Credit Card ShimmersAre You Prepared for “Skimming 2.0?”

Monica Eaton | July 2, 2026 | 10 min read

This featured video was created using artificial intelligence. The article, however, was written and edited by actual payment experts.

Credit Card Shimmers

In a Nutshell

Card skimming is a tactic by which scammers use a device to steal data from magnetic stripe cards. It’s an old trick that no longer really applied in the age of EMV cards…until now. Credit card “shimming” is the next big threat at the gas pump, and it might be the key that helps scammers defeat EMV chip technology. Let’s find out how this tool works, and how much of a risk it poses.

Credit Card Shimmers: How This Simple, Cheap Technology is Helping Criminals Defeat EMV Cards

When EMV technology was rolled out in the US in 2015, it was pitched as a means to bring an end to card-present fraud. The technology made conventional card “skimming” impossible, and also made it much harder for fraudsters to create counterfeit credit cards.

Fraudsters are resourceful, though. In the years since the EMV liability shift, they’ve figured out a workaround for EMV chip protections. Everyone — consumers and merchants alike — is at risk. So, what is card shimming, and how can you protect yourself?

What is a Credit Card Shimmer?

Credit Card Shimmer

[noun]/kre • dət • kärd • SHi • mər/

A credit card shimmer is a device designed to illegally capture data stored in the microchips implanted in EMV-compliant debit and credit cards. Shimmers are very tiny, thin devices that can be fitted into a card terminal, and can read EMV microchip data much in the same way that skimmers can read magstripe data.

Shimming devices were developed as a means to work around EMV microchips, which have all but replaced magstripe stripes that skimmers used to rely on. The tech is so insidious it would be fair to describe card shimming as “skimming 2.0”. 

Credit Card Shimmers

Credit: Hackaday

Fraudsters can't yet fully "clone" an EMV chip that's encoded with a valid user's information. However, they can copy the information stored on an EMV chip using a shimmer, then encode that onto a magnetic stripe card.

The fraudster can use the dummy card at any card-present retailer which allows customers to use a magnetic stripe card. Since mag-stripe cards are still commonly accepted when EMV chips are not available, this means a fraudster can effectively clone your chip card.

Fraud is changing. Are you prepared?

Request a Demo
The Original End-to-End Chargeback Management Platform

Card Shimmers vs. Card Skimmers

TL;DR

Skimmers target magnetic stripe data; shimmers target EMV chip data—but both are tiny devices hidden inside card terminals. Shimmers wirelessly transmit stolen data and are much harder to detect than external skimmer overlays.

So, what’s really the difference between card skimming devices and newer “shimming” devices?

Where the two differ is in the target. Skimmers rely on the static information stored in magnetic stripe cards to steal card credentials. This data can then be copied and uploaded to a counterfeit magstripe card. If you don’t swipe, they can’t copy or clone this data

Skimmers and shimmers are both tiny, often paper-thin devices that fit inside the card terminal directly between the card and the reader. The device itself is so small and innocuous that it’s extremely easy for fraudsters to slip them inside the card slot and very difficult for users to detect. They can also be loaded onto the front of a terminal or ATM machine.

Skimmers read information off of the magstripe included on the card. Shimmers, on the other hand, capture data located inside the EMV microchip that is embedded into your card.

A lot of newer devices now use Bluetooth technology to transmit stolen data wirelessly. This allows criminals to retrieve card information from a distance without physically returning to the compromised terminal, reducing their risk of getting caught. Some law enforcement agencies and security professionals use Bluetooth scanning tools to detect these devices; if a terminal is broadcasting an unfamiliar Bluetooth signal, that’s a sign it’s been compromised. This is a good reason why you should work with payment terminal vendors who build tamper detection and wireless monitoring into their hardware.

Thankfully, shimmers aren’t exactly infallible. For instance, the data stolen can’t be immediately used by the fraudster. If a PIN reader isn’t present, it must be uploaded and then cloned to a separate magstripe card. 

