Also called: ATM skimming · gas pump skimming · card cloning · point-of-sale skimming · shimming
Card skimming hides an electronic device inside an ATM, gas pump or checkout terminal's card slot to copy a card's magnetic-stripe data, usually paired with a pinhole camera or fake keypad to capture the PIN. The stolen data is encoded onto blank cards for cash withdrawals or purchases. The Secret Service removed 411 skimming devices across the US in 2025 alone, preventing an estimated $428 million in losses.
What it is
No phone call. No text message. No email, no link, no stranger to talk you into anything. You put your
card into a machine you have used a hundred times before, and a device hidden inside the slot copies
the data off your card’s magnetic stripe as it passes through. If a second, smaller device — a
pinhole camera above the keypad, or a fake keypad laid over the real one — is also in place, it
captures your PIN at the same moment.
Days later, whoever installed it comes back, removes both devices, and encodes the stolen data onto the
magnetic stripe of a blank card. From there it is cash out of an ATM or purchases on a cloned card,
usually within hours, before a bank’s fraud system or the cardholder notices anything wrong.
Skimming is the one scheme on this site where the victim does nothing wrong. There is no red flag in
their own behaviour to teach, because they behaved exactly as they always do.
How it actually works
The device goes in
A card reader, memory chip and battery, built thin enough to sit inside or over a real card slot —
on an ATM, a gas pump, or a checkout terminal — without an ordinary user noticing.
Where it could have stopped
Before you insert a card anywhere, give the card slot and the PIN pad a firm, gentle tug. A skimmer sitting loosely over the real hardware will move, wiggle or come away in a way the original equipment does not. It takes five seconds and it is the one check that works whether the device is an obvious external shell or a nearly invisible internal one.
A second device for the PIN
A pinhole camera aimed at the keypad, or a fake keypad overlay placed directly on top of the real
one, captures the PIN as it is typed — the piece that turns a copied card number into cash.
Ordinary use, invisible theft
The card goes in, the transaction completes normally, and the machine gives no sign anything is
wrong. This is the stage every other scheme on this site tries to interrupt with a red flag — here
there isn’t one.
Retrieval
Days later, the person who installed the device returns to collect it and the data it has stored —
the one moment in the entire scheme where a criminal has to be physically present at the scene.
Encoding
The captured magnetic-stripe data is written onto the stripe of a blank card or an ordinary gift
card using a simple encoder, producing a working clone of the original.
Fast cashout
ATM withdrawals or purchases on the cloned card, usually within hours of encoding — speed matters
here for the same reason it does in a money mule scheme: get the value out before a bank can freeze
anything.
The operation moves on
Devices get relocated to new machines, new cities, sometimes new states entirely. A single group has
operated skimmers across seven US states from one shared residence.
Caught at the retrieval, not the device
Devices are anonymous; the person coming back for one is not. Investigators in more than one
documented case made their arrest by waiting for whoever returned to collect the equipment.
Why it works
It requires no persuasion at all. Every other scheme on this site depends on getting the victim to
do, say or click something. Skimming needs nothing from the victim beyond using a card the ordinary way,
which removes the one thing most anti-fraud advice trains people to watch for.
The devices are built to be invisible. Early skimmers were bulky add-ons easy to spot; the Secret
Service now describes internal skimmers “impossible to detect from the ATM’s exterior.” The technology
improved specifically to defeat the advice to look for tampering.
A card works identically whether or not it has been cloned. There is no moment of realisation — no
declined transaction, no odd message — until a statement arrives or a bank’s fraud system flags
unusual activity, by which point the cloned card may already have been used.
The retrieval risk is small and brief. A criminal is only physically present at the scene for the
minute it takes to install or remove a device, versus the days or weeks a romance or investment scheme
needs to run.
And EBT and debit cards carry less built-in protection than credit cards. A stolen debit PIN gives
direct access to a bank balance, and EBT cards in particular often lack the fraud monitoring a bank
applies to its own products — which is why the Secret Service names EBT recipients as a specifically
vulnerable population.
Where it comes from
Every documented case on this page involves Romanian nationals, alone or working with British or Irish
co-conspirators — a pattern that recurs across the wider set of DOJ and Secret Service skimming
prosecutions, not just the three here.
Scale ranges from a single ATM to a seven-state operation. Tarta’s group worked a handful of Chicago
and New Jersey ATMs; the Codreanu family’s ring ran devices across Rhode Island, Massachusetts,
Virginia, Maryland, New Jersey, Pennsylvania and New York from one shared address in California.
Targets range from banks to grocery stores. Ionescu and Stanciu’s 23 devices sat on point-of-sale
terminals at grocery checkouts, not ATMs — the same technique, aimed at a target with less dedicated
fraud-monitoring infrastructure than a bank.
