POS Terminal Tampering & Swap Scam
A payment terminal at a shop, restaurant, or fuel station is overlaid, tampered with, or swapped for a look-alike that captures your card data and PIN. Sometimes a dishonest employee runs your card through a second, hidden skimming device out of sight.
Last reviewed: 24 July 2026
What this scam is
Point-of-sale terminal tampering is the manipulation of the card machine you pay with, so that a routine, legitimate-looking transaction quietly copies your card details and, where a PIN is entered, your PIN as well. It takes several forms. A terminal may be fitted with a thin overlay keypad and a fake card slot that sit on top of the real hardware and record every keystroke and swipe. An entire terminal may be swapped for a look-alike that has been opened up and re-engineered inside. At an unattended kiosk — a fuel pump, a parking or ticket machine — a skimmer and a pinhole camera may be hidden within the housing. And in the insider version, a dishonest member of staff takes your card out of sight, or runs it through a second, concealed reader in addition to the real till. The captured data is later used to clone the card's magnetic stripe or to spend where the physical card is not required. Because the payment itself succeeds normally and you keep your card, nothing at the counter signals that anything went wrong; the loss surfaces later, on your statement.
How it works
The tampering happens before you arrive. Overlays and swapped terminals are installed during a staged distraction, an out-of-hours break-in, or by a complicit employee, and are built to be almost indistinguishable from the genuine device. When you insert or swipe your card and type your PIN, the real transaction reaches your bank while the hidden electronics record the stripe data and the PIN in parallel — sometimes the PIN via a pinhole camera angled at the keypad. At unattended machines, criminals return later to retrieve the stored data or collect it wirelessly. The captured details are then encoded onto a blank card to withdraw cash or shop in person, or sold on for use where no physical card is needed. In the insider variant, the mechanics are simpler: a waiter or attendant carries your card away to a back counter and passes it through a handheld skimmer, or the shop's own terminal has been quietly modified. Across every version, the giveaway is not the payment, which works perfectly, but the state of the hardware and where your card travels — and both are easy to miss in a normal, hurried transaction.
Why this scam works
The scam hides inside an interaction you perform without thinking. Paying by card is so routine that few people inspect the terminal, and a good overlay or a swapped unit looks exactly like the real thing. The transaction succeeds and you walk away with your card, so there is no moment of loss to notice — the theft is silent and the consequences are deferred by days or weeks. Trust in the setting helps too: a machine on a shop counter or a branded fuel pump feels institutionally safe, and handing a card to a waiter is a social norm nobody wants to challenge. By the time fraudulent charges appear, the encounter is forgotten and impossible to connect to the debit, which is precisely why compromised terminals can keep harvesting cards for a long time.
Common red flags
- A card slot, keypad, or fascia that looks bulky, loose, or slightly misaligned with the rest of the terminal
- Being asked to hand your card over or told the portable machine 'isn't working, come to the back'
- A staff member taking your card out of your sight to process payment
- Broken, mismatched, or peeling security seals on an unattended pump or kiosk
- A terminal or pump that looks newer, differently coloured, or different from others at the same location
- Being steered toward inserting and typing a PIN when a contactless tap would work
- Unexpected charges or small unfamiliar transactions appearing on your statement afterward
Sanitized example messages
Illustrative, sanitized examples. Personal details are replaced with placeholders such as [phone number] and [fake link].
This card reader is playing up today — just pop your card in and enter your PIN, that side still works fine.
The portable terminal's out of battery, so I'll take the card to the machine at the back and bring your receipt over.
Sign here on the pump screen — oh, the tap isn't reading, use the chip and PIN instead.
Bank alert: a card-present transaction of [amount] was made at [merchant/location]. If this wasn't you, contact us — a mystery charge from a shop you visited days earlier.