Shimmers are also still quite rare… at least for now. As EMV chips increasingly become the standard, though, shimming is bound to take off and grow rapidly. We’re already seeing the beginning of that trend now.

How Big of a Problem is Card Shimming?

TL;DR

Card shimming is a serious and growing threat that undermines the security EMV was designed to provide. If chip data is no longer safe, the impacts will ripple through every industry connected to payments.

EMV was meant to be the “silver bullet” for card-present fraud. Now, though, we’re seeing more sophisticated card shimmers capable of capturing dynamic transaction keys embedded into EMV chips. That means we’re in serious trouble. 

If EMV data is no longer safe, the impacts will reverberate through every industry linked with payments. With all the time and resources poured into EMV mandates, we could be back at square one for in-person fraud. Not only that, but we must also contend with the surge in card-not-present fraud resulting from the initial EMV liability shift. Online scammers won’t leave online channels and go back to brick-and-mortar; they’ll just take advantage of the opportunity to commit more fraud.

Prevent fraud. Stop chargebacks. Get started today.

Request a Demo
The Original End-to-End Chargeback Management Platform

Why are Criminals Switching to Card Shimmers?

TL;DR

EMV chips use dynamic CVV3 technology that's harder to crack than static magstripe data, forcing fraudsters to innovate. Shimmers let criminals bypass EMV protections entirely by capturing chip data and using it on magstripe cards instead.

Shimmers have actually been around for a few years now, but they only started gaining in popularity fairly recently.

EMV cards use CVV3 verification technology, which is much harder to crack than the older versions of CVV technology used by magstripe cards. Trying to work around CVV3 technology requires a lot more effort than a simple scan and copy. CVV3, unlike CVV1 and CVV2, does not contain static data, meaning that it changes with each transaction. 

The theory is that CVV3-enabled chip cards can prevent the majority of in-person fraud. This may be true to some degree, but it also poses another problem. Without the ability to easily copy and counterfeit cards, fraudsters have been forced to do the same thing as banks and financial institutions the world over: innovate

Shimming essentially allows fraudsters the means to circumvent EMV standards without tipping off CVV3 verification methods. In short, the fraudster can avoid these safeguards altogether and take that information wherever a magstripe swipe is still available.

How Cardholders Can Prevent Card Shimming

TL;DR

Consumers should use contactless payments (tap-to-pay) and mobile wallets like Apple Pay or Google Pay whenever possible, since shimmers can't intercept NFC transactions. Avoid unsecured ATMs and monitor accounts closely for unauthorized activity.

Cardholders do have some recourse if they fall victim to fraud. They may be able to file a chargeback and recover their funds. However, this may be a long, protracted process, and there’s no guarantee that it will succeed. That’s why it’s best to prevent fraud from happening whenever possible.

It’s important for cardholders to opt for the newest security features whenever available. They can look for gas stations, grocery stores, and shops that allow for the use of NFC (near-field communications) technology to complete transactions. They can also try using mobile wallet apps like Apple Pay or Google Pay, which will facilitate contactless payments. 

Currently, shimmers have no real impact on contactless transactions. So, cardholders should take advantage of this payment option wherever available. 

Cardholders should also exercise extra caution when using ATMs in unsecured locations or at gas pumps. These terminals are frequent shimming targets because they're often unattended and may not be inspected as regularly as indoor payment terminals. Before inserting your card, check for signs of tampering: loose or wobbly card slots, unusual bulk around the reader, mismatched colors, or anything that looks out of place. If something feels off, use a different terminal or pay inside where staff can monitor the transaction. Transferring funds with a P2P (person-to-person) payment app like Zelle or Cash App is also a secure option.

Frankly, the best we can do at the moment is to increase awareness of the issue as much as possible and respond accordingly. And, as always, never count on just one method of fraud prevention. 

What Can Merchants Do?

