a customer cannot see it. Store terminals: the FTC describes scammers who "sneak illegal card skimmers onto payment terminals in stores." And automated teller machines, where the National Credit Union Administration's reportable-incident example is "member information compromised as a result of card skimming at a credit union's ATM."
The fuel-pump problem has been treated as a hardware-design question as well as a crime. A 2019 Weights and Measures proposal reported in the Federal Register would bring credit and debit card skimmers within the scope of NIST Handbook 44 and require card readers used with fuel dispensers to "be designed and constructed to restrict access and tampering by unauthorized persons" and to carry "an event counter that records the date and time of access." The premise of both requirements is that the vulnerable part of a pump is the cabinet somebody can open.
The PIN is the second half, and it is the half that turns a copy into cash. A copied card number can be used for transactions that do not require a PIN. A copied card number together with the PIN can be used at an ATM to take money directly out of a deposit account. That is why the FTC treats capturing the code as a separate step with its own methods, a hidden camera aimed at the keypad or a phishing message or call asking for the number outright, and it is why shielding the keypad while entering a PIN is worth the two seconds: a camera cannot record what it cannot see, even where the reader has already been compromised. At the pump, the FTC's suggestion is more direct still: "If you use a debit card at the pump, run it as a credit card instead of entering a PIN."
The chip changed where the technique works, without ending it. The magnetic stripe and the chip are treated as two different ways of authenticating a card. The Federal Reserve's fraud-prevention guidance for debit card issuers tells them to consider whether their policies are effective "for each method used to authenticate the card (e.g., a chip or a code embedded in the magnetic stripe) and the cardholder (e.g., a signature or a PIN), and for different sales channels." Both FTC warnings describe the skimmer as reading "the magnetic stripe," which is the part of the card a simple reader can copy in a form another device can reproduce. The practical consequence is that the technique depends on a stripe still being read somewhere in the transaction.
How it is normally discovered, which is late. The cardholder has the card, so there is no moment of loss to notice. The FTC puts the consequence in one sentence: "You won't know your information has been stolen until you get your statement or an overdraft notice." What appears is a pattern on the account rather than an event: transactions in a place the cardholder has not been, sometimes beginning with a small transaction that tests whether the data works. Reviewing statements or alerts is therefore doing more work here than with a lost card, and the interval between the copy and its use can be long, because, as the FTC notes, "criminals sell the stolen data or use it to buy things online."
What this is not. It is not phishing, which obtains credentials by persuading a person to hand them over; the two often feed the same downstream crime and the technique is different. It is not account takeover, where the criminal gains control of the account itself and changes the contact details of record; a skimmed card produces unauthorized transactions on an account the victim still controls. And it is not identity theft in the sense of new accounts opened in someone's name, which has its own remedies. Each of those is covered separately.
The rules that decide who bears the loss are not on this page, and that is deliberate. A skimmed debit card produces unauthorized electronic fund transfers, and the federal rule that governs them sets a liability ceiling that turns on how quickly the cardholder reports after learning of the loss, with a separate outer limit measured from the statement. Those tiers, the two clocks and the error-resolution timetable are set out in full on the debit card and bank statement pages, and a skimmed credit card is governed by a different and more generous regime described on the credit card page. Reading the right one matters more than anything on this page, because the numbers differ and the clocks start in different places.