---
title: "Be AWARE: How “Skimmers” Steal Payment Card Data"
description: "12 Steps to Stop Holiday Hackers: Be Aware: Skimming"
image: https://blog.pcisecuritystandards.org/hubfs/step01-1.png
---

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/be-aware-skimming#)

# [Be AWARE: How “Skimmers” Steal Payment Card Data](https://blog.pcisecuritystandards.org/be-aware-skimming)

 Posted by [Laura K. Gray](https://blog.pcisecuritystandards.org/author/laura-k-gray) on 9 Nov, 2015 in [Small Business](https://blog.pcisecuritystandards.org/topic/small-business) and [Holidays](https://blog.pcisecuritystandards.org/topic/holidays) and [Skimming](https://blog.pcisecuritystandards.org/topic/skimming)

![Be Aware: Skimming. Be Aware. Check Controls. Test Security.](https://blog.pcisecuritystandards.org/hs-fs/hubfs/step01-1.png?width=800&name=step01-1.png "Be Aware: Skimming. Be Aware. Check Controls. Test Security.")

<https://www.linkedin.com/shareArticle?mini=true&url=https://blog.pcisecuritystandards.org/be-aware-skimming>

<https://www.facebook.com/share.php?u=https://blog.pcisecuritystandards.org/be-aware-skimming>

<https://twitter.com/intent/tweet?original_referer=https://blog.pcisecuritystandards.org/be-aware-skimming&url=https://blog.pcisecuritystandards.org/be-aware-skimming&source=tweetbutton&text=Be%20AWARE:%20How%20“Skimmers”%20Steal%20Payment%20Card%20Data> 

[mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/be-aware-skimming](mailto:?subject=Check%20out%20this%20article&body=https://blog.pcisecuritystandards.org/be-aware-skimming)

*  
Our [12-post series](https://blog.pcisecuritystandards.org/blog/topic/small-business) explores how small retailers can [**ACT now**](https://blog.pcisecuritystandards.org/blog/act-now-black-friday-hacker-season) to repel data thieves during this prime shopping season. *

***A**wareness, **C**hecking security controls and **T**esting security now will help your business lock down your systems before the holiday rush.*

*Merchants looking for more information on how to secure customer payment data should visit the    *[*PCI SSC merchant site*](https://www.pcisecuritystandards.org/merchants/)*. *

**How “Skimmers” Steal Payment Card Data**

Picture a swimming pool cleaner sweeping up leaves with a net. Likewise, hackers attach small hardware “skimming devices” to the card reader that sweeps up your customers’ payment card data when they use their cards at your store. Hackers use the data to create counterfeit cards and make illegal purchases.

Skimming is one of the leading types of fraud. Watch out for skimmers during the busy holiday shopping season!

A skimming device can fit in the palm of a dishonest retail employee. Data thieves also slip skimmers into your point-of-sale card reader. Some skimmers have tiny cameras that capture PINs entered by unsuspecting customers. Make sure (and make sure your employees know) that anyone coming to service your equipment is known and planned for – that is most often how these skimmers are installed.   

Here are three simple steps how you can prevent card skimming:

1. **Scout easy targets of attack. **For retail stores, skimmers are most often found in point-of-sale terminals or card readers. Beware when your terminal or card reader sits where easily reached by customers! Move these devices out of reach to keep them safe.
2. **Watch for skimming devices. **A skimming device hidden in your terminal or card reader is invisible. Regularly inspect your point-of-sale devices for signs of tampering, such as a broken seal over an access cover or screws, odd cables, or new devices that you don’t recognize.
3. **Disable skimmers immediately!** If you think a skimmer is present, immediately call your point-of-sale installer for help. Follow their instructions. You might need to manually process cards until the installer arrives to inspect your device. Better to be safe than sorry!

Resources that can help you:

- [Resource Guide: Skimming](https://www.pcisecuritystandards.org/documents/PCI%20SSC%20Skimming%20Resource%20Guide-v05.pdf)

Merchants looking for more information on payment security essentials should start here:

[![Payment Security Essentials for Merchants](https://no-cache.hubspot.com/cta/default/281302/07b993b4-2ba8-4a34-8bf5-afbb43bca162.png)](https://cta-redirect.hubspot.com/cta/redirect/281302/07b993b4-2ba8-4a34-8bf5-afbb43bca162)

 

### LIKE WHAT YOU READ?

Subscribe to the PCI Perspectives blog to receive insights, information and practical resources to help your organization protect payment data.

[Subscribe Here](https://training.pcisecuritystandards.org/subscribe-to-pci-perspectives-blog)

![Laura K. Gray](https://blog.pcisecuritystandards.org/hubfs/Headshots/laura-gray.jpg)

[ Laura K. Gray ](https://blog.pcisecuritystandards.org/author/laura-k-gray)

[Twitter ](https://www.twitter.com/pcissc) [Email](mailto:blog@pcisecuritystandards.org) [Website](http://www.pcisecuritystandards.org)

 The PCI Security Standards Council (PCI SSC) is a global forum that brings together payments industry stakeholders to develop and drive adoption of data security standards and resources for safe payments worldwide.

[< Return to Blog Home](https://blog.pcisecuritystandards.org) [Print](https://blog.pcisecuritystandards.org/be-aware-skimming#)