- Home/
- Credit Cards/
- Credit Card Skimming Is Getting Smarter—Here's How to Stay Safe
Credit Card Skimming Is Getting Smarter—Here's How to Stay Safe
August 27, 2026
August 27, 2026
Credit card skimming steals card data at physical terminals and online checkouts. The FBI estimates skimming costs financial institutions and consumers more than $1 billion each year.
Credit card skimming is the criminal practice of stealing card information during legitimate transactions. Devices on ATMs, fuel pumps, and point-of-sale terminals steal card data and PINs during real payments; web-based checkout skimming can also capture card data online. Installing a skimming device can take only seconds, especially when clerks are distracted. You can lower risk by tapping when possible, inspecting readers before inserting a card, preferring credit over debit when accounts are linked, and turning on real-time alerts. Those habits matter when comparing credit cards.
This guide is for everyday spenders who want practical defenses against credit card skimming.
Drivers and shoppers who pay at outdoor gas pumps, ATMs, or freestanding terminals
Online shoppers worried about checkout malware and e-skimming
People who still use debit at freestanding or outdoor terminals and want safer defaults
Readers supporting someone who relies on EBT or SNAP benefits cards
Travelers using cards in busy tourist corridors
Credit card skimming steals card data and PINs during real payments through hidden hardware. Online, Magecart-style attacks inject scripts into checkout pages to capture payment data. The FBI estimates the crime costs institutions and consumers more than $1 billion each year.
Per FBI and state consumer-protection guidance, credit card skimmer setups can include:
Hidden or internal devices: The FBI explains that skimmers can be installed on or inside ATMs, POS terminals, or fuel pumps.
Overlays and keypad covers: The FBI and Georgia Attorney General describe overlay-style readers and keypad covers designed to blend into legitimate terminals.
Wireless data theft: Per the FBI, devices can store card data for later download or transfer it wirelessly to nearby equipment.
Insert-style readers: Some skimmers sit inside the card path rather than as a bulky exterior shell, per FBI descriptions of devices installed in or over card readers.
Camera or keypad overlays for PINs: The FBI describes pinhole cameras and keylogging keypad overlays used to capture PIN entries.
Shimming devices: Thin inserts slip into the chip slot rather than sitting as an exterior overlay. The Georgia Attorney General's Consumer Protection Division notes shimmers are even harder to spot than classic skimmers. When a terminal supports contactless, the FBI advises tapping instead of swiping or inserting.
The FBI also notes that installing a skimming device can take only seconds, especially when clerks are distracted. A quick visual check before you pay still helps.
Digital skimming targets online checkouts without a physical device on the terminal.
Ecommerce skimming: Also known as "Magecart" attacks, these schemes inject malicious JavaScript into legitimate checkout pages to capture payment information as customers enter it, then send that data to attacker-controlled servers.
What criminals do with stolen data: Per the same New Jersey cybersecurity guidance, captured card details can be used for fraudulent purchases or sold. Treat any unexpected card-not-present charge as a signal to lock the card and call your issuer.
After any checkout risk, the FBI recommends routine monitoring and, when possible, email or text alerts for your accounts.
The FBI highlights fuel pumps, ATMs, POS terminals, freestanding convenience-store machines, and tourist areas among common skimming settings.
Outdoor gas pumps: The FBI notes fuel-pump skimmers can attach to internal wiring and stay out of view.
Standalone ATMs: The FBI flags freestanding ATMs in convenience stores among common skimming settings.
Tourist area merchants: The FBI lists tourist areas among common skimming settings and urges extra alertness there.
Small retail and POS terminals: The FBI includes POS terminals among common skimming settings and notes POS overlays used to capture EBT card data.
Freestanding and outdoor terminals: The FBI flags freestanding ATMs (such as those in convenience stores), outdoor fuel pumps, and POS readers among common skimming settings.
Benefit cards deserve special care. The FBI reports that Electronic Benefits Transfer (EBT) and similar mag-stripe benefits cards have been high-value targets since at least 2021, and EBT cardholders generally have more limited protections than holders of common credit and debit cards if funds are stolen. If you support someone on SNAP or related benefits, help them inspect terminals, cover the PIN pad, and check balances often.
The FBI advises avoiding debit when you have linked accounts and using a credit card instead. Review the differences between credit cards and debit cards before you decide which to tap or insert.
The FBI and Georgia Attorney General's Consumer Protection Division list practical checks before you pay:
Loose, crooked, damaged, or scratched parts: The FBI recommends inspecting readers for anything loose, crooked, damaged, or scratched before you insert a card.
Mismatched look versus nearby terminals: The Georgia Attorney General's office warns that hardware that looks loose, crooked, damaged, or unlike nearby terminals can signal a skimmer.
Keypad that feels thick or hard to press: The same Georgia guidance notes that a thick keypad or numbers that are hard to press can signal an overlay skimmer.
Tap when you can, inspect before you insert, and prefer supervised terminals when the choice is yours.
Inspect before insertion: The FBI recommends inspecting ATMs, POS terminals, and other readers for anything loose, crooked, damaged, or scratched before you pay.