TL;DR

Merchants should tighten magstripe acceptance policies, implement contactless readers, encourage mobile wallet adoption, and deploy layered fraud detection tools. Requiring ID verification for magstripe transactions can prevent shimmed data from being used in your store.

Merchants typically get the short end of the stick when it comes to fraud, even when there’s no obvious way for them to avoid being targeted. That said, merchants can drastically reduce the risk of shimming scams through a combination of effective fraud tools and best practices. 

Here are a few tips for merchants to prevent credit card shimming:

Crack Down on Magstripes

Simply put: there can’t be any shimming scams without a functional magstripe reader to complete the crime. If a customer needs to pay with a card that lacks an EMV chip, the merchant needs to go the extra mile to validate that user’s identity. This means checking the user’s ID and matching it to the card in question. 

This won’t stop consumer data from being stolen through shimmers in other stores. But, it can at least reduce the likelihood that any of it can be used in your store.

Implement Contactless Readers

Shimmers work by making direct contact with the EMV-enabled card. But, contactless card readers are largely impervious to shimming scams.

Despite the fact that contactless payments utilize the same CVV3 technology as EMV chip cards, this data isn’t accessible through a physical skimmer. It’s much more difficult to intercept through wifi and online sources.

Encourage Mobile Wallet Use

Mobile payments like Apple Pay and Google Pay are also impervious to shimming scams and for the same reasons. Without a physical card to insert, a shimmer cannot read the data.

Merchants should consider offering their customers incentives to pay with mobile wallets. For instance, there are ways to offer promo codes and loyalty programs to incentivize adoption.

Did You Know?

When shimmed data is used to make a fraudulent magstripe purchase, the merchant who accepted the swipe often bears liability under the EMV liability shift. If your terminal had chip capability but you allowed a fallback to swipe, you may be on the hook for the chargeback. This positions limiting magstripe acceptance as a direct defense against chargeback losses.

Deploy Fraud Tools

Fraud is not a static problem. In fact, fraudsters are every bit as adaptable as banks and financial institutions. Preventing fraudsters from using stolen data online is just as important as brick-and-mortar detection. This is why every merchant should be using a multitude of fraud tools to spot and prevent fraud. 

Address verification, CVV validation, and 3DS technology are just a few examples of tools that can — and should — be used to verify card-not-present buyers. Odds are, fraudsters may be able to circumvent one verification method, but likely not several working in tandem.

Monitor for Fallback Transactions

Train staff to treat “fallback transactions” — transactions where you get a a chip read error, and you’re prompted to swipe the magstripe instead — with suspicion, especially when combined with other red flags like high-value purchases, unfamiliar customers, or out-of-state IDs.

When a chip fails to read, staff should ask for government-issued photo ID and verify that the name and signature match the card. If something feels off, it's better to decline the transaction than to absorb a chargeback later.

Set a Hard Limit for Fallbacks

On the backend, you can configure your POS system to flag fallback transactions for additional screening, or even to limit the volume or dollar value of non-EMV transactions allowed.

Some systems let you set dollar thresholds that trigger manager approval for swipe transactions after a chip failure. Others can generate reports showing fallback frequency by terminal, helping you identify potentially compromised devices before the damage spreads.

Inspect Terminals Regularly

Regular terminal inspections should be part of your standard operating procedures, especially if you operate unattended card readers, like ATMs, gas pumps, or self-service kiosks.

Even without specialized equipment, staff can look for warning signs: card slots that feel loose or sticky, terminals that look misaligned or have unusual bulk, and keypads that feel spongy or raised. Any terminal that looks or feels different from others in the same location should be taken out of service immediately and reported to law enforcement. Weekly inspections at high-traffic terminals significantly reduce the window criminals have to exploit.

Did You Know?

Physical detection tools can help combat card shimming. Companies like Target have developed internal solutions (such as Target's patented EasySweep tool) that allow staff to quickly check chip card slots for hidden devices. Third-party products like Skim Swipe and Skim Scan can detect both skimmers and shimmers in POS terminals and ATMs, reducing inspection time from hours to minutes.

