Skimming
PCIComplianceHubLast updated
Capturing card data by tampering with the physical point of acceptance, using a device fitted over or inside a terminal, ATM or fuel pump to read the magnetic stripe, and often a pinhole camera or overlay keypad to capture the PIN. PCI DSS requires point-of-interaction devices to be inventoried, inspected periodically for tampering and substitution, and staff to be trained to recognise it.
Applies to. Card-present environments: any entity operating point-of-interaction devices that read a card by physical interaction, including terminals, ATMs and unattended fuel dispensers.
Example. An overlay fitted over a terminal's card slot reads the magnetic stripe while a pinhole camera or a false keypad captures the PIN. The real transaction still goes through, so nothing looks wrong at the till.
Limits. The PCI DSS controls are an up-to-date device list, periodic inspection of device surfaces for tampering or substitution, and training so staff can verify a technician's identity and notice a swapped device (9.5.1 and its sub-requirements). None makes a device tamper-proof; a substituted device that passes a glance is the case the training exists for. Online theft that copies the technique is e-skimming, governed by different requirements.
Related. E-Skimming, Point of Interaction (POI), Point of Sale (POS), Magnetic Stripe Data, Card-Present Transaction, User Training and Awareness
Sources. PCI DSS v4.0.1 (June 2024)