Payment terminal fraud awareness

What is shimming?

Shimming is a form of payment-card data theft that uses a very thin electronic insert hidden inside the card slot of an ATM or payment terminal. The Consumer Financial Protection Bureau describes a shim as a paper-thin device that is not visible from outside the machine and that reads data from a card's chip while the card is inserted.

A shim differs from the familiar external skimmer that sits over or around a card reader. Both involve unauthorized equipment, but the location and targeted card interface differ. Merchants do not need to diagnose the device themselves; they need a safe process for recognizing unusual reader behavior, taking the terminal out of service, and escalating the concern to the parties responsible for the equipment.

How shimming differs from skimming

A traditional skimmer commonly captures magnetic-stripe data through an overlay, an altered reader, or equipment installed inside a terminal. The FBI notes that skimming equipment may be installed on or inside ATMs, point-of-sale terminals, and fuel pumps. A shim is designed to fit farther inside the insertion path where it can interact with a chip card as the terminal reads it.

That distinction matters, but it should not be overstated. Capturing information during chip insertion is not the same as creating a fully functional duplicate chip. Chip transactions use security features that make counterfeit chip use more difficult than copying static magnetic-stripe data. Stolen information may still create fraud risk through other channels, so a suspected shim deserves prompt investigation.

Warning signs around a card reader

Insertion feels different

A card that suddenly catches, meets unusual resistance, or does not seat normally may indicate debris, damage, or unauthorized material inside the slot. Stop using the reader rather than forcing the card.

The terminal shows physical changes

Loose parts, scratches, adhesive residue, crooked components, broken seals, or an unfamiliar keypad overlay can signal tampering. Compare the device with its approved appearance and maintenance records.

Chip transactions fall back unexpectedly

Repeated prompts to swipe after a chip-read failure deserve attention. A fallback can also result from ordinary equipment or card problems, so treat the pattern as an investigation signal rather than proof of fraud.

What a merchant should do after a suspected shim

  • Stop using the affected device. Follow the business's incident procedure and prevent additional customers from inserting cards until the reader is assessed.
  • Preserve the scene safely. Do not pry into the slot, power-cycle equipment without direction, or attempt to remove a suspected device. Limit handling and note when and how the concern was discovered.
  • Contact the responsible support channel. Notify the terminal owner, payment provider, approved service company, or internal security team using verified contact information. Follow their evidence-preservation and replacement instructions.
  • Escalate suspected crime. The FBI directs skimming reports to the Internet Crime Complaint Center at IC3.gov. Local law enforcement or the machine owner may also have an established reporting path.
  • Review related activity. Use authorized business reports and provider guidance to look for unusual terminal errors or transactions. Do not copy, request, or transmit full card numbers, PINs, passwords, or security codes through ordinary email or web forms.

Practical controls for staffed payment devices

Create a simple inspection routine for opening, shift changes, and closing. Staff can compare serial numbers and seals, confirm that cables and reader components match the approved setup, and record exceptions without photographing customer payment details. Restrict physical access to spare terminals and keys, and keep an inventory showing which device belongs at each checkout position.

Train employees to recognize distraction tactics and unauthorized service visits. Maintenance should be performed only through verified channels. Keep terminal software and configurations under the control of the responsible provider or qualified administrator, and investigate recurring chip-read failures instead of routinely asking customers to swipe. These practices support detection; they do not guarantee that every concealed device will be visible.

Related fraud and security concepts

Shimming is one part of a broader card-present risk program. Review what card-present fraud means for channel-level context. Learn how device fingerprinting works as a separate, probabilistic signal for digital interactions, and see how end-to-end encryption is defined when evaluating protection across a payment-data path.

No single control replaces physical inspection, secure configuration, staff training, transaction monitoring, and a documented response process. The exact procedures for a terminal depend on its owner, model, provider configuration, and service arrangements.

Plan the next step for a suspicious reader

If a reader is behaving unusually, take it out of service and use verified support contacts for the equipment and payment account. For broader planning, Payments Max can help a business organize questions about terminal workflows, staff access, and payment-security features without promising that a particular device or configuration prevents every attack.

When requesting guidance, describe the business type, payment environment, device ownership, and observed symptoms. Do not send cardholder data, PINs, passwords, bank credentials, complete account numbers, security codes, or secret API keys through a general contact form.

Discuss a payment workflow

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US