Credit Card Skimmers: What They Are and How Skimming Works

Last updated October 7, 2026 · 1,439 words · Identity Theft

A credit card skimmer is a hidden device or malicious script that copies payment card data at fuel pumps, ATMs, checkout lanes, and online payment pages. It captures the account number and the data used to authorize charges, and the stolen details are later used for unauthorized purchases or counterfeit cards.

This guide is general educational information for U.S. readers. It is not financial advice and does not describe your individual credit file. Figures such as score ranges and timeline estimates are typical examples, not promises.

Key takeaways

A credit card skimmer is a hidden device, or a hidden piece of code, that copies payment card data without the cardholder's knowledge. Skimmers are fitted over or inside card readers at fuel pumps, ATMs, and checkout terminals, or injected into the software that runs an online store's payment page. The copied data is later used to make unauthorized purchases or to produce counterfeit cards, which is why skimming is classified as a form of identity theft.

What a credit card skimmer is

A skimmer is not one product. The term covers any tool that intercepts payment card data on its way from the card to the payment network. The Federal Trade Commission groups these schemes under identity theft, and the Consumer Financial Protection Bureau tracks them within consumer fraud and scam categories.

What a skimmer wants is narrow. It needs the account number and whatever data the payment network uses to authorize a charge: a magnetic stripe track, a chip conversation, or the card verification value used for online orders. Everything else on the card — the cardholder's name, the expiration date, the issuing bank — is secondary, but it is often captured anyway.

Physical and digital skimmers differ in form and are alike in effect. A physical skimmer is hardware placed on or inside a legitimate reader. Digital skimming, sometimes called e-skimming, happens in the code of a checkout page, where a malicious script copies payment form fields as the shopper submits them. In both cases, card data ends up somewhere the merchant cannot see.

How credit card skimmers work

Skimming works because card data is read at a point a criminal can reach. During a normal card-present transaction, the reader collects data from the card and passes it to the processor. A skimmer sits between those two steps and keeps a copy of what passes through.

Overlay skimmers and magnetic stripes

A magnetic stripe carries static data: once a track is recorded, it can be written to a blank card and reused. Overlay skimmers exploit that. The device is a shell that fits over the genuine reader and is usually designed to look identical, containing its own read head plus a small storage chip or a short-range transmitter.

Shims and chip slots

A shim is thinner than an overlay and is pushed into the card slot itself, where it sits between the chip and the reader's contacts. A chip generates a fresh code for each transaction, so a recorded chip exchange is harder to replay than a recorded stripe, although the account number itself remains usable for card-not-present purchases.

PIN capture

At a cash machine or a fuel pump, a skimmer is frequently paired with a camera aimed at the keypad or with a false keypad overlay that records each press. A copied stripe or chip exchange can support a purchase that does not require a PIN; paired with a PIN, the same data reaches cash withdrawal flows as well.

Digital skimming

In e-skimming, an attacker compromises a retailer's site or a third-party script loaded by its checkout page, then injects code that captures what shoppers type. There is no hardware to inspect and no tamper-evident seal to check, and an injected script can run for a long time before it is discovered.

Skimmer typeWhat it collectsWhere it is usually found
Overlay skimmerMagnetic stripe track dataFuel pumps, ATMs, older payment terminals
Shim / insert skimmerChip and card data, sometimes a PINCard slots on ATMs and terminals
Camera or false keypadPIN and card face detailsAbove ATM keypads and pump keypads
Wireless skimmer moduleStripe or chip data, transmitted off-siteInside a terminal housing
E-skimming scriptPayment form fields typed onlineRetail checkout web pages

Where credit card skimming tends to appear

Why skimming counts as identity theft

Card data has a second life after a single unauthorized charge. Account numbers and card details circulate in bulk, and they can be used to open new accounts, file fraudulent tax returns, or take over accounts that already exist. That is the shift from card theft to identity theft: the goal is not the plastic, but the identity attached to it.

Unauthorized accounts opened with skimmed data appear as tradelines in a credit file, which is how activity that never happened at the cardholder's own bank becomes visible. Under the Fair Credit Reporting Act (FCRA, 15 U.S.C. section 1681), consumers have the right to a free credit report from each of the three nationwide credit reporting agencies — Equifax, Experian, and TransUnion — every 12 months, and the three agencies currently provide free reports weekly through AnnualCreditReport.com. A fuller description of those files appears in the guide to credit reports.