Use contactless options when available: Tap the card instead of swiping or inserting when the terminal allows it—tap-to-pay is more secure and less likely to be compromised. The Georgia Attorney General's Consumer Protection Division also suggests a mobile wallet, such as Apple Pay or Google Pay, instead of swiping when you can.
Choose indoor payment terminals: When possible, pay inside rather than outside at the pump, and prefer well-lit indoor ATMs over isolated machines.
Shield your PIN: Cover the keypad as fully as possible when you enter your PIN to help block cameras from recording your entry.
Use bank-owned ATMs: Whenever possible, use well-lit indoor ATMs—ideally at bank branches—rather than freestanding machines in convenience stores, which the FBI flags among common skimming settings.
Online checkout fraud needs a different checklist than a gas pump.
Enable purchase alerts: The FBI recommends routine monitoring and, if possible, email or text-message alerts so you spot unauthorized charges quickly.
Prefer credit for online checkout: New Jersey cybersecurity guidance on Magecart attacks encourages using credit cards over debit cards when shopping online because they often have better consumer fraud protections, and enabling payment charge notifications.
Leave unexpected checkouts: If a checkout page looks unexpected or your browser shows a security warning, stop and pay another way—then use the account alerts the FBI recommends.
Lock and call after a surprise charge: Per the same NJ guidance, lock the card and notify your bank if you see unexpected card-not-present activity.
For more checkout-focused habits, see our guide to credit cards for online shopping.
The FBI advises routine account monitoring after any exposure risk.
Review statements often: Check accounts through online banking or mobile apps rather than waiting only for monthly credit card statements.
Use account alerts: The FBI recommends email or text-message alerts when available so you see unauthorized charges sooner.
Keep watching after a suspicious swipe: The Georgia Attorney General's Consumer Protection Division notes skimmed data may be sold or used quickly—or not for weeks or months.
If you believe your card was skimmed, act the same day: call your issuer, lock the card, and start a paper trail.
Call the number on the back of your card as soon as you notice suspicious transactions or have reason to believe your card was compromised.Visa's Zero Liability Policy says you will not be held responsible for unauthorized charges when you protect the card and report misuse promptly (coverage rules and card types vary—confirm with your issuer). Under federal rules explained by the Consumer Financial Protection Bureau, your liability for unauthorized credit card charges is limited when you report the problem promptly.
Request a replacement card with a new number and ask the issuer to deactivate the compromised card right away.
If you need documentation for your issuer, file a local police report and keep the case number with your dispute records.
If you can identify where the skim likely happened, notify the business. The FBI directs skimming reports to IC3 at ic3.gov.
Gas stations: Contact station management.
ATMs: Alert the bank or ATM operator.
Retail locations: Inform store management.
Online merchants: Contact the merchant security team and file with IC3.
After a skim, monitor linked accounts, automatic payments, and digital wallet connections for unusual activity, and keep using the account alerts the FBI recommends.
If you see signs of broader identity theft, review options in our guide to credit monitoring services.
Keep records of fraudulent transactions, calls with your issuer, police report numbers, and notices you send to businesses.
Stack the habits backed by the sources above: tap when you can, inspect readers, prefer credit when accounts are linked, turn on alerts, and report problems quickly.
When you're ready to compare issuer alerts and liability protections side by side, start by comparing credit cards. For more red flags beyond skimmers, read our guide to credit card red flags.
Follow the FBI inspection tips and Georgia consumer-protection checks: look for loose, crooked, damaged, or mismatched hardware and a thick or hard-to-press keypad. If anything looks off, use another payment method.
Yes. The FBI advises tapping instead of swiping or inserting when you can, because tap-to-pay is more secure and less likely to be compromised than mag-stripe use at the pump or terminal.
Call your card issuer right away using the number on the back of your card, request a replacement, and monitor your accounts. File a police report if you need a case number for your records.
Tap-to-pay is more secure and less likely to be compromised than swiping or inserting, so prefer contactless when the terminal supports it. Keep monitoring accounts afterward.
Per the Georgia Attorney General's Consumer Protection Division, skimmers are illegal readers mounted on payment terminals to grab mag-stripe data, while shimmers are thin devices that slip into the reader and are even harder to detect. In both cases, tapping or paying inside when you can is safer than forcing a swipe.
This refresh relies on secondary authoritative sources rather than a proprietary BestMoney skimming survey. We reviewed current guidance from the FBI skimming hub, U.S. Secret Service public reporting on 2025 nationwide card-reader operations, state consumer protection materials (including Georgia's skimming and shimming overview), New Jersey cybersecurity guidance on Magecart-style attacks, CFPB explanations of unauthorized credit card use, network zero-liability policy pages, and the FBI Internet Crime Complaint Center reporting channel. We cross-checked high-risk locations and consumer tips against those primary materials and removed competitor-attributed quotes that could not be verified as BestMoney sources.
David Kindness is a finance, insurance and tax expert at BestMoney.com. He has written for Investopedia, The Balance, and Techopedia, sharing his deep expertise in taxation, accounting, and finance. A CPA with a Bachelor’s in Accounting, David has worked as a tax specialist and Senior Accountant for high-net-worth clients and businesses in the San Diego area.