Skip to content

Comment on Shimming: the newest con for stealing credit card info from ATM machinesparent

Comments

I believe that the current attack in the US combines the aforementioned technology with a small camera mounted on the top of the ATM to capture a user's pin number.

It's even simplier, the crook usually stands in line behind the victin watching when the PIN is inserted. It's called should-surfing.

More sophisticated techniques are a hidden spy camera mounted on the top of the ATM (as you say) or even a fake PIN pad wich logs every button pressed. However the majority of attacks are usually performed trough social engineering.

Anyway to stole credit card information for forgery you need to retrieve the data stored in the card and the PIN. Skimming/Shimming is about the first part only, and the data obtained is useless without a valid PIN.

For this reason next generation ATM will avoid PIN insertion by using biometric technologies. Actually Japan an Poland are the first country in the world with biometric ATMs, for what I know.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.