Fraud alerts, security freezes, and what federal law provides

Two FCRA provisions address identity theft directly. Section 605A (15 U.S.C. section 1681c-1) covers fraud alerts, which direct a credit reporting agency to take reasonable steps to confirm identity before new credit is opened in a consumer's name. An initial fraud alert lasts 1 year; an extended fraud alert lasts 7 years. Section 605B (15 U.S.C. section 1681c-2) covers blocking information that resulted from identity theft, once an identity theft report has been filed.

A security freeze is free to place, temporarily lift, or remove under federal law. A freeze restricts access to a credit file, so most new lenders cannot pull it; a credit lock is a similar arrangement offered through a credit reporting agency's own product rather than through the statute. The pages on the security freeze and the credit lock describe both, and the broader subject is covered under identity theft.

How fraudulent accounts appear in a credit profile

Credit files run on their own timelines. Most negative information, including late payments, stays on a credit report for 7 years. A Chapter 7 bankruptcy stays on a credit report for 10 years and a Chapter 13 bankruptcy for 7 years. Hard inquiries typically remain on a credit report for 2 years. When an item is disputed, a credit reporting agency generally must investigate within 30 days, and that window can extend to 45 days if the consumer provides additional information during the initial 30-day period.

Scores read the same file from a different angle. Most credit scores, including FICO and VantageScore, use a range of 300 to 850. FICO score factors and their approximate weights are payment history 35%, amounts owed 30%, length of credit history 15%, new credit 10%, and credit mix 10%. VantageScore uses its own factor weighting and does not publish fixed percentages. That is why a fraudulent new account can register as both a new-credit event and, if it goes unpaid, a payment history problem. The mechanics are set out in how credit scores are calculated and in FICO vs VantageScore.

Monitoring, reporting, and the agencies involved

Because card data can surface months after a skimmer is installed, the first sign is usually an account alert rather than the skimmer itself. Bank and card-issuer alerts cover the accounts they hold. A monitoring service watches credit files and reports changes such as a new account or a new inquiry; see credit monitoring and the credit check overview. A wider view of what goes into a consumer's file sits in the credit profile guide.

On the regulatory side, the FCRA was enacted in 1970 and amended by the Fair and Accurate Credit Transactions Act in 2003. The Consumer Financial Protection Bureau was created by the Dodd-Frank Act in 2010 and began operating in 2011, and it publishes consumer-facing material on fraud through the CFPB. The FTC maintains the federal identity theft reporting pathway. If an identity is stolen, it can be reported at IdentityTheft.gov and to the IRS using Form 14039.

At the level of the whole economy, card fraud is one component of the consumer credit picture the Federal Reserve summarizes in its G.19 release, which reports total outstanding consumer credit. A skimmer does not change the amount anyone owes; it changes who may be asked to answer for it.

This page is published for education only and is not financial advice.

Compare three-bureau credit scores and reports from a single place. Educational links, disclosed below.

Three Bureau Credit Scores and Reports

CreditMonitored.com may earn a commission from partner links at no additional cost to you.

Frequently asked questions

What is a credit card skimmer?

A credit card skimmer is a device or script that copies payment card data without the cardholder's knowledge. Physical skimmers are fitted over or inside card readers at fuel pumps, ATMs, and terminals. Digital skimmers operate inside the code of an online checkout page and copy payment form fields as they are submitted.

How do credit card skimmers work?

A skimmer sits between the card and the payment processor and keeps a copy of the data that passes between them. Overlay devices copy magnetic stripe tracks, shims sit in the chip slot, cameras or false keypad overlays capture PINs, and e-skimming scripts copy payment details typed into a web checkout.

Can credit card skimming affect a credit report?

It can. Unauthorized accounts opened with skimmed data appear as tradelines in a credit file, and unpaid balances on those accounts can be reported. Under the FCRA, consumers have the right to a free credit report from each of the three nationwide credit reporting agencies every 12 months, and the agencies currently provide free reports weekly through AnnualCreditReport.com.

How long does a fraud alert last?

An initial fraud alert lasts 1 year, and an extended fraud alert lasts 7 years. Fraud alerts are covered by FCRA section 605A (15 U.S.C. section 1681c-1).

Is a security freeze free to place?

Yes. A security freeze is free to place, temporarily lift, or remove under federal law. A freeze restricts access to a credit file, which is a different arrangement from a credit lock offered through a credit reporting agency's own product.

Where can identity theft be reported?

Identity theft can be reported at IdentityTheft.gov and to the IRS using Form 14039. The FTC's identity theft page and the CFPB's fraud and scams resources both describe how reporting works and what information is collected.

Related guides

Related terms

Sources