What Is ATM Skimming? | Bankrate (2024)

Our writers and editors used an in-house natural language generation platform to assist with portions of this article, allowing them to focus on adding information that is uniquely helpful. The article was reviewed, fact-checked and edited by our editorial staff prior to publication.

Key takeaways

  • ATM skimming is a type of payment card fraud that involves hidden recording devices.
  • Skimming devices can be physically attached to ATMs.
  • Consumers can protect themselves by being vigilant.
  • E-skimming, where hackers inject malicious code into websites to steal credit card data, is on the rise.

ATM skimming is a type of payment card fraud. It’s a way of stealing PINs and other information off credit cards, ATM cards and debit cards by rigging machines with hidden recording devices.

Bank ATMs and payment terminals at gas pumps and other merchants are the targets of this scam. Thieves then use the stolen information to produce fake cards and spend victims’ money or take cash straight from their bank accounts.

“If they are able to retrieve the card number itself, it’s common to use those in online marketplaces or to sell the card numbers in batches to other criminal groups who may attempt to use them for fraudulent purchases,” says Nathan Wenzler, chief security strategist at Tenable, a cybersecurity firm in Columbia, Maryland.

Here is what you need to know about ATM skimming and how to protect yourself.

Methods of ATM skimming

Thieves employ several techniques to steal data that’s embedded in the magnetic stripe on credit and debit cards:

  • A plastic overlay placed over the ATM keypad captures PINs as they are entered.
  • An overlay placed over the card insertion slot records the data on the magnetic stripe.
  • Tiny cameras placed on an ATM record keypad entries and your fingers as you type.
  • An overlay that covers the whole ATM faceplate is embedded with cameras and card-slot and keypad overlays.

“Skimmers are getting harder and harder to detect, especially with the advent of 3D printers and other inexpensive fabrication devices,” warns Wenzler.

In some cases, skimming devices don’t even need to be physically connected to the card reader. Instead, as they collect consumers’ data they transmit the information to the thief via Bluetooth technology.

Even chip-enabled payment cards, which are more secure than magnetic stripe cards, are vulnerable to theft. By placing a super-thin shim between the chip and the chip reader inside the ATM, thieves can capture your PIN and other card information. These devices are called “shimmers,” and as chip technology becomes more prevalent, they are starting to supplant skimmers as thieves’ choice tool.

How prevalent is ATM skimming?

You hear quite a lot about ATM skimming these days, especially at gas pumps. It’s a scam that costs consumers and U.S. financial institutions more than $1 billion each year.

As mentioned, over 161,000 cards were compromised by skimming in 2022. Furthermore, 2,730 separate financial institutions were affected by a customer’s card being compromised.

California was the most targeted state for skimming scams, accounting for 47 percent of all skimming cases. The northeastern U.S. was also a frequent target — New York, New Jersey, Pennsylvania, Maryland and Virginia collectively accounted for 29 percent of skimming cases.

“ATMs and gas pumps are certainly the most common targets,” Wenzler says, “but customers should be aware and vigilant of any card reader anywhere, whether that’s restaurants, retail stores, coffee shops or wherever else you may swipe your card.”

Also, wireless technology enables cyber-thieves to retrieve stolen PINs and other card data “without approaching the ATM ever again, making it very difficult to catch them in the act,” Wenzler says.

Ways to avoid ATM skimming

To avoid becoming a victim of ATM skimming and possibly having your bank account cleaned out, follow these tips:

  • Go with cardless ATM transactions. Using your smartphone and your bank’s mobile app, you can conduct ATM transactions from anywhere, without a physical debit card.
  • Use debit and credit cards with chip technology, which is more secure.
  • Run your debit card as a credit card transaction and don’t enter your PIN, or use a credit card to begin with.
  • Use a mobile payment system such as Google Pay, Apple Pay, Samsung Pay or PayPal.
  • Check your bank statements regularly for suspicious transactions; sign up for account alerts and notifications.

