Insertion feels different
A card that suddenly catches, meets unusual resistance, or does not seat normally may indicate debris, damage, or unauthorized material inside the slot. Stop using the reader rather than forcing the card.
Payment terminal fraud awareness
Shimming is a form of payment-card data theft that uses a very thin electronic insert hidden inside the card slot of an ATM or payment terminal. The Consumer Financial Protection Bureau describes a shim as a paper-thin device that is not visible from outside the machine and that reads data from a card's chip while the card is inserted.
A shim differs from the familiar external skimmer that sits over or around a card reader. Both involve unauthorized equipment, but the location and targeted card interface differ. Merchants do not need to diagnose the device themselves; they need a safe process for recognizing unusual reader behavior, taking the terminal out of service, and escalating the concern to the parties responsible for the equipment.
A traditional skimmer commonly captures magnetic-stripe data through an overlay, an altered reader, or equipment installed inside a terminal. The FBI notes that skimming equipment may be installed on or inside ATMs, point-of-sale terminals, and fuel pumps. A shim is designed to fit farther inside the insertion path where it can interact with a chip card as the terminal reads it.
That distinction matters, but it should not be overstated. Capturing information during chip insertion is not the same as creating a fully functional duplicate chip. Chip transactions use security features that make counterfeit chip use more difficult than copying static magnetic-stripe data. Stolen information may still create fraud risk through other channels, so a suspected shim deserves prompt investigation.
A card that suddenly catches, meets unusual resistance, or does not seat normally may indicate debris, damage, or unauthorized material inside the slot. Stop using the reader rather than forcing the card.
Loose parts, scratches, adhesive residue, crooked components, broken seals, or an unfamiliar keypad overlay can signal tampering. Compare the device with its approved appearance and maintenance records.
Repeated prompts to swipe after a chip-read failure deserve attention. A fallback can also result from ordinary equipment or card problems, so treat the pattern as an investigation signal rather than proof of fraud.
Create a simple inspection routine for opening, shift changes, and closing. Staff can compare serial numbers and seals, confirm that cables and reader components match the approved setup, and record exceptions without photographing customer payment details. Restrict physical access to spare terminals and keys, and keep an inventory showing which device belongs at each checkout position.
Train employees to recognize distraction tactics and unauthorized service visits. Maintenance should be performed only through verified channels. Keep terminal software and configurations under the control of the responsible provider or qualified administrator, and investigate recurring chip-read failures instead of routinely asking customers to swipe. These practices support detection; they do not guarantee that every concealed device will be visible.
Shimming is one part of a broader card-present risk program. Review what card-present fraud means for channel-level context. Learn how device fingerprinting works as a separate, probabilistic signal for digital interactions, and see how end-to-end encryption is defined when evaluating protection across a payment-data path.
No single control replaces physical inspection, secure configuration, staff training, transaction monitoring, and a documented response process. The exact procedures for a terminal depend on its owner, model, provider configuration, and service arrangements.
If a reader is behaving unusually, take it out of service and use verified support contacts for the equipment and payment account. For broader planning, Payments Max can help a business organize questions about terminal workflows, staff access, and payment-security features without promising that a particular device or configuration prevents every attack.
When requesting guidance, describe the business type, payment environment, device ownership, and observed symptoms. Do not send cardholder data, PINs, passwords, bank credentials, complete account numbers, security codes, or secret API keys through a general contact form.
To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.
CONTACT US