Skimming
Skimming is the theft of payment card data at the moment a card is used, by a device secretly attached to or installed inside a legitimate card reader. The terminal works normally, the transaction completes, and the cardholder has no indication anything happened. The captured data is later used to produce counterfeit cards or to make purchases online.
Card skimming remains concentrated where terminals are unattended and unsupervised: ATMs, fuel pumps and standalone kiosks.
| What is captured | Card track data, and often the PIN |
| Skimmer | Reads the magnetic stripe, usually via an overlay on the card slot |
| Shimmer | A thin device inserted into the reader that intercepts chip communication |
| PIN capture | Pinhole camera or an overlay keypad above the real one |
| Highest-risk locations | ATMs, fuel pumps, unattended kiosks |
| Downstream use | Counterfeit cards, ATM withdrawals, card-not-present purchases |
How skimming works
A skimmer is a reader placed over or inside the card slot that copies the magnetic stripe as the card passes. Modern versions are thin, molded to the specific terminal model, and increasingly transmit wirelessly, so the operator never has to return to collect the device — which removed the main opportunity to catch them.
A shimmer addresses chip cards. It is a paper-thin circuit inserted into the reader slot that sits between the chip and the terminal’s contacts and records the exchange. It cannot clone a chip — the chip’s cryptographic response is unique per transaction by design — but it captures enough card data to be useful elsewhere, particularly where a magnetic stripe fallback is accepted.
PIN capture is the other half, and it is what converts stolen data into cash. A pinhole camera positioned above the keypad, or a false keypad laid over the real one, records entry. Card data without a PIN supports purchases; card data with a PIN supports withdrawal.
The deployment pattern follows opportunity. Fuel pumps are outdoors, often on a universal lock, and can be opened in under a minute. ATMs away from branches go unexamined for long periods. Both are used by people in a hurry who have no reason to inspect the machine.
Why chip cards did not end skimming
EMV chips made counterfeiting the card difficult, and the fraud moved rather than stopped.
- The magnetic stripe is still there. Most cards carry one for fallback and international use, and where it is accepted, skimmed stripe data still works.
- Card-not-present use needs no card at all. The number, expiry and name skimmed from a stripe are sufficient online, where no chip is present to authenticate.
- Unattended terminals upgraded slowly. Fuel dispensers in particular ran years behind other merchant categories on EMV deployment, keeping a large installed base of stripe-reading equipment in exactly the least supervised locations.
The general lesson is worth keeping: a control that authenticates the card does nothing about a channel where the card is not presented. Chip authentication is genuine security applied to one interaction, and skimming routes around it into another.
Why it matters for identity verification
Skimming is a data capture problem, and identity verification does not prevent a device being fitted to a fuel pump. Being clear about that is more useful than claiming otherwise.
Where identity work does apply is downstream, because skimmed data has to be monetized and every route to monetization passes through an identity decision. Card details are aggregated into fullz and sold; buyers use them to open accounts, register with payment services, or fund wallets. That is application fraud, and it is catchable.
The cash-out side is the same story. Withdrawals and transfers from skimmed cards are routed through accounts opened for the purpose — a bank drop — and those accounts are created by someone presenting an identity that can be tested.
So the honest position is narrow and real: verification does not stop the skimmer, it raises the cost of using what the skimmer collects.
Skimming compared with related techniques
| Skimmer | Shimmer | Digital skimming | |
|---|---|---|---|
| Target | Magnetic stripe | Chip interface | Online checkout page |
| Physical device | Yes — overlay or internal | Yes — inside the slot | No — injected script |
| Captures PIN | With a camera or overlay keypad | With a camera or overlay keypad | Captures whatever the form collects |
| Detectable by the cardholder | Sometimes, by inspection | Rarely | No |
| Typical location | ATMs, fuel pumps | ATMs, retail terminals | Compromised ecommerce sites |
Digital skimming is included because the name is now used for both. It is a different attack — malicious JavaScript on a checkout page harvesting details as they are typed — and it shares only the principle that the theft happens at the point of entry while everything appears to work.
What skimming controls cannot do
Inspection catches the crude ones. Tugging the card slot and covering the keypad are worth doing, and they do not detect an internal skimmer or a shimmer, which leave no external trace at all.
Anti-skimming hardware is an arms race. Jamming and detection modules work against known designs and are reverse-engineered in turn.
Detection is usually retrospective. Most skimmers are found by correlating fraud back to a common point of purchase — which means the device was already operating for some time, and every card used in that window is affected.
Frequently asked questions
What is the difference between a skimmer and a shimmer?
A skimmer reads the magnetic stripe, usually from an overlay on the card slot. A shimmer is a thin device inserted inside the reader that intercepts communication with the chip. A shimmer cannot clone the chip, because the chip’s response changes every transaction, but it captures card data that remains useful online or where stripe fallback is accepted.
Can a chip card be skimmed?
The chip itself cannot be cloned from a skimmed read. The card can still be compromised, because most chip cards also carry a magnetic stripe, and because the card number and expiry are enough for card-not-present purchases where no chip is involved.
Where does skimming happen most?
At unattended, unsupervised terminals — ATMs away from branches, fuel pumps, and standalone kiosks. These can be accessed without being observed and are used by people who have no reason to inspect the machine.
How do people find out they have been skimmed?
Usually from the fraudulent transactions rather than from the skimming. There is frequently a gap of weeks between capture and use, and investigators identify the compromised terminal afterward by finding the point of purchase that every affected card has in common.
Related reading
- Debit card fraud — why skimmed debit cards produce the worst outcomes
- Credit card fraud — the broader category and its liability rules
- Carding — the market where skimmed data is sold
- Bank drop — the accounts used to cash out