SardineCon SF/2026

Learn More

What is Card cloning?

SUBSCRIBE

Card cloning is copying the data from a real card, usually the magnetic stripe, onto a fake card to use in person. A cloned card lets a criminal spend at a store or ATM as if they were holding the genuine card, which is why the technique targets older magstripe flows rather than the chip.

What is card cloning, in plain English?

A magnetic stripe stores card data as static, unchanging information. Card cloning takes that data, captured from a real card, and writes it onto a blank or re-encoded card. The result is a counterfeit that carries a genuine cardholder's details. Swiped at a terminal, it behaves like the real thing, letting the criminal buy goods or pull cash at an ATM on someone else's account.

The stripe data usually comes from skimming, a hidden device on an ATM, gas pump, or terminal, or from stolen track data sold as dumps. Because the magstripe is static, whoever holds a copy can reproduce it. This is what separates cloning from online card fraud: it produces a physical, swipeable card for card-present use.

The catch for the criminal is the chip. Cloned magstripe data cannot pass an EMV chip check, because the chip generates a unique code for each transaction that a static copy cannot reproduce. So cloning depends on forcing a swipe: exploiting fallback when the chip appears to fail, or finding old magstripe-only terminals that never read a chip at all.

How a card gets cloned and used

  1. Capture — Steal the stripe data. A skimmer, compromised terminal, or purchased dump provides the card's magnetic-stripe track data.
  2. Write — Encode a blank card. The stolen data is written onto a blank magstripe card, creating a working counterfeit.
  3. Deploy — Force a swipe. The cloned card is used at magstripe-only terminals or via fallback where chip reads are bypassed.
  4. Cash out — Spend or withdraw. The criminal buys resellable goods or pulls cash, often far from the real cardholder's usual area.

Who is involved?

Who

Their role

The skimmer or data seller

Captures or supplies the stolen magnetic-stripe track data.

The cloner

Encodes blank cards with the stolen data and puts them to use.

The merchant or ATM

Accepts the swipe, especially magstripe-only or fallback flows, and may bear liability.

The cardholder and issuer

See charges or withdrawals the genuine cardholder never made, often in a distant location.

What it looks like in practice

In practice

A cardholder uses her debit card at a gas pump that, unknown to her, has a skimmer inside and a pinhole camera over the keypad. Her stripe data and PIN are captured. Days later, her data is written onto a blank card.

That night, an ATM in another state dispenses several cash withdrawals from her account using the cloned card and stolen PIN. Her bank's monitoring flags the geography: a swipe-based ATM withdrawal in a city hundreds of miles from where she just bought coffee an hour earlier is physically impossible for one person. The card is frozen, but the cash is gone, and the gas pump has fed several other victims the same way.

Why chip changed the picture

The rollout of chip cards (EMV) cut card cloning sharply in chip-enabled markets. Because the chip produces a unique cryptographic code per transaction, static stripe data copied onto a fake card cannot satisfy a proper chip read. Fraud did not disappear, though; it moved. Much of it shifted online to card-not-present channels, and the cloning that remains hunts for the gaps chip did not close.

Those gaps are what operators watch. Cloning now lives in magstripe fallback, where a terminal accepts a swipe because a chip read supposedly failed, in magstripe-only and unattended terminals like some older pumps and ATMs, and in regions where chip adoption is uneven. The strongest single tell is geographic impossibility: a swipe in a place the genuine cardholder could not have reached given their last transaction.

What to watch in the data

  • Stripe use on chip cards. A swipe on a card known to be chip-capable, especially when a chip read was available, is suspicious.
  • Fallback transactions. Repeated magstripe fallback after a claimed chip failure can indicate deliberate downgrade to a cloneable path.
  • Impossible geography. A swipe in a location the cardholder could not physically reach given the timing of their last transaction.
  • ATM and unattended terminals. Cash withdrawals or purchases at magstripe-only, self-service, or unattended machines.
  • Common point of purchase. Clusters of cloned-card fraud whose victims all used the same skimmed terminal earlier.

Quick questions

Why can a cloned card not use the chip?

The chip generates a one-time cryptographic code for each transaction, which a static copy of the magnetic stripe cannot reproduce. Cloned data only satisfies a magstripe read, so fraudsters must force a swipe or fallback.

Where does the stripe data come from?

Mainly skimming, using a hidden device on an ATM, pump, or terminal, often paired with a camera or fake keypad to grab the PIN, and from stolen track data sold as dumps on criminal markets.

Did chip cards end card cloning?

They cut it sharply in chip markets but did not end it. Cloning persists through magstripe fallback, magstripe-only and unattended terminals, and regions with uneven chip adoption, while much fraud shifted online instead.

What is the clearest detection signal?

Geographic impossibility. If a card is swiped in a location the genuine holder could not have reached in the time since their last transaction, that is a strong indicator of a cloned card in use.

How is cloning related to skimming and dumps?

Skimming and dumps are how the stripe data is obtained; cloning is the act of writing that data onto a fake card and using it. They are consecutive stages of the same card-present fraud chain.

Go deeper

What to know alongside Card cloning