Multi-Layered Strategies Work Best

Fraud prevention isn’t a one-way street. What works for one business may not necessarily work for another.

Also, not every fraudster is apt to try the same tactic twice. Merchants need to be nimble, adaptable, and willing to embrace multifaceted fraud management strategies. 

Thankfully, this isn’t something you have to suffer through alone. With over a decade in fraud prevention and chargeback management, Chargebacks911 is uniquely placed to help consumers and merchants adjust to an ever-changing fraud landscape. Call us today for your free ROI analysis.

FAQs

What is a card shimmer vs. skimmer?

Skimmers and shimmers are both tiny, often paper-thin devices that fit inside the card terminal directly between the card and the reader. Where the two differ is in the target. Skimmers rely on the static information stored in magnetic stripe cards to steal card credentials. This data can then be copied and uploaded to a counterfeit magstripe card. If you don’t swipe, they can’t copy or clone this data.

Shimmers, on the other hand, capture data located inside the EMV microchip that is embedded into your card. The data collected will then be offloaded wirelessly via a small radio module built into the device.

How do card shimmers work?

Shimmers are very tiny, thin devices that can be fitted into a card terminal, and can read EMV microchip data much in the same way that skimmers can read magstripe data.

Fraudsters can't yet fully "clone" an EMV chip that's encoded with a valid user's information. However, they can copy the information stored on an EMV chip using a shimmer, then encode that onto a magnetic stripe card. The fraudster can use the dummy card at any card-present retailer which allows customers to use a magnetic stripe card.

Is card skimming still a thing?

Yes, card skimming is still a concern. Their use has been declining since EMV mandates went live in the US,  but in 2022, researchers observed a sudden spike in skimmer-related scams. Attacks were up nearly 700% in just the first half of 2022. It is likely that card “shimmers,” or EMV skimmers, were involved in most of these reported scams.

How can you tell if an ATM has a skimmer?

Skimmers are generally loaded onto the front of a card terminal, where a card would be swiped or dipped. There will generally be some ill-fitting colors or some other sign that the device has been tampered with. Watch for these warning signs to spot a skimming device.

Can contactless cards be shimmed?

No. Contactless payments use near-field communication (NFC) technology, which transmits encrypted, one-time-use transaction data wirelessly between the card and the terminal. Because there's no physical insertion into the card slot, a shimmer has no opportunity to intercept the chip data. This is one of the key reasons security experts recommend using tap-to-pay whenever available.

How do I know if my card has been shimmed?

You typically won't know your card was shimmed until fraudulent transactions appear on your account. Unlike skimmers, which are sometimes visible as bulky overlays, shimmers are installed inside the card reader and are virtually undetectable to consumers. The best defense is vigilance: monitor your account regularly for unauthorized transactions, set up real-time transaction alerts through your bank, and report suspicious activity immediately.

What should I do if I think I've been a victim of shimming?

Contact your bank or card issuer immediately to report the suspected fraud. They can freeze your card, issue a replacement, and begin investigating the unauthorized transactions. You should also review your recent transaction history to identify which terminal may have been compromised — this information can help law enforcement. If the fraud involved a debit card, federal law (the Electronic Fund Transfer Act) limits your liability, but acting quickly is essential to minimize losses. Finally, consider filing a report with the FTC at ReportFraud.ftc.gov and your local police department.

Like What You're Reading? Join our newsletter and stay up to date on the latest in payments and eCommerce trends.
Newsletter Signup
We’ll run the numbers; You’ll see the savings.
triangle shape background particle triangle shape background particle triangle shape background particle
Please share a few details and we'll connect with you!
Revenue Recovery icon
Over 18,000 companies recovered revenue with products from Chargebacks911
Close Form
Embed code has been copied to clipboard