Skimming

PCIComplianceHubLast updated

Capturing card data by tampering with the physical point of acceptance, using a device fitted over or inside a terminal, ATM or fuel pump to read the magnetic stripe, and often a pinhole camera or overlay keypad to capture the PIN. PCI DSS requires point-of-interaction devices to be inventoried, inspected periodically for tampering and substitution, and staff to be trained to recognise it.

Applies to. Card-present environments: any entity operating point-of-interaction devices that read a card by physical interaction, including terminals, ATMs and unattended fuel dispensers.
Example. An overlay fitted over a terminal's card slot reads the magnetic stripe while a pinhole camera or a false keypad captures the PIN. The real transaction still goes through, so nothing looks wrong at the till.
Limits. The PCI DSS controls are an up-to-date device list, periodic inspection of device surfaces for tampering or substitution, and training so staff can verify a technician's identity and notice a swapped device (9.5.1 and its sub-requirements). None makes a device tamper-proof; a substituted device that passes a glance is the case the training exists for. Online theft that copies the technique is e-skimming, governed by different requirements.
In PCI DSS v4.0.1. 9.5.1, 9.5.1.1, 9.5.1.2, 9.5.1.3