Credit Card Skimmers: What They Are and How Skimming Works
A credit card skimmer is a hidden device or malicious script that copies payment card data at fuel pumps, ATMs, checkout lanes, and online payment pages. It captures the account number and the data used to authorize charges, and the stolen details are later used for unauthorized purchases or counterfeit cards.
This guide is general educational information for U.S. readers. It is not financial advice and does not describe your individual credit file. Figures such as score ranges and timeline estimates are typical examples, not promises.
Key takeaways
- A credit card skimmer is any device or script that captures payment card data between the card and the payment network.
- Physical skimmers sit on or inside card readers, while digital skimming runs inside the code of an online checkout page.
- Skimming is treated as identity theft because stolen card data is used to open accounts, not only to make a single purchase.
- Under the FCRA, an initial fraud alert lasts 1 year and an extended fraud alert lasts 7 years.
- A security freeze is free to place, temporarily lift, or remove under federal law.
- Most negative information, including late payments, stays on a credit report for 7 years.
A credit card skimmer is a hidden device, or a hidden piece of code, that copies payment card data without the cardholder's knowledge. Skimmers are fitted over or inside card readers at fuel pumps, ATMs, and checkout terminals, or injected into the software that runs an online store's payment page. The copied data is later used to make unauthorized purchases or to produce counterfeit cards, which is why skimming is classified as a form of identity theft.
What a credit card skimmer is
A skimmer is not one product. The term covers any tool that intercepts payment card data on its way from the card to the payment network. The Federal Trade Commission groups these schemes under identity theft, and the Consumer Financial Protection Bureau tracks them within consumer fraud and scam categories.
What a skimmer wants is narrow. It needs the account number and whatever data the payment network uses to authorize a charge: a magnetic stripe track, a chip conversation, or the card verification value used for online orders. Everything else on the card — the cardholder's name, the expiration date, the issuing bank — is secondary, but it is often captured anyway.
Physical and digital skimmers differ in form and are alike in effect. A physical skimmer is hardware placed on or inside a legitimate reader. Digital skimming, sometimes called e-skimming, happens in the code of a checkout page, where a malicious script copies payment form fields as the shopper submits them. In both cases, card data ends up somewhere the merchant cannot see.
How credit card skimmers work
Skimming works because card data is read at a point a criminal can reach. During a normal card-present transaction, the reader collects data from the card and passes it to the processor. A skimmer sits between those two steps and keeps a copy of what passes through.
Overlay skimmers and magnetic stripes
A magnetic stripe carries static data: once a track is recorded, it can be written to a blank card and reused. Overlay skimmers exploit that. The device is a shell that fits over the genuine reader and is usually designed to look identical, containing its own read head plus a small storage chip or a short-range transmitter.
Shims and chip slots
A shim is thinner than an overlay and is pushed into the card slot itself, where it sits between the chip and the reader's contacts. A chip generates a fresh code for each transaction, so a recorded chip exchange is harder to replay than a recorded stripe, although the account number itself remains usable for card-not-present purchases.
PIN capture
At a cash machine or a fuel pump, a skimmer is frequently paired with a camera aimed at the keypad or with a false keypad overlay that records each press. A copied stripe or chip exchange can support a purchase that does not require a PIN; paired with a PIN, the same data reaches cash withdrawal flows as well.
Digital skimming
In e-skimming, an attacker compromises a retailer's site or a third-party script loaded by its checkout page, then injects code that captures what shoppers type. There is no hardware to inspect and no tamper-evident seal to check, and an injected script can run for a long time before it is discovered.
| Skimmer type | What it collects | Where it is usually found |
|---|---|---|
| Overlay skimmer | Magnetic stripe track data | Fuel pumps, ATMs, older payment terminals |
| Shim / insert skimmer | Chip and card data, sometimes a PIN | Card slots on ATMs and terminals |
| Camera or false keypad | PIN and card face details | Above ATM keypads and pump keypads |
| Wireless skimmer module | Stripe or chip data, transmitted off-site | Inside a terminal housing |
| E-skimming script | Payment form fields typed online | Retail checkout web pages |
Where credit card skimming tends to appear
- Fuel pumps. Outdoor readers sit unattended for long stretches and often fall back to the older stripe reader.
- ATMs. Standalone machines in low-traffic locations offer both card and PIN capture in a single visit.
- Self-checkout lanes. Many different hands reach the same reader every day.
- Restaurants and bars. A card that leaves the table is a card that can be run through a handheld skimmer out of sight.
- Online checkouts. Compromised payment scripts collect data without the shopper ever touching hardware.
Why skimming counts as identity theft
Card data has a second life after a single unauthorized charge. Account numbers and card details circulate in bulk, and they can be used to open new accounts, file fraudulent tax returns, or take over accounts that already exist. That is the shift from card theft to identity theft: the goal is not the plastic, but the identity attached to it.