Besides using safer payment methods, there are some physical, common-sense ways to avoid becoming an ATM skimming victim:

  • Don’t use ATMs located in dark, out-of-the-way places, in bars and restaurants or in areas with lots of tourists. Go to your bank or inside a store to use an ATM.
  • If the ATM doesn’t immediately return your card after the transaction, waste no time in reporting it to the card issuer.
  • Look over the ATM for signs of skimmers or ask the store manager to do it for you. Don’t use ATMs that have damaged or loose parts or look as if they have been tampered with.
  • “Try wiggling the card reader area to see if it feels loose or if there is a ‘cover’ over it,” advises Wenzler. “That could be a sign of a skimmer having been placed on top of the actual card reader itself.”
  • Use a gas pump that is within view of the gas station attendant or pay inside.
  • Cover the PIN pad when you enter your PIN – even if nobody is around.

Beware of e-skimming

While some criminals skulk around banks and stores to attach skimmers to physical payment terminals, others steal your credit and debit card data without getting out of their pajamas.

“Cyber-criminals now practice the concept of digital skimming or e-skimming,” says Ameet Naik, security evangelist and director of product marketing at Cloudflare, a California-based cybersecurity company. “Instead of placing a physical device on the ATM, they inject a piece of malicious code into a website script that skims credit card numbers from checkout pages on e-commerce sites.”

When there is an online payment transaction, the business collects personal data from the buyer, explains Naik. This usually includes name, email address, phone number, password, payment card data and verification code. “This data is most vulnerable at the point of entry,” Naik says.

The store, payment processor or bank is often not aware that skimming has occurred, Naik says, because the information was taken from the consumer’s device, not a company server.

“The lack of visibility means that the attacks often go undetected for weeks or months, while hackers yield a rich bounty of credit card numbers to sell on the dark web,” he says.

Ways to avoid e-skimming:

  • Don’t enter your card number repeatedly on a website. “If your trusted merchant has an option to save the card number for future purchases, choose it so as to minimize the times you have to type in your information,” advises Naik.
  • Use alternative payment methods such as Apple Pay, Google Pay or PayPal so you don’t have to type in payment card information. “However, consumers must ensure they use strong passwords to secure these services and avoid account compromise,” Naik says.
  • Be on the lookout for fake checkout pages that impersonate an online merchant. “Be especially wary of payment transactions that appear to fail,” warns Naik. “If that happens, immediately contact the card issuer who can place a fraud alert on your account.
  • Monitor your credit reports and bank and credit card statements routinely for suspicious activity, and report it right away.

Bottom line

Whether you’re using a physical bank ATM, a point-of-sale terminal at a merchant or doing cardless ATM transactions, there is always a risk of fraud. Chip-enabled credit and debit cards are safer than magnetic stripe cards, but even those can be hacked.

“Frankly, until we can move away from using magnetic stripes for transactions, the technology that creates skimmers will continue to advance and improve, resulting in more attacks against more devices around the globe,” Wenzler says.

Fortunately, you can minimize your risk exposure by following the tips and advice outlined here and staying vigilant.

— Bankrate’s René Bennett contributed to an update of this story.

What Is ATM Skimming? | Bankrate (2024)

FAQs

What Is ATM Skimming? | Bankrate? ›

Methods of ATM skimming

How do you tell if your card has been skimmed? ›

You won't know that your card has been skimmed until you see unusual transactions, which is why it's important to regularly monitor your account and review card statements. You can also set up card alerts to get emails, texts or app notifications for new transactions.

What to do if your ATM card is skimmed? ›

Contact your bank: The first thing you should do is contact your bank or card issuer to report the fraudulent activity. They can work quickly to cancel any compromised cards and issue a replacement to prevent the criminal from using it any further.

Does tap to pay avoid skimmers? ›

Use tap to pay or contactless pay whenever you can. These methods are usually safer because the skimmer can't grab your card info like it can when you slide or dip. This uses Near Field Communication (NFC) technology, which only works over a very short distance (a few centimeters).

Do skimmers get your PIN? ›

Skimming occurs when devices illegally installed on or inside ATMs, point-of-sale (POS) terminals, or fuel pumps capture card data and record cardholders' PIN entries.

What is the simplest way to protect yourself from ATM skimmers? ›

How to Protect Yourself from Skimming Fraud
  • Inspect the machine carefully before using it. ...
  • Shield the keypad while entering the PIN. ...
  • Use ATMs inside bank branches or well-lit areas with surveillance cameras. ...
  • Regularly check bank statements and transaction history to ensure all transactions are genuine.

