Defending POS Terminals Against Skimmers, Shimmers, and Tampering
Even as payment cryptography has grown stronger, the physical payment terminal remains a target. Attackers do not need to break EMV if they can attach a device that captures data before the chip ever protects it, or if they can tamper with a terminal to harvest PINs. This field guide explains the main physical threats and the inspection habits that keep terminals trustworthy.
Skimmers
A skimmer is a device attached over or inside a card reader to capture magnetic stripe data. On unattended terminals like fuel pumps and ATMs, skimmers are often paired with a hidden camera or an overlay keypad to capture the PIN as well. Because they read the static magnetic stripe, they remain effective wherever stripe fallback is still possible.
Shimmers
A shimmer is the chip-era evolution of the skimmer. It is a thin device inserted into the chip slot that sits between the card and the reader to intercept data from the chip. Shimmers are harder to detect because they hide inside the slot. Importantly, the dynamic cryptograms EMV produces limit what a shimmer can reuse, but shimmers can still capture enough data to enable magnetic stripe counterfeiting where fallback is allowed.
Why fallback matters: many physical attacks only pay off because a captured card can still be used as a magnetic stripe transaction somewhere. Restricting stripe fallback undercuts the entire business model.
Terminal Tampering
Beyond add-on devices, attackers may open a terminal to implant hardware that captures PINs or card data internally. Modern PIN entry devices include tamper-responsive protections that wipe cryptographic keys if the case is opened, but only if the terminal is genuine and its protections are intact. Swapped or counterfeit terminals defeat this entirely.
An Inspection Routine That Works
- Know your baseline: Photograph your terminals when new so staff can spot changes in color, seams, or attachments.
- Tug and wiggle: Overlays and skimmers are often attached with tape or glue and will move or come loose.
- Check the card slot: Look for anything protruding or resistance when inserting a card, which can indicate a shimmer.
- Verify serial numbers and seals: Confirm tamper-evident seals are intact and that the device on the counter is the one you deployed.
- Control physical access: Never leave terminals unattended in a way that lets someone swap them.
Reduce the Incentive
Layered controls shrink the payoff of physical attacks. Point-to-point encryption means captured data is already encrypted, disabling magnetic stripe fallback removes the easy cash-out path, and staff training turns every employee into a sensor for tampering.
Conclusion
Skimmers, shimmers, and tampering exploit the physical layer that cryptography cannot reach on its own. Regular, informed inspection combined with P2PE and restricted stripe fallback keeps these attacks from paying off. Make terminal inspection a routine part of opening and closing, not a reaction after fraud appears.