Skimming Scams

Overview

Skimming is the theft of payment-card information through a compromised card reader. A skimming device may be attached over a legitimate reader at an ATM, fuel pump, checkout terminal, ticket machine, or other payment location. The device captures information from the card's magnetic stripe when the card is inserted or swiped.

Criminals may also use a hidden camera, false keypad, or other device to capture a PIN. A related device may be inserted inside a card reader, making it difficult to see from the outside.

Online card theft is sometimes called e-skimming. In these cases, malicious code on a compromised checkout page copies payment information as a customer enters it. A fake checkout page may also imitate a real merchant to collect card and account information.

A skimmer may not be visible, and using a compromised reader does not necessarily cause an immediate problem. Unauthorized charges may appear later.

Warning Signs

Possible signs of a compromised physical card reader include:

  • A card slot or keypad that is loose, bulky, misaligned, damaged, or different from nearby readers.
  • A reader that moves when gently touched.
  • Broken seals, opened panels, adhesive residue, or unexpected attachments.
  • A keypad overlay that changes the height, feel, or alignment of the keys.
  • A small object or opening positioned to view the keypad.
  • A terminal that repeatedly fails and asks you to swipe the magnetic stripe instead of using the chip or contactless payment.

Possible signs of online card theft include:

  • A checkout page reached through an unexpected email, advertisement, text message, or QR code.
  • A website address that is misspelled or does not match the merchant.
  • Unexpected redirects to a different domain during payment.
  • A page that asks for information unrelated to the purchase.
  • Browser security warnings or a checkout process that behaves differently from the merchant's normal site.

Unauthorized transactions, small unfamiliar “test” charges, or alerts for purchases you did not make may indicate that card information has been stolen.

How to Protect Yourself

  • Inspect a card reader before using it. Compare it with nearby readers and avoid it if the slot, keypad, seal, or surrounding panel appears altered.
  • Use chip or contactless payment when available. Avoid swiping the magnetic stripe unless no safer option is available.
  • Cover the keypad when entering a PIN. This can reduce the risk from hidden cameras or people watching nearby.
  • Use well-monitored payment locations. ATMs and terminals inside staffed or secured areas may be less accessible to tampering, although no location is risk-free.
  • Go directly to a merchant's official site or application. Do not enter card information on a checkout page reached through an unexpected message.
  • Keep browsers and devices updated. Security updates help protect against malicious websites and compromised software.
  • Enable transaction alerts. Alerts can help you identify unauthorized use quickly.
  • Review bank and card statements regularly. Report unfamiliar transactions promptly.
  • Do not continue using a reader that appears suspicious. Notify the business or organization responsible for the terminal.

What You Should Do at UM

If you suspect that a card reader, ATM, kiosk, or online payment page associated with UM has been compromised:

  1. Stop using the reader or page. Do not insert another card or enter additional information.
  2. Do not remove or handle a suspected device. Record the location and, when safe, the time and identifying details of the terminal.
  3. Contact the UM IT Helpdesk or UM Information Security Office so the concern can be documented and routed to the appropriate UM unit.
  4. Contact your bank or card issuer if you used the reader or entered payment information. Ask whether the card should be locked, replaced, or monitored.
  5. Review recent account activity and report transactions you do not recognize.

If the page also asked for your UM username, password, or MFA approval and you provided it, change your UM password through the normal account-management process and contact the UM IT Helpdesk or UM Information Security Office.

Using a suspected reader does not prove that your card was copied. Monitoring the account and following the card issuer's guidance are the appropriate next steps.

Additional Questions

For a suspected skimmer or payment page connected to a UM location, device, service, or account, contact the UM IT Helpdesk and the UM Information Security Office. Involve the appropriate UM financial or purchasing office when a university payment card or UM financial process is involved.

For a personal payment card, contact the issuing bank or credit union immediately if the card may have been exposed or you notice an unauthorized transaction. Use the official number on the card, account statement, or financial institution's website.

Additional Resources

Was this helpful?
0 reviews