ATM Card Skimming & PIN Capturing - : Customer Awareness Guide
ATM Card Skimming & PIN Capturing - : Customer Awareness Guide
ATM Card Skimming & PIN Capturing - : Customer Awareness Guide
Group Security
Commonwealth Bank of Australia
November 2009
What is ATM card skimming?
ATM Skimming is a worldwide problem
Skimming is a method used by criminals to capture
data from the magnetic strip on the back of an ATM
card
The devices used are smaller than a deck of
cards and are fastened in close proximity to, or over
the top of the ATM’s factoryinstalled card reader
Personal Identification Number (“PIN”) capturing is a
worldwide problem
PIN capturing refers to a method of strategically
attaching cameras and various other imaging devices
to ATMs to fraudulently capture PIN numbers
Once captured, the electronic data is encoded onto
fraudulent cards and the captured PINs are used to
withdraw money from customers’ accounts
• Light diffuser area
1
11 • Speaker area
2
2
• ATM side fascia
3
3 3
4 • Card reader entry slot
5 4
Could you tell if
this ATM had a
skimming device
fitted to the card
reader?
Normal fascia Skimmer device attached near
An unadulterated ATM fascia. The the card reader slot.
flashing leadthrough entry indicator Although the device has been given
can be easily seen. the appearance of being a standard
Note: Most skimming devices will part of the terminal, it is in fact an
obscure the flashing entry indicator. additional fitted piece clearly
This detail serves as a vital clue in different from the photo on the left.
identifying suspect tampering. Note: No flashing leadthrough light
can be seen & the shape of the bezel
is clearly different.
An example of
a skimming
device being
‘piggybacked’
onto the card
reader
Another
example of a
skimming
device being
installed on
the ATM’s card
reader
An example of
where a hole was
made in the fascia
to insert a
skimming device.
The fascia plate
was then replaced
to conceal the
entry point
The ATM fascia
plate
(highlighted in
yellow) has a
PIN capturing
device fitted to
the top of the
ATM – typically,
these devices
are difficult for
the untrained
eye to detect
Open
The PIN
capturing
device has
been
installed on
the inner
side of the
fascia plate
1 A brochure holder has been placed
on the side ATM fascia wall
Take a closer look at brochure
holder…. a pinhole camera has
been installed. This is done to
capture images of the keypad and
customers’ inputting their PIN
A skimmer plate
can be placed
over the top of
the existing
keyboard as a
method of PIN
capturing
An example of
what an ATM
skimmer plate
can look like
4
• Skimming • Length of time • Successful • Criminals may
devices are skimming skimming stay nearby to
normally devices can requires both observe
affixed to be affixed can a card proceedings &
ATMs during vary, but skimmer (card remove
periods of low normally are reader) & equipment at
traffic, e.g. no more than camera (PIN short notice in
early for 24 hours capturing order to later
morning/late device) to be download
evening fitted to the information.
ATM in order • This data may
to steal card be transmitted
data wirelessly to
other devices
located
nearby
3 Familiarise yourself with the look/feel of the ATM fascia on the machines
6 Is there anything unusual? (card reader, area immediately above the screen)
By being vigilant, you can reduce the risk of skimming