Skip to main content
My Consumer Finance

Skimming and card cloning: how to reduce the risk

How skimming and card cloning work at ATMs and terminals, how to reduce the risk, and what to do if your Visa, Mastercard, Amex, or Discover card is copied.

Skimming is hardware or software that steals card data when you tap, insert, or swipe. Card cloning is using that stolen data to create a counterfeit card or run card-not-present charges. Gas pumps, standalone ATMs, restaurant handhelds, and compromised e-commerce checkouts are common venues. This is different from a phishing link that tricks you into typing a password—see Phishing and account takeover—but the cleanup often overlaps.

Broader scam patterns: Credit and debt scams.

Where skimmers show up

LocationTypical tellLower-risk habit
ATM vestibule / outdoor ATMLoose card slot, odd keypad overlay, cheap camera aimed at PINPrefer indoor bank ATMs (Chase, Bank of America, credit-union branches)
Gas pumpBroken security seal, bulky reader, delayed “approve” screenPay inside; use tap/chip; favor pumps near the cashier
Store terminalDetached overlay, cable dongle, unusual Bluetooth readerTap or insert chip; avoid swipe when chip is offered
Online checkoutLookalike domain, odd payment redirectType the merchant URL yourself; prefer card tokens / official apps

Contactless tap and chip EMV make classic magnetic-stripe clones harder, but stolen numbers still fuel online fraud. PIN capture (overlays or hidden cameras) turns a skim into full debit access.

Habits that cut risk

  1. Prefer tap or chip over swipe whenever the terminal allows it.
  2. Cover the PIN pad with your hand; glance for cameras above the keypad.
  3. Wiggle the card slot gently—overlays sometimes shift.
  4. Use bank-branch ATMs over freestanding lobby machines when cashing out.
  5. Turn on transaction alerts in Chase, Capital One, Amex, Citi, Discover, and debit apps.
  6. Keep a low daily ATM limit on debit; prefer credit for travel terminals when you can pay in full.
  7. Freeze cards instantly in-app if a terminal felt wrong.

Worked example

Alex uses an outdoor ATM on a Friday night. Monday, a $640 charge appears at an electronics shop two states away on the same debit card. Alex did not travel.

  1. Alex freezes the debit card in the credit-union app and calls the number on the back of the card (not a number from a text).
  2. Alex documents the ATM location, time, and the unauthorized charge list.
  3. Alex files an unauthorized-transaction dispute—path: Unauthorized card charges and Disputing a credit card charge (debit timelines differ; ask for Regulation E rights).
  4. Alex changes online banking passwords and reviews whether phishing could have paired with the skim.
  5. If new accounts appear, Alex places freezes at Equifax, Experian, and TransUnion: Credit freezes and fraud alerts.

Waiting a week to “see if it reverses” can burn liability windows on debit cards. Credit cards often have stronger statutory caps, but speed still helps.

What cloning is not

A merchant that double-charges you by mistake is a billing error, not cloning. A family member with a card you shared is a household problem, not a skimmer. A fake “card locked—verify” text is phishing. Sort the category before you pick the dispute path.

Checklist

  1. Inspect ATM and pump readers before you insert.
  2. Prefer tap/chip; treat swipe as last resort.
  3. Enable real-time alerts on every card you carry.
  4. Separate a low-limit debit for cash from cards you use online.
  5. Dispute unauthorized charges immediately; keep case numbers.
  6. Replace compromised cards and update autopay lists the same week.

Educational only. Not legal or fraud-recovery advice. Liability rules differ for credit vs debit and by network; confirm with your issuer.