And the scale of the countermeasure is now industrial too. The Secret Service ran 22 skimming
operations across major US cities in 2025 alone, visiting more than 9,000 businesses and inspecting
roughly 60,000 ATMs, gas pumps and point-of-sale terminals — removing 411 devices and preventing an
estimated $428.1 million in losses. The agency puts the broader annual cost of skimming to US
financial institutions and consumers at over $1 billion.
Real cases
2026 US Sentenced $51,000
Denis Adelin Ionescu, 24, and Ioan Victor Stanciu, 33 — both Romanian nationals unlawfully present in the US — were sentenced on 26 March 2026 to 46 and 24 months in federal prison for installing 23 card-skimming devices at 12 grocery store point-of-sale terminals across Alabama and Mississippi. A third defendant, Marian Catalin Matei, pleaded guilty and awaited sentencing.
Read the case file ·
1 source
2025 US Convicted $300,000
Four members of an extended family — Nicolas Longin Codreanu, Armando Ion Codreanu, Isabela Ignat Codreanu and Robby Vicson Codreanu, all in their early twenties and living together in Placentia, California — pleaded guilty in mid-2025 to running a card-skimming conspiracy across seven states that compromised more than 15,000 credit, debit and EBT cards. A fifth defendant, Mila Ciuciu, also pleaded guilty; a sixth, Ionut Zamfir, remained a fugitive.
Read the case file ·
2 sources
2025 US Sentenced $177,280
Florin Nicolae Tarta, a 40-year-old Romanian national, was sentenced on 10 September 2025 to six years and nine months in federal prison for installing skimming devices and a pinhole camera on Bank of America ATMs in Chicago, then expanding to New Jersey. He and two co-defendants captured card data and PINs, encoded the data onto counterfeit gift cards, and withdrew cash before New Jersey police caught Tarta retrieving a camera he had planted.
Read the case file ·
1 source
Red flags
- A raised, loose or misaligned PIN pad — give it a firm, gentle tug before using it.
- A card slot overlay that does not sit flush with the rest of the machine.
- Inoperable indicator lights or components that look broken or mismatched.
- Unusual stickers or attachments anywhere near the card slot or keypad.
- A keypad that feels different from the one you remember using at that machine before.
- An ATM outside a bank or away from a staffed location, which is inspected and maintained less often.
- Anything that looks like a small lens or pinhole above or beside the keypad.
If it’s happening to you
Before you use any card reader: give the card slot and PIN pad a firm, gentle tug, and shield the
keypad with your hand as you enter your PIN regardless of whether you see anything suspicious — it
costs nothing and defeats a hidden camera even if you never spot it. Where you have the choice, prefer
ATMs inside or attached to a bank branch, use a credit card rather than a debit card, and consider a
contactless or chip tap instead of a swipe or insert.
If you think a machine has been tampered with:
- Do not use it. Use a different machine and report the one you suspect.
- If it is a business’s terminal, tell a staff member immediately so they can take it out of service
and contact their security department; call local law enforcement if the business does not.
- Report it to the Secret Service or your local police, and at ReportFraud.ftc.gov. See
where to report for other countries.
If you think your card has already been skimmed:
- Call your card issuer’s fraud department immediately — the number on the back of your card, not
one from a text or search result — and request the card be deactivated and reissued with a new PIN.
- Review recent transactions closely for anything you do not recognise, and file a fraud affidavit
with your bank if you find any.
- Watch your account for several weeks afterward. Skimmed data is sometimes sold or used later
rather than immediately.
Where the money goes
Compared to most schemes on this site, skimming’s money trail is short and physical rather than
layered through accounts and borders.
Value moves from a compromised card straight to cash — an ATM withdrawal or a purchase on a cloned
card — usually within hours of the data being encoded, converting a database of numbers into money a
person is physically holding. That immediacy is the point: unlike a wire transfer, which a bank can
sometimes claw back before it settles, cash withdrawn from an ATM is essentially gone the moment it is
in someone’s hand.
From there, the physical devices themselves are the more durable asset. A skimmer costing a few hundred
to a few thousand dollars can generate tens or hundreds of thousands of dollars in fraudulent
transactions before it is found — which is why relocating equipment to new machines and new cities, as
documented across every case on this page, is worth more to an operation than any single installation.
One earlier RICO prosecution traced the further step explicitly: proceeds from a six-state, 18-month
skimming operation were transferred internationally to Romania and China, partly to buy more skimming
equipment from abroad — the device supply chain and the cash-out network funding each other.
By the numbers
No published dataset breaks this scheme out as its own category yet, so there is no chart to show.
The data page explains which agency categories exist and why some schemes are
invisible in official statistics.
Every factual claim above traces to one of these. Statistics are reported losses; see
methodology for what that does and does not measure.