Unauthorized accounts opened with skimmed data appear as tradelines in a credit file, which is how activity that never happened at the cardholder's own bank becomes visible. Under the Fair Credit Reporting Act (FCRA, 15 U.S.C. section 1681), consumers have the right to a free credit report from each of the three nationwide credit reporting agencies — Equifax, Experian, and TransUnion — every 12 months, and the three agencies currently provide free reports weekly through AnnualCreditReport.com. A fuller description of those files appears in the guide to credit reports.
Fraud alerts, security freezes, and what federal law provides
Two FCRA provisions address identity theft directly. Section 605A (15 U.S.C. section 1681c-1) covers fraud alerts, which direct a credit reporting agency to take reasonable steps to confirm identity before new credit is opened in a consumer's name. An initial fraud alert lasts 1 year; an extended fraud alert lasts 7 years. Section 605B (15 U.S.C. section 1681c-2) covers blocking information that resulted from identity theft, once an identity theft report has been filed.
A security freeze is free to place, temporarily lift, or remove under federal law. A freeze restricts access to a credit file, so most new lenders cannot pull it; a credit lock is a similar arrangement offered through a credit reporting agency's own product rather than through the statute. The pages on the security freeze and the credit lock describe both, and the broader subject is covered under identity theft.
How fraudulent accounts appear in a credit profile
Credit files run on their own timelines. Most negative information, including late payments, stays on a credit report for 7 years. A Chapter 7 bankruptcy stays on a credit report for 10 years and a Chapter 13 bankruptcy for 7 years. Hard inquiries typically remain on a credit report for 2 years. When an item is disputed, a credit reporting agency generally must investigate within 30 days, and that window can extend to 45 days if the consumer provides additional information during the initial 30-day period.
Scores read the same file from a different angle. Most credit scores, including FICO and VantageScore, use a range of 300 to 850. FICO score factors and their approximate weights are payment history 35%, amounts owed 30%, length of credit history 15%, new credit 10%, and credit mix 10%. VantageScore uses its own factor weighting and does not publish fixed percentages. That is why a fraudulent new account can register as both a new-credit event and, if it goes unpaid, a payment history problem. The mechanics are set out in how credit scores are calculated and in FICO vs VantageScore.
Monitoring, reporting, and the agencies involved
Because card data can surface months after a skimmer is installed, the first sign is usually an account alert rather than the skimmer itself. Bank and card-issuer alerts cover the accounts they hold. A monitoring service watches credit files and reports changes such as a new account or a new inquiry; see credit monitoring and the credit check overview. A wider view of what goes into a consumer's file sits in the credit profile guide.
On the regulatory side, the FCRA was enacted in 1970 and amended by the Fair and Accurate Credit Transactions Act in 2003. The Consumer Financial Protection Bureau was created by the Dodd-Frank Act in 2010 and began operating in 2011, and it publishes consumer-facing material on fraud through the CFPB. The FTC maintains the federal identity theft reporting pathway. If an identity is stolen, it can be reported at IdentityTheft.gov and to the IRS using Form 14039.
At the level of the whole economy, card fraud is one component of the consumer credit picture the Federal Reserve summarizes in its G.19 release, which reports total outstanding consumer credit. A skimmer does not change the amount anyone owes; it changes who may be asked to answer for it.
This page is published for education only and is not financial advice.
Compare three-bureau credit scores and reports from a single place. Educational links, disclosed below.
Three Bureau Credit Scores and ReportsCreditMonitored.com may earn a commission from partner links at no additional cost to you.
Frequently asked questions
What is a credit card skimmer?
A credit card skimmer is a device or script that copies payment card data without the cardholder's knowledge. Physical skimmers are fitted over or inside card readers at fuel pumps, ATMs, and terminals. Digital skimmers operate inside the code of an online checkout page and copy payment form fields as they are submitted.
How do credit card skimmers work?
A skimmer sits between the card and the payment processor and keeps a copy of the data that passes between them. Overlay devices copy magnetic stripe tracks, shims sit in the chip slot, cameras or false keypad overlays capture PINs, and e-skimming scripts copy payment details typed into a web checkout.
Can credit card skimming affect a credit report?
It can. Unauthorized accounts opened with skimmed data appear as tradelines in a credit file, and unpaid balances on those accounts can be reported. Under the FCRA, consumers have the right to a free credit report from each of the three nationwide credit reporting agencies every 12 months, and the agencies currently provide free reports weekly through AnnualCreditReport.com.
How long does a fraud alert last?
An initial fraud alert lasts 1 year, and an extended fraud alert lasts 7 years. Fraud alerts are covered by FCRA section 605A (15 U.S.C. section 1681c-1).
Is a security freeze free to place?
Yes. A security freeze is free to place, temporarily lift, or remove under federal law. A freeze restricts access to a credit file, which is a different arrangement from a credit lock offered through a credit reporting agency's own product.
Where can identity theft be reported?
Identity theft can be reported at IdentityTheft.gov and to the IRS using Form 14039. The FTC's identity theft page and the CFPB's fraud and scams resources both describe how reporting works and what information is collected.
Related guides
- How Credit Scores Are Calculated
- Fico Vs Vantagescore
- Credit Utilization Explained
- Payment History And Credit Scores