Skip to Content

How Credit Card Shimming Is Quietly Stealing Your Data at the Checkout Counter

How Credit Card Shimming Is Quietly Stealing Your Data at the Checkout Counter
If you still think your EMV chip card makes you safe from in-store theft, you are behind the curve. Criminals have adapted. The old skimmers that read magnetic stripes are mostly dead, but a newer, stealthier method called shimming has taken their place. Shimming targets the chip itself, and it is happening right now at retail terminals, grocery store self‑checkouts, and gas station pumps across the country. For middle‑class Americans between 45 and 64, who tend to use credit cards for everyday purchases and often carry large reward point balances, the risk is real and growing.

Shimming works like this. A shim is a paper‑thin circuit board, often no thicker than a few sheets of aluminum foil. A thief inserts it into the card reader slot where you normally push your chip card. When you insert your card, the shim intercepts the communication between your chip and the terminal’s legitimate reader. It captures the data that your chip transmits — the same information used to authorize a transaction. At the same time, a hidden camera or an overlay keypad records your PIN if you use a debit card. The thief then takes that captured chip data and writes it onto the magnetic stripe of a blank card. That cloned magnetic stripe card can be used at older terminals that still accept swipe transactions, or the data can be used for online purchases where no chip is required.

The reason shimming is dangerous for your credit card points is simple. Once a criminal has your full card number, expiration date, and CVV — all of which can be extracted from the chip data — they can load that information into a digital wallet or use it to make purchases that earn or redeem points. Some thieves specifically target high‑limit cards with large reward balances. They drain your points by buying gift cards or merchandise that is later resold. By the time you notice your points are missing, the thief has moved on.

Real‑world cases have confirmed that shimming is not just a theory. In 2023, a network of thieves in the Midwest was caught using shims at self‑checkout lanes in big‑box stores. They retrieved the shims after a few hours, collected the data, and produced cloned cards. The damage ran into the hundreds of thousands of dollars before the operation was shut down. Law enforcement agencies note that shimming is hardest to detect at unattended or lightly monitored terminals — self‑checkout at grocery stores, fuel pumps, and parking lot payment kiosks are prime targets.

What should you look for? Start by inspecting the card reader before you insert your card. A shimmed reader often feels looser than normal, or the slot itself may appear slightly deeper because the shim takes up space. Look for a thin gap between the plastic housing of the reader and the slot opening. Some thieves also place a small piece of tape or a sticker designed to disguise the shim. If the reader wobbles, has scratches around the slot, or looks different from other readers in the same store, do not use it. Consider using a different terminal or paying cash.

Your best defense is to avoid inserting your chip card entirely. Contactless payments — tap‑to‑pay with your physical card, or using Apple Pay, Google Pay, or Samsung Pay on your phone — are immune to shimming. The reason is that contactless transactions use a different, encrypted method of communication that changes for every transaction. A thief cannot capture a static piece of data from a tap. Many retailers have enabled tap functionality, even at checkout lanes that still have a chip slot. Make it a habit to tap instead of insert whenever you see the contactless symbol.

If you must insert your card, use a shielded wallet or RFID‑blocking sleeve, though these do not fully protect against an internal shim inside the reader. More importantly, monitor your credit card and debit card statements at least once a week. Set up transaction alerts for any charge over a small amount — say, $25 — so you get a text or email in real time. For your reward points, log into your loyalty accounts regularly and check your recent activity. Many programs let you set up alerts for point redemptions. Enable two‑factor authentication on your reward account to prevent a thief from logging in with just your credit card number.

If you find a suspicious charge or missing points, call your card issuer immediately. Federal law limits your liability for unauthorized credit card charges to $50, and most issuers waive that. For debit cards, the protections are weaker, so act fast. Report the terminal location to the store manager and to the Secret Service or local authorities — shimming is considered a form of credit card fraud and is often investigated by federal agencies.

The bottom line is this: chip cards were a major step forward, but they are not bulletproof. Criminals now have shims that cost pennies to make and can be installed in seconds. Staying safe means staying skeptical of every card reader you touch, using tap‑to‑pay whenever possible, and keeping a close eye on your statements and points balances. The thieves are counting on you to be complacent. Do not give them that satisfaction.


Scam Watch

Protect it before they take it.

Dual Agency: The Hidden Pitfall That Could Wipe Out Your Home Equity

Dual Agency: The Hidden Pitfall That Could Wipe Out Your Home Equity

Real Estate Agents and Broker Misconduct · You’re selling your home.
How Loan Modification Scams Prey on Homeowners

How Loan Modification Scams Prey on Homeowners

Home Loans and Mortgage Manipulation · If you are a homeowner struggling to keep up with your mortgage payments, you may be desperate for a lifeline.
The Gift Card Tampering Scam: How Thieves Steal Your Money Before You Even Hand Over the Card

The Gift Card Tampering Scam: How Thieves Steal Your Money Before You Even Hand Over the Card

Prepaid Cards and Gift Card Tampering · You pick up a prepaid gift card at the drugstore for a niece’s birthday.