Dumpster diving, phishing, skimming, and now we have shimming

The latest method of getting card information is a more sophisticated version of an older scheme. It’s a new attack targeting debit cards at ATMs. That doesn’t make a big bang for merchants because the bad guys go for cash but you can bet it’s going to hurt a lot of banks. Because the attacks are targeting debit cards with PINs, cardholders will be feeling the pain as well.

Earlier ATM skimming techniques involved installing a device over the legitimate card reader and also placing a camera near the reader to visually record the PIN as it was entered.

An article on ATM shimming in Networkworld makes it clear that this attack is not trivial but it is almost undetectable. A .1mm shim is inserted inside the existing card reader. According to the article, these devices are already being mass produced in Europe.

Once again, we’ve moved one step forward to the bad guys two.

Similar Posts:

About Tom Mahoney

Tom Mahoney is the Founder and Director of Merchant911, a site dedicated to helping e-commerce merchants.
This entry was posted in fraud trends, Vulnerability and tagged , , . Bookmark the permalink.
Post comment as twitter logo facebook logo
Sort: Newest | Oldest