Skimming

Skimming is the theft of payment card data at the moment a card is used, by a device secretly attached to or installed inside a legitimate card reader. The terminal works normally, the transaction completes, and the cardholder has no indication anything happened. The captured data is later used to produce counterfeit cards or to make purchases online.

Card skimming remains concentrated where terminals are unattended and unsupervised: ATMs, fuel pumps and standalone kiosks.

What is captured Card track data, and often the PIN
Skimmer Reads the magnetic stripe, usually via an overlay on the card slot
Shimmer A thin device inserted into the reader that intercepts chip communication
PIN capture Pinhole camera or an overlay keypad above the real one
Highest-risk locations ATMs, fuel pumps, unattended kiosks
Downstream use Counterfeit cards, ATM withdrawals, card-not-present purchases

How skimming works

A skimmer is a reader placed over or inside the card slot that copies the magnetic stripe as the card passes. Modern versions are thin, molded to the specific terminal model, and increasingly transmit wirelessly, so the operator never has to return to collect the device — which removed the main opportunity to catch them.

A shimmer addresses chip cards. It is a paper-thin circuit inserted into the reader slot that sits between the chip and the terminal’s contacts and records the exchange. It cannot clone a chip — the chip’s cryptographic response is unique per transaction by design — but it captures enough card data to be useful elsewhere, particularly where a magnetic stripe fallback is accepted.

PIN capture is the other half, and it is what converts stolen data into cash. A pinhole camera positioned above the keypad, or a false keypad laid over the real one, records entry. Card data without a PIN supports purchases; card data with a PIN supports withdrawal.

The deployment pattern follows opportunity. Fuel pumps are outdoors, often on a universal lock, and can be opened in under a minute. ATMs away from branches go unexamined for long periods. Both are used by people in a hurry who have no reason to inspect the machine.

Why chip cards did not end skimming

EMV chips made counterfeiting the card difficult, and the fraud moved rather than stopped.

  • The magnetic stripe is still there. Most cards carry one for fallback and international use, and where it is accepted, skimmed stripe data still works.
  • Card-not-present use needs no card at all. The number, expiry and name skimmed from a stripe are sufficient online, where no chip is present to authenticate.
  • Unattended terminals upgraded slowly. Fuel dispensers in particular ran years behind other merchant categories on EMV deployment, keeping a large installed base of stripe-reading equipment in exactly the least supervised locations.

The general lesson is worth keeping: a control that authenticates the card does nothing about a channel where the card is not presented. Chip authentication is genuine security applied to one interaction, and skimming routes around it into another.

Why it matters for identity verification

Skimming is a data capture problem, and identity verification does not prevent a device being fitted to a fuel pump. Being clear about that is more useful than claiming otherwise.

Where identity work does apply is downstream, because skimmed data has to be monetized and every route to monetization passes through an identity decision. Card details are aggregated into fullz and sold; buyers use them to open accounts, register with payment services, or fund wallets. That is application fraud, and it is catchable.

The cash-out side is the same story. Withdrawals and transfers from skimmed cards are routed through accounts opened for the purpose — a bank drop — and those accounts are created by someone presenting an identity that can be tested.

So the honest position is narrow and real: verification does not stop the skimmer, it raises the cost of using what the skimmer collects.

Skimming compared with related techniques

Skimmer Shimmer Digital skimming
Target Magnetic stripe Chip interface Online checkout page
Physical device Yes — overlay or internal Yes — inside the slot No — injected script
Captures PIN With a camera or overlay keypad With a camera or overlay keypad Captures whatever the form collects
Detectable by the cardholder Sometimes, by inspection Rarely No
Typical location ATMs, fuel pumps ATMs, retail terminals Compromised ecommerce sites

Digital skimming is included because the name is now used for both. It is a different attack — malicious JavaScript on a checkout page harvesting details as they are typed — and it shares only the principle that the theft happens at the point of entry while everything appears to work.

What skimming controls cannot do

Inspection catches the crude ones. Tugging the card slot and covering the keypad are worth doing, and they do not detect an internal skimmer or a shimmer, which leave no external trace at all.

Anti-skimming hardware is an arms race. Jamming and detection modules work against known designs and are reverse-engineered in turn.

Detection is usually retrospective. Most skimmers are found by correlating fraud back to a common point of purchase — which means the device was already operating for some time, and every card used in that window is affected.

Frequently asked questions

What is the difference between a skimmer and a shimmer?

A skimmer reads the magnetic stripe, usually from an overlay on the card slot. A shimmer is a thin device inserted inside the reader that intercepts communication with the chip. A shimmer cannot clone the chip, because the chip’s response changes every transaction, but it captures card data that remains useful online or where stripe fallback is accepted.

Can a chip card be skimmed?

The chip itself cannot be cloned from a skimmed read. The card can still be compromised, because most chip cards also carry a magnetic stripe, and because the card number and expiry are enough for card-not-present purchases where no chip is involved.

Where does skimming happen most?

At unattended, unsupervised terminals — ATMs away from branches, fuel pumps, and standalone kiosks. These can be accessed without being observed and are used by people who have no reason to inspect the machine.

How do people find out they have been skimmed?

Usually from the fraudulent transactions rather than from the skimming. There is frequently a gap of weeks between capture and use, and investigators identify the compromised terminal afterward by finding the point of purchase that every affected card has in common.

Related reading

Discover Our Solutions

Exploring our solutions is just a click away. Try our products or have a chat with one of our experts to delve deeper into what we offer.

Report
Mapping the Rise of AI-Powered Identity Fraud

AI didn't just make fraud faster. It made it a system. We analyzed millions of identity interactions to map how identity attacks are evolving across regions, attack types, and sophistication levels — and what organizations need to rethink to keep pace.

See the Data