Conventional Credit Card Frauds Persist

Conventional Credit Card Frauds Persist

Welcome to Kernel Panic! A weekly newsletter authored by Lily Hay Newman and Matt Burgess, delving into the evolving realm of privacy and digital security. To get this newsletter delivered to your inbox every week, sign up here.

When every unexpected text message seems like a scam, and with AI amplifying digital fraud, traditional credit card skimmers and fake letters arriving in your mailbox may appear ludicrous as potential dangers in 2026. However, as we all endure what feels like an endless stream of possible scams, these outdated tactics continue to exact a heavy toll on victims globally.

The counterfeit-new-credit-card-in-your-mailbox scheme is especially devious. Portugal, France, and Germany have experienced waves of physical credit card scams in recent times where criminals have sent out fake replacement cards or letters to potential targets. The accompanying letters often assert that a current card is about to expire, regardless of whether the victim has one nearing its expiration or not. To activate the new (fraudulent) card, the scam letter instructs that it must be registered using a provided QR code or URL. Some bogus cards even display legitimate customer names, says Georg Hauer, an advisor for digital banks. “The card acts almost like a token that establishes the trust required to fall for the actual ruse,” he explains.

If an individual scans the QR code, they are usually redirected to a counterfeit banking site, where they’re prompted to input their information—potentially granting cybercriminals direct access to their true accounts. “This has been on the rise for nearly two years, and I suspect this type of scam might have proven successful enough to be implemented in other countries,” Hauer notes. “The cost of producing a customized fake card has decreased in recent years due to AI’s ability to replicate a design from an image, and the higher conversion rate per victim may warrant the added expenses.”

Mail scams are not the only ‘90s revival on the agenda. The US Attorney’s Office for the Northern District of Alabama charged two Romanian nationals last week with offenses related to alleged credit card skimming. Officials indicate that the duo specifically targeted government SNAP food assistance benefits disbursed to recipients across most states on outdated magnetic stripe-only debit cards, known as Electronic Benefit Transfer (EBT) cards.

Fraud linked to chip credit cards exists as well, but this recent case serves as a reminder that classic skimmers targeting magnetic stripe credit cards are still being used by scammers due to the apparently sufficient swiping occurring to justify their efforts. The FBI reports that EBT card skimming has gained traction among scammers since around 2021.

“Skimmer fraud is widespread with losses in the United States alone surpassing $1 billion annually,” US Attorney Phillip W. Williams Jr. stated in a press release concerning the recent indictment. (This billion dollars encompasses various types of credit card skimming, not just EBT targeting.) “It is a silent, insidious theft that occurs simply by swiping a credit card at a point-of-sale.”

Gary Warner, the intelligence director at the cybersecurity firm DarkTower, highlights that numerous states continue to employ mag-stripe only cards for benefits. “The risk here is that if the mag stripe is compromised, a clone of the card can be generated and access not only the current value but future value as well,” he states.

More broadly, Warner informs us, there are still multiple dangers associated with making payments using the magnetic stripes on any cards—even if they also have more secure chips that have been issued over the past decade. “Non-bank ATMs and smaller non-chain merchants may expose your chip-enabled card to mag stripe reading,” Warner explains. “Mag-stripe skimmers are often positioned in such a manner that the chip read is compelled to fail.”

Leave a Reply