Old Scams, New Tricks: Physical Card Fraud and Skimming Endure
Despite the rise of sophisticated digital fraud, 'antiquated' physical credit card scams and magnetic stripe skimmers continue to pose a significant threat, costing victims worldwide. Cybercriminals are leveraging AI to enhance the believability of physical mail scams, while targeting vulnerable systems like EBT cards.
While AI-powered digital fraud dominates headlines, a quieter, yet equally damaging, wave of 'old-school' scams continues to plague consumers and IT security professionals alike. Physical credit card fraud, often involving fake replacement cards sent through the mail, and magnetic stripe skimming are proving remarkably resilient.
### The Resurgence of Mail-Based Card Scams
Countries like Portugal, France, and Germany have recently seen a surge in physical credit card scams. Criminals are mailing phony replacement cards or letters claiming existing cards are expiring soon. These letters often instruct recipients to activate the 'new' card by scanning an included QR code or visiting a URL.
According to Georg Hauer, an advisor for digital banks, some sham cards even feature real customer names, lending an air of authenticity. "The card is almost like a token that creates the trust that is needed in order to fall for the actual trick," Hauer explains.
Scanning the QR code typically redirects victims to a fake banking website, where they are prompted to enter their sensitive details, potentially granting cybercriminals direct access to their real accounts. Hauer believes this type of scam is escalating, noting that "the cost of producing a personalized fake card has dropped in recent years thanks to **AI** just being able to copy a design based on an image, and the higher conversion rate per victim might justify the extra costs."
### Magnetic Stripe Skimming Persists
Beyond mail fraud, the classic credit card skimmer remains a potent threat. The **US Attorneyβs Office for the Northern District of Alabama** recently indicted two Romanian nationals for alleged credit card skimming, specifically targeting government **SNAP** food assistance benefits distributed via antiquated magnetic stripe-only debit cards, known as **Electronic Benefit Transfer (EBT)** cards.
While **EMV** chip cards offer enhanced security, this case highlights that classic skimmers targeting magnetic stripes are still deployed because enough 'swiping' still occurs to make it profitable. The **FBI** reports that **EBT** card skimming has seen a rise in popularity among scammers since approximately 2021.
**US Attorney Phillip W. Williams Jr.** stated in a press release that "Skimmer fraud is rampant with losses in the United States alone reaching over $1 billion each year." He emphasized that it's "a silent insidious theft that occurs by merely swiping a credit card at a point of sale."
Gary Warner, Director of Intelligence at cybersecurity firm **DarkTower**, points out that dozens of states still utilize magnetic stripe-only cards for benefits. "The risk here is that if the mag stripe is compromised, a clone of the card can be created and access not only the current value, but future value as well," Warner warns.
Even chip-enabled cards aren't immune. Warner notes that "Non-bank ATMs and smaller non-chain merchants may expose your chip-enabled card to mag stripe reading. Mag-stripe skimmers are often installed in such a way that the chip read is forced to fail."
### The Future of Card Security and User Vigilance
Though magnetic stripe cards are gradually being phased outβ**Mastercard**, for example, announced it will stop issuing them by 2029, with all remaining cards out of circulation by 2033βthey remain a vulnerability in the interim. Financial fraud has become one of the largest crime types globally, with many attacks relying on social engineering and mass phishing.
Hauer underscores that criminals are driven by maximizing their illicit gains. "The real idea behind some of these scams is to not essentially try to steal β¬2,000 from someoneβs bank account, but rather actually empty a proper savings account, which holds much more money," he explains.
To mitigate these enduring threats, IT security professionals and privacy-conscious users should advise caution:
* **Avoid swiping cards whenever possible**, opting for chip or contactless payments.
* **Inspect terminals** for any signs of tampering, alteration, or damage, especially when using **EBT** cards or at non-bank ATMs and smaller merchants. If a terminal looks suspicious, use another.
* **Apply the same skepticism to physical mail** as you would to suspicious texts or emails. Verify any requests for personal or financial information directly with the issuing institution through official channels, not via links or QR codes provided in the mail.