Track data is the information encoded on a payment card's magnetic stripe, mainly Track 1 and Track 2, holding the card number, expiry date, and service code. It is exactly what skimmers and shimmers steal, because whoever holds it can clone a working card.
What is track data, in plain English?
Every magnetic-stripe card carries a few narrow bands of encoded characters. The two that matter for fraud are Track 1, which includes the cardholder name along with the account number and expiry, and Track 2, which carries the account number, expiry, and a short service code that tells a terminal how the card should be handled. Together this is the raw material a point-of-sale reader uses to authorize a swipe.
The problem is that track data is enough to build a counterfeit magstripe card. It is not a picture of the plastic; it is the machine-readable payload. Copy it onto a blank card with a writer and you have a functioning clone that swipes like the original. That is why criminals prize it and why it trades on carding markets as dumps.
In the fraud stack, track data sits at the very front of card-present and fallback fraud. It is the ingredient stolen by skimmers on ATMs and pumps, by shimmers reading chip cards, and by breaches of merchant systems. Because it is so dangerous, PCI DSS bans storing full track data after a transaction is approved, full stop.
How stolen track data becomes fraud
The path from a compromised stripe to a real loss is short and well worn:
- Capture — Skim or shim the card. A device on an ATM, pump, or terminal reads the stripe, or a breach dumps stored track data from a merchant.
- Sell — List it as dumps. Track records are packaged and sold on carding markets, priced by card type, region, and freshness.
- Clone — Write to a blank card. A buyer encodes the track onto blank plastic, producing a counterfeit that swipes like the real thing.
- Cash out — Buy goods or withdraw cash. The clone is used in stores that fall back to swipe, or at ATMs, before the issuer flags the account.
Who touches track data?
Who | Their role |
The cardholder | Owns the card whose stripe is copied; usually unaware until fraudulent charges appear. |
The skimmer operator | Installs capture devices or breaches systems to harvest track records at volume. |
The carding market | Buys and resells the stolen dumps, connecting harvesters with cash-out crews. |
The issuer and acquirer | See the counterfeit swipes and carry the fraud loss; the first to spot cloned-card patterns. |
What it looks like in practice
In practice
A customer fills up at a gas station and swipes as normal. Hidden inside the pump, a skimmer records the Track 2 data along with a keypad camera catching the PIN. The card keeps working, so nothing seems wrong.
Two weeks later that track record is encoded onto a blank card and used for swipe purchases in another state, plus an ATM withdrawal. The issuer's model flags a cluster of counterfeit-tagged transactions from the same gas station BIN range and freezes affected cards, tracing them back to a single compromised location.
Why it matters to operators
Track data is one of the clearest early-warning signals you get. A breach or skimming find that exposes it does not mean fraud might happen someday; it means cloning is imminent and you likely have days, not months, to reissue or watch the affected cards. Treating a track-data exposure as urgent is the difference between a contained event and a wave of counterfeit losses.
It also shapes compliance exposure. Storing full track data post-authorization is a direct PCI violation, so an operator who finds it in logs, memory dumps, or backups has both a security incident and a regulatory problem to close out fast.
What to watch in the data
- Common point of compromise. A cluster of cloned-card fraud tracing back to the same merchant or ATM is the classic skimming signature.
- Counterfeit entry mode. Swiped transactions carrying a counterfeit or magstripe-fallback indicator on cards that normally use chip.
- Stored track fields. Full Track 1 or Track 2 sitting in logs, databases, or memory after authorization is a PCI red flag, not just a bug.
- Geographic jumps. A card swiped in one region minutes or hours after legitimate use somewhere far away.
- Fresh dumps chatter. A spike in cloned-card fraud on your BINs can trail a new batch of dumps hitting carding markets.
Quick questions
What is the difference between Track 1 and Track 2?
Track 1 holds the cardholder name plus the account number and expiry, while Track 2 is a shorter numeric record with the account number, expiry, and service code. Track 2 is the one most terminals read and most often targeted, because it alone is enough to clone a magstripe.
Does chip-and-PIN stop track data theft?
Chip transactions use dynamic data that cannot simply be replayed, which is why EMV cut cloning sharply. But shimmers can still read chip cards, and any fallback to magstripe or a card used at a swipe-only terminal reopens the risk.
Can stored track data ever be kept legally?
No. PCI DSS prohibits storing full track data, the card verification value, or the PIN block after a transaction is authorized. Finding it retained anywhere is a compliance failure that has to be remediated.
What are dumps?
Dumps are stolen track data records sold on carding markets, typically priced by card brand, issuing region, and how fresh the data is. Buyers encode them onto blank cards for in-person cash-out.
How is track data stolen at scale?
Physical skimmers and shimmers grab it card by card, but the largest hauls come from breaches of merchant or processor systems that improperly stored or intercepted the data in transit.
What should a team do after a track-data exposure?
Treat it as imminent cloning risk: identify affected cards, coordinate reissue or heightened monitoring, contain and report the PCI incident, and watch for counterfeit-mode transactions on the exposed range.
Go deeper
- EMVCo ↗ — Maintains the EMV chip and 3-D Secure specifications for card payments.
- PCI Security Standards Council ↗ — Security standards for handling cardholder data, including PCI DSS.

