What is Card Cloning? Card cloning, also know as credit or skimming, involves the illegal replication of credit or debit cards without authorization. This illicit practice enables criminals to utilize copied cards for payments, essentially seizing the cardholder's funds and potentially plunging them into debt.

Recruitment of an accomplice, often someone with physical access to credit cards such as a cashier or restaurant server. Equipping the accomplice with a skimmer, a compact device designed to illicitly capture card details. Skimmers can be standalone machines or add-ons to regular card readers. The unsuspecting customer hands their card to the accomplice for payment.

The accomplice swipes the card through both the skimmer and the standard point-of-sale (POS) machine. The card is returned to the customer, who remains unaware of the cloning process. The captured details are transferred by the thief to the magnetic strip of a counterfeit card, which may have been stolen itself. The counterfeit card can then be used for various fraudulent activities, including unauthorized transactions and gift card scams. Variations and Additional Techniques: Card cloning schemes can vary, with criminals employing different tactics to obtain card information:

Skimmers may be affixed to ATMs or handheld card readers, allowing thieves to capture data whenever cards are swiped or inserted. Thieves may also resort to shoulder-surfing or social engineering tactics to obtain additional information, such as PINs or billing addresses, enhancing their ability to exploit stolen card details across multiple platforms.

Card cloning, or the creation of counterfeit credit and debit cards, has long been a concern for financial institutions and consumers alike. With the adoption of more secure chip-and-PIN cards regulated by the EMV standard in the United States, there was hope for increased transaction security and a decrease in card fraud. However, recent discoveries by our researchers reveal a concerning development.

A group of cybercriminals from Brazil has manage to exploit vulnerabilities in chip-and-PIN card technology, demonstrating the ability to steal card data and successfully clone these supposedly secure cards. This revelation challenges the notion that chip-and-PIN cards are immune to cloning-based fraud.

During investigations into ATM jackpotting malware used by the Brazilian group Prilex, our researchers uncovered a modified version of this malware. This modified malware not only targeted ATMs but also infected point-of-service (POS) terminals, enabling the collection of card data during transactions.

By infecting POS terminals, the malware intercepted and transmitted card data to the cybercriminals in real-time when customers made purchases. However, possessing the card data was only part of the equation; the cybercriminals also needed the ability to clone cards, a process complicated by the security measures inherent in chip-and-PIN technology.

The Prilex group develope a sophisticated infrastructure that allowed them to create cloned cards, defying the assumptions of card security. To understand how this was possible, it's essential to grasp the workings of EMV cards and the cloning process.

EMV cards contain embedded chips functioning as miniature computers, executing various applications during transactions. Upon insertion into a POS terminal, a sequence of steps is initiated: Buy Cloned Debit Cards

  1. Initialization: The terminal receives fundamental card information, including the cardholder’s name, expiration date, and supported applications.
  2. Data authentication (optional): The terminal verifies the card’s authenticity using cryptographic algorithms, ensuring its legitimacy.
  Cardholder verification (optional): The cardholder provides either a PIN code or a signature to authenticate the transaction, preventing unauthorize card usage.

Despite these security measures, the Prilex group devise methods to circumvent them, highlighting the ongoing challenges in combating sophisticate cybercrime.

Is Card Cloning Still a Threat?

With payment card issuers and networks ramping up security and introducing new technologies, and consumers getting savvier, card skimming is believed to be on the decrease, with counterfeit cards only amounting to 2% of card fraud losses in 2019 compared to 13% in 2010, per a 2020 report by UK Finance.

It seems that the focus has shifted to different methods, such as card not present (CNP) attacks and using NFC technology to obtain the details of contactless-enabled cards.

Nevertheless, this does not mean that card cloning has stopped. For instance, in January 2021 the debit card data of over 500 customers was stolen using card cloning in India. The authorities arrested four men and recovered three credit card skimmers, with which they had made payments of INR 150,000.

Together with its more recent incarnations and variations, card skimming is and ought to remain a concern for organizations and consumers.

What Is Credit Card Fraud?

  • Credit card fraud is the theft and unauthorized use of your credit card information.
  • Two of the most common types of credit card fraud are skimming and card cloning. Be sure you know how to recognize the warning signs of each scam.
  • If you or a loved one has fallen victim to credit card fraud, be sure to reach out to your card issuer to dispute fraudulent charges and request a new credit card.

Credit card fraud — the theft and unauthorized use of your credit card information — can wreak havoc on your finances and credit scores. Luckily, you can help protect your credit card from thieves by recognizing the signs of fraud and taking steps to secure your personal information.

4 Common Ways Credit Card Fraud Happens

Credit card fraud is a surprisingly common crime that can occur in many different forms.

  • Card-present fraud occurs when someone uses a stolen credit card or a fraudulent duplicated card to make unauthorized purchases in a store or other face-to-face setting. However, modern technology brings plenty of opportunities for digital theft as well.
  • Card-not-present fraud occurs when someone gains access to your credit card information without obtaining the card itself. For example, a thief might use a phishing scheme to install harmful software, known as malware, on your computer to record your keystrokes or otherwise spy on your device, with the intent to steal your credit card information from a distance. The criminal might then sell the card’s information or use it themselves to make fraudulent purchases.

