SardineCon SF/2026

Learn More

What is Card skimming?

SUBSCRIBE

Card skimming is capturing card data with a hidden device attached to an ATM, gas pump, or checkout terminal, often paired with a tiny camera or fake keypad to grab the PIN too. One rigged machine can feed a whole wave of later fraud.

What is card skimming, in plain English?

Card skimming is the theft of card data at a physical machine using a hidden capture device. The classic skimmer is an overlay or insert placed on an ATM, gas pump, or checkout terminal that reads the magnetic stripe as the card passes through. To make the stolen data usable at ATMs, skimmers are often paired with a pinhole camera or a fake keypad overlay that records the PIN at the same time.

The customer notices nothing. The machine functions normally, the transaction completes, and the skimmer silently stores the card details. That is what makes skimming so productive: a single compromised device can quietly harvest data from everyone who uses it over days or weeks before anyone spots it.

Skimming is a data-supply technique, the front end of card-present fraud. The stripe data it captures feeds cloning and dumps, and later shows up as in-person or ATM fraud. Its most important operational property is that all the resulting fraud shares one thing: the victims all used the same compromised terminal.

How skimming feeds later fraud

  1. Rig — Install the skimmer. A capture device goes onto an ATM, pump, or terminal, often with a camera or fake keypad for the PIN.
  2. Harvest — Collect card data. Every card used at the rigged machine is silently captured while the machine works normally.
  3. Clone — Turn data into cards. Stolen stripe data is written to blank cards or sold as dumps for others to use.
  4. Cash out — Spend or withdraw. Cloned cards and stolen PINs are used for in-person purchases and ATM withdrawals.

Who is involved?

Who

Their role

The skimmer operator

Installs and retrieves the capture device and harvests the stolen data.

The machine owner

Owns the ATM, pump, or terminal and is responsible for tamper detection and inspection.

The cardholders

Everyone who used the compromised machine and had their card and possibly PIN captured.

The issuer

Sees a cluster of fraud whose victims share one common point of purchase.

What it looks like in practice

In practice

A gas station pump gets fitted with an internal skimmer and a small camera aimed at the keypad. For two weeks, every driver who pays at that pump has their card data and PIN captured while fueling up normally. No one suspects a thing.

Then the fraud starts landing across dozens of unrelated cardholders at once: ATM withdrawals and in-person purchases in a different city. The issuer's analysts run a common-point-of-purchase check and find the single thread connecting all the victims: they all used that one pump within the same window. That points investigators straight at the compromised machine, which is inspected and found to be rigged.

Why the common point matters

Skimming fraud looks scattered at first: many different cardholders, in many places, defrauded around the same time with no obvious link between them. The link is not in the fraud transactions themselves, it is in their shared history. Every victim used the same rigged machine, so common-point-of-purchase analysis, working backward to find the one merchant or terminal they all touched, is the thread investigators follow.

Finding that common point does two things: it locates the compromised device so it can be pulled, and it lets the issuer proactively reissue every card that used it before more fraud lands. On the prevention side, the defenses are physical: tamper-proof hardware, regular terminal inspections, and prompt response to tamper alerts. Because skimming feeds cloning and dumps, cutting it off at the machine stops a whole downstream wave.

What to watch in the data

  • Common point of purchase. A sudden cluster of unrelated cardholders defrauded together whose one shared touchpoint is a single terminal.
  • ATM and pump concentration. Fraud tracing back to self-service machines, which are prime skimmer targets.
  • PIN-based withdrawals. ATM cash-outs alongside stolen stripe data suggest a paired camera or keypad overlay.
  • Delayed onset. A burst of fraud starting well after the victims' legitimate use, reflecting the harvest-then-cash-out lag.
  • Tamper alerts. Devices reporting interference or physical tampering that warrant immediate inspection.

Quick questions

How is skimming different from shimming?

Skimming captures magnetic-stripe data with a device on the outside of a reader. Shimming captures chip data with a thin device inside the chip slot. Skimmed stripe data is more directly usable for cloning than shimmed chip data.

Why add a camera or fake keypad?

To capture the PIN. Stripe data alone lets a fraudster clone a card, but ATM withdrawals need the PIN too. A pinhole camera or keypad overlay records it as the customer types, completing the package.

How do investigators find the skimmer?

Through common-point-of-purchase analysis: linking a cluster of newly defrauded cards by the one terminal or ATM they all used before the fraud started. That shared point reveals where the skimmer is installed.

Did chip cards stop skimming?

Chip reduced the value of skimmed stripe data, since cloned magstripe cards cannot pass a proper chip check. But skimming persists where magstripe fallback and stripe-only machines exist, and the data still fuels online and fallback fraud.

What defends against skimming?

Tamper-resistant and tamper-evident hardware, regular physical inspections of ATMs and pumps, staff awareness, and fast reissue once a common-point-of-purchase pattern is confirmed to limit downstream fraud.

Go deeper

What to know alongside Card skimming