How to verify before you act
You cannot audit a terminal's internals, so rely on habits rather than inspection. The distinction that matters most is control: pay only on a device that stays in your sight and, ideally, in your own hand. Prefer contactless tap or a mobile wallet, which transmit a one-time token and never expose the stripe or a PIN to a tampered reader. If you must insert and enter a PIN, cover the keypad with your other hand to defeat any hidden camera, and give the card slot and keypad a quick wiggle — overlays and fake fascia are often loose or bulky. At unattended pumps and kiosks, favour ones in staffed view and check for mismatched colours, misaligned panels, or broken security seals. Never let your card be carried out of sight; ask for a portable terminal brought to you or pay at the counter. Finally, verification is retrospective as much as preventive: read every statement line and enable instant transaction alerts, because the fraud is designed to be invisible until then.
Payment methods used
- Debit card
- Credit card
- Cash withdrawal
Who is usually targeted
- Shoppers and diners
- Fuel and travel customers
- Kiosk and parking users
- Tourists
What to do immediately
- Freeze or lock the card immediately through your banking app, then call your bank or card provider to report suspected skimming
- Ask the bank to cancel and reissue the card and to reverse any fraudulent charges — card-present fraud is usually refundable
- Change your PIN, and change it on any other card that shared it
- Report the compromised terminal or premises to the merchant's head office and to your national fraud service
- Note the exact location, date, and time you used the terminal, so the bank can trace the common point of compromise
- Watch statements on all your cards for further unauthorised activity over the following weeks
How to prevent it
- Pay by contactless tap or mobile wallet where possible — a tokenised tap never exposes your stripe or PIN to a tampered reader
- Keep your card in view at all times and decline to let staff carry it away; ask for a portable terminal or pay at the counter
- Always shield the keypad with your free hand when entering a PIN, to block any hidden camera
- Give the card slot, keypad, and fascia a quick tug — overlays and swapped panels are often loose, bulky, or misaligned
- At unattended pumps and kiosks, choose machines in staff view and check for broken seals or mismatched components
- Turn on real-time transaction alerts and read every statement line, since a tampered terminal leaves no clue at the point of sale
Evidence to preserve
- The date, time, and exact location or pump number where you used the terminal
- Your bank statement or app entries showing the genuine payment and any later fraudulent charges
- Any receipt from the transaction, which records the merchant and terminal reference
- Photos of a suspicious terminal, pump, or kiosk if you can take them safely
Where to report it
- Action Fraud (UK) — UK national fraud & cybercrime reporting centre
- FTC ReportFraud (US) — US Federal Trade Commission fraud reports
- FBI IC3 (US) — US Internet Crime Complaint Center
- Scamwatch (Australia) — Australian competition & consumer reporting
- Your bank's fraud line — Use the number on the back of your card or in your banking app — never a number the caller gives you
Always verify reporting routes and emergency contacts on the official government or agency website for your country.
Frequently asked questions
If my card never left my sight and the payment worked, how could it be skimmed?
A tampered terminal does not need your card to leave your sight — the theft happens inside the device while the real transaction goes through normally. An overlay keypad and fake slot, or a swapped unit, record your stripe data and PIN silently as you pay. That is why the payment succeeding and your keeping the card prove nothing. The compromise is invisible at the counter and only shows up later as unfamiliar charges, so a smooth transaction is not evidence that the machine was safe.
Is tapping my card or phone safer than inserting it?
Generally yes. A contactless tap or a mobile wallet transmits a one-time token rather than your full card number, and no PIN is entered, so a tampered reader or hidden camera has far less to capture. Inserting the card and typing a PIN exposes both the chip or stripe data and the PIN to any overlay or camera on the device. Where a tap is offered, it is the lower-risk choice, and a phone wallet, which never shares the real card number, is safer still.
How do I spot a tampered or swapped payment terminal?
You often can't be certain, so treat it as a habit rather than an inspection. Look for a card slot, keypad, or front panel that seems bulky, loose, mismatched, or newer than the rest of the machine, and give components a gentle wiggle — overlays are frequently not fully secured. At unattended pumps and kiosks, check for broken security seals and panels that don't line up. Most importantly, keep the card in your own hand, shield the PIN pad, and prefer contactless, so a compromised device has less to steal.