Payment reader fraud awareness

What is skimming?

Skimming is the unauthorized capture of payment-card information through equipment placed on, inside, or alongside a legitimate card reader. The FBI describes skimmers installed at ATMs, point-of-sale terminals, and fuel pumps. Some devices collect card data, while a concealed camera or false keypad may also capture a cardholder's PIN.

For merchants, skimming is both a customer-safety concern and a physical-security issue. A store team does not need to identify the exact technology or investigate a crime on its own. The practical goal is to recognize unusual conditions, stop use of the affected reader, preserve relevant details, and contact the parties responsible for the device and payment account.

How payment-card skimming works

A skimmer can be an overlay fitted over a reader, a component installed inside a terminal or fuel pump, or other unauthorized equipment connected to the payment path. The U.S. Secret Service warns that some point-of-sale overlays are shaped to resemble the terminal they cover. Captured information may later be used for unauthorized activity or transferred to another card.

Skimming is often associated with magnetic-stripe data, but merchants should avoid assuming that a chip slot makes every reader immune to tampering. The safest response is based on observed device condition and established incident procedures, not a guess about what data a particular object could capture. Skimming also differs from shimming inside a card slot, even though both involve concealed equipment and require careful escalation.

Warning signs merchants can monitor

Parts do not match

A reader, keypad, seal, cable, or housing that looks different from an approved reference deserves attention. Watch for changes in color, shape, alignment, or labeling without treating appearance alone as proof of tampering.

Components feel loose

Crooked parts, unexpected movement, adhesive residue, scratches, damaged seals, or an overlay that lifts at the edge can indicate damage or unauthorized modification. Do not pull apart a suspected device.

Reader behavior changes

Cards that catch, repeated read failures, or a keypad that suddenly feels different can result from ordinary faults or tampering. Record the symptom and follow the business's device-escalation procedure.

A safe response to a suspicious reader

  • Stop transactions on the device. Prevent additional use while keeping another approved payment option available when the business can do so safely.
  • Limit handling. Do not pry off an overlay, open the terminal, disconnect unfamiliar components, or attempt to test suspected equipment with a payment card.
  • Document what was observed. Note the terminal location, asset identifier, time, visible condition, and who discovered the issue. Avoid photographing or transmitting customer payment details.
  • Use verified support contacts. Notify the terminal owner, payment provider, approved service company, or internal security lead through a known phone number or portal, then follow their preservation and replacement instructions.
  • Escalate suspected crime. Follow the organization's incident plan and applicable law-enforcement reporting path. The FBI directs skimming complaints to its Internet Crime Complaint Center.

If a customer reports unauthorized activity, direct the customer to the financial institution or card issuer using contact information from a trusted source. Store staff should not ask a customer to provide a full card number, PIN, password, security code, or bank credential through a general form or ordinary email.

Build a repeatable device-check routine

The PCI Security Standards Council advises merchants to check payment devices regularly for rogue software or skimming equipment. A useful local routine can compare each device with an approved reference at opening, shift changes, and closing. Record the terminal's expected location, serial or asset number, seals, connected cables, and known physical features so employees have a consistent baseline.

Control access to spare devices, keys, cabinets, and service areas. Verify unexpected maintenance visits through an established contact before granting access. Train staff to recognize distraction attempts around checkout equipment and to report anomalies without confronting a suspected installer. These measures can improve the chance of noticing a problem, but they cannot guarantee that every concealed device will be detected.

Skimming within a broader fraud program

Physical reader checks are only one layer of a merchant's payment-risk process. Review what card-present fraud means for context on in-person transactions, and see how end-to-end encryption is defined for a separate data-protection concept. Neither topic replaces device inventory, access controls, staff training, transaction monitoring, or an incident-response plan.

Merchants should use instructions specific to the terminal owner, model, provider configuration, and operating environment. Do not claim that a particular seal, chip interface, network control, or payment method eliminates skimming risk. When procedures are unclear, pause use of the reader and ask the responsible support channel for direction.

Plan the next step for payment-device oversight

Payments Max can help a business organize questions about device ownership, checkout workflows, staff access, and support responsibilities. That conversation can clarify what to verify with a prospective provider without promising that any device or configuration will prevent every form of fraud.

To prepare, list the number and location of payment devices, who owns and services them, how employees confirm approved maintenance, and where unusual behavior is reported. Do not send cardholder data, PINs, passwords, complete account numbers, security codes, bank credentials, or secret API keys through a general contact form.

Discuss a payment workflow

To learn more about how TSYS can help improve the way your organization accepts payments, markets to new customers, or manages its HR responsibilities, get in touch by calling 585-981-8463 to get started.

CONTACT US