What is an example of ATM skimming? ›

Methods of ATM skimming
  • A plastic overlay placed over the ATM keypad captures PINs as they are entered.
  • An overlay placed over the card insertion slot records the data on the magnetic stripe.
  • Tiny cameras placed on an ATM record keypad entries and your fingers as you type.
May 31, 2024

What is the penalty for ATM skimming? ›

California skimming fraud penalties

Misdemeanor penalties: Up to $1,000 fine and one year in county jail. Felony penalties: Up to $10,000 fine and three years in county jail.

How do I stop my card from being skimmed? ›

Tips to Avoid Being Skimmed
  1. Do a quick scan. Before using any machine, take a look to make sure it hasn't been tampered with. ...
  2. Be wary of non-bank ATMs. ...
  3. Check the keypad. ...
  4. Block your PIN. ...
  5. Use mobile wallet. ...
  6. Pay inside. ...
  7. Stay in public view. ...
  8. Check your account regularly.

Can I get my money back if my card was skimmed? ›

Most bank policies have protections for consumers who experience card fraud or unauthorized electronic transactions. For example, if someone uses your debit card without your consent and you file a dispute, your bank will likely refund the unauthorized transaction.

Do skimmers work on chip cards? ›

Key takeaways. Chip cards are less vulnerable to skimming than magnetic stripe cards, but they aren't completely safe. Crooks can still capture your card information from a chip card using a technique called shimming. Shimming allows criminals to create fake credit cards with your card information.

Is there a device to detect skimmers? ›

Skim Scan can even detect tiny card skimmers hidden inside bezels and card readers on the outside of machines. Skim Scan was developed by the same engineers that created BlueSleuth Bluetooth skimmer locator already in use by dozens of local, state and federal skimmer task forces.

How to avoid skimmers at ATMs? ›

7 Ways to Protect Yourself from ATM Skimming
  1. Know what to look for. ...
  2. Look for hidden cameras. ...
  3. Pay attention to the keypad. ...
  4. Shield your PIN. ...
  5. Be aware of your surroundings. ...
  6. Get to know your financial institution. ...
  7. Know what's happening Review your statement and keep an eye out for anything that seems out of place.

How to detect a skimmer device? ›

Check For Hidden Text Or Graphics:

Make sure that the text and graphics should be unobscured and aligned. If a credit card skimmer has been installed on the machine, you may notice the covered graphics or text. You can see the partially concealed graphics such as a cut off the word.

Is money from an ATM traceable? ›

Yes cash can be tracked, down to a single note, but it's extremely hard and expensive, as most of us here with a little more knowledge understand. No big conspiracies, just a sobering appraisal of the state of the art.

How to tell if an ATM has been tampered with? ›

The Federal Deposit Insurance Corporation (FDIC) has recommended the following on knowing what to look for:
  1. Card-reader overlays. The most common ATM skimmer, and perhaps the easiest device to detect, is the card-reader overlay. ...
  2. Hidden cameras. ...
  3. PIN-capture overlays. ...
  4. Fake ATM faceplates.

Top Articles
Airbnb: What is the Go To Market strategy of the vacation rental site that revolutionized the world?
6 Common VPN Protocols Explained
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Shasta County Most Wanted 2022
Energy Healing Conference Utah
Aaa Saugus Ma Appointment
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Holzer Athena Portal
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Selly Medaline
Latest Posts
Article information

Author: Ouida Strosin DO

Last Updated:

Views: 6365

Rating: 4.6 / 5 (56 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Ouida Strosin DO

Birthday: 1995-04-27

Address: Suite 927 930 Kilback Radial, Candidaville, TN 87795

Phone: +8561498978366

Job: Legacy Manufacturing Specialist

Hobby: Singing, Mountain biking, Water sports, Water sports, Taxidermy, Polo, Pet

Introduction: My name is Ouida Strosin DO, I am a precious, combative, spotless, modern, spotless, beautiful, precious person who loves writing and wants to share my knowledge and understanding with you.