A driver pays at a fuel pump on a Tuesday evening in 2026. Nine days later, USD 400 is withdrawn from the account at a cash machine 300 miles away. The card never left the wallet. The strip of data on the back was tampered with.
The FBI estimates that skimming costs financial institutions and consumers more than USD 1 billion each year. Skimming is only how the data gets taken. Cloning is one of the things criminals use it for afterwards, and the two require different controls.
If you run fraud, risk, or compliance at an issuer, an acquirer, or a merchant, the controls in this piece are yours to set. Anyone who has just found a charge they do not recognise should jump straight to the next section.
If a charge you do not recognise has just appeared
Speed matters more here than working out exactly what happened. The people who lose the least are those who freeze the card first and ask questions afterwards. Work through these four steps in order, then come back to the rest of the article once the immediate problem is contained.
- Freeze the card in your banking app. Most issuers offer this now, and it takes seconds.
- Call the number printed on the back of the card. Never use a number from a text message or an email, because that is how the follow-up scam usually starts.
- Dispute every transaction you do not recognise, including the small ones. A tiny charge is often a test to see whether the card is live.
- Ask the issuer to remove any wallet tokens linked to the old card, not just to post you a new one. A replacement card does not always kill the digital copies of the old one.
What is Card Cloning?
Card cloning is the copying of reusable payment-card data onto another magnetic stripe so that the duplicate can be presented as the original. The driver at the fuel pump did not lose a card. They lost a copy of the data that identifies it, which is harder to notice and much harder to undo.
Everything turns on one weakness. Magnetic-stripe data is static, so the same values are presented every single time the card is swiped. Read it once, and you can write it somewhere else. An EMV chip, named for the Europay, Mastercard, and Visa standard behind it, behaves differently. It produces a fresh cryptogram for every transaction, and a used one cannot be reused. Attackers can copy a stripe. They generally cannot build a working copy of the chip sitting beside it.
A quick note on the words, because they get used interchangeably, and that confusion costs money. Skimming is how the data is stolen. Cloning is one way it gets reused, copied onto another stripe. Online purchases and wallet fraud reuse the same details with no plastic involved at all. Same stolen card, three different problems, three different sets of controls.
Credit and debit card cloning starts from the same theft and hurts in different ways. A cloned debit card paired with a stolen PIN can pull cash straight out of a current account, and that money is gone while the dispute runs its course. Cloned credit cards often surface later as purchases the cardholder never made. Liability and reimbursement rules vary by country, issuer, and card type, which is why reporting speed matters more than knowing the rules.
How does card cloning work?
Three stages, each belonging to a different owner. Data is captured at a terminal that someone else is responsible for. The copy gets made somewhere nobody will ever see. Then the clone gets used at a point of acceptance, which you may or may not control. That split matters because it tells you which control actually failed when a loss lands on your desk.
How the data gets captured
A skimmer is an unauthorised reader placed over, inside, or beside a legitimate card reader at a cash machine, fuel pump, or point-of-sale terminal. It captures magnetic-stripe data while the card is being used completely normally. Some devices store what they read for later collection. Others transmit it, which means the operator never has to return to the scene. Often, a concealed camera or a keypad overlay sits alongside, recording the PIN, and a stolen PIN is what turns a card-fraud problem into a cash-withdrawal problem.
A shimmer works differently. Thin enough to sit inside a chip reader, it intercepts data passing between the chip and the terminal. What it cannot do is produce the chip’s one-time cryptogram, so no amount of shimming yields a working EMV clone.
The static data it captures is still worth something, and this is the part most articles skip. In a technique Gemini Advisory documented in 2020, called EMV-Bypass Cloning, criminals lifted data from chip transactions and reformatted it into magnetic-stripe records. It worked because some issuers were not checking that the card verification value presented actually matched the one the chip should have produced. Two breaches in that research accounted for more than 720,000 compromised cards. The chip did its job. What failed was the validation sitting behind it, and that distinction is where the fix lives.
How the copy gets made
Once static stripe data is in hand, writing it onto another stripe is trivial. Blank cards and encoders are cheap and perfectly legal to own because hotels, gyms, and transit systems all use the same technology. This is the cloning step, and from a defensive point of view, it is the least interesting link in the chain. The copy lacks the original chip’s protection. What it needs is somewhere that will still take a swipe.
How the clone gets used
A physical clone is presented at a cash machine when the PIN is captured or at a merchant that still accepts swipe data. Stolen details may also be typed into a checkout page or pushed into a digital wallet, and those are separate routes that need separate answers. Swipe fallback is what physical clones depend on, so retiring it weakens them considerably. It does nothing about card-not-present fraud; it needs authentication and transaction-risk controls instead.
Card skimming vs cloning, and where shimming fits
The three terms describe three distinct moments, and getting them straight changes the order in which you investigate. Skimming reads magnetic-stripe data at the point of use. Shimming intercepts data inside the chip-reader path. Cloning copies reusable data onto another stripe afterward. When a loss lands, work backward from how the data was captured, because that is what tells you which control failed.
| Comparison | Card skimming | Card shimming | Card cloning |
|---|---|---|---|
| What it is | Reading static magnetic-stripe data | Intercepting data inside a chip reader | Copying reusable data onto another magnetic stripe |
| Where the device sits | Over, inside, or beside a card reader | Inside the chip slot, between the card and the reader | No capture device; this is a later duplication step |
| What it captures or uses | Track data, with the PIN often captured separately. | Some data exchanged during the chip transaction | Previously stolen reusable card data |
| What makes it possible | Stripe counterfeiting and unauthorised transactions | Other fraud where static data is accepted elsewhere | Swipe, fallback, or cash-machine fraud is where accepted |
| What it cannot do | Create a valid EMV cryptogram | Create a working EMV chip clone | Pass chip or token authentication is enforced |
Where else does stolen card data end up?
Not every stolen card ends up on counterfeit plastic. Plenty of it goes straight to a checkout page or a digital wallet, and those attacks result in the same customer loss without a single piece of plastic being made. Only controls that follow the payment credential across channels will catch both routes.
In “In Wallet We Trust”, presented at USENIX Security 2024, researchers from the University of Massachusetts Amherst and Penn State tested this directly. They ran attacks against cards from several major US banks, including Chase, American Express, and Bank of America, across Apple Pay, Google Pay, and PayPal. Weak knowledge-based checks were enough to add somebody else’s card to an attacker’s wallet. Worse, wallet tokens sometimes continued to work after the victim had locked the card and received a replacement. UMass has since stated that the specific loophole was resolved, so read the paper as evidence for control design rather than a live description of any issuer today.
Tokenisation is not the weak point here. EMV payment tokenisation replaces the primary account number with a token restricted to a single merchant, device, or payment scenario, and the cryptographic protections hold up. The risk sits in front of it, at the moment, an attacker passes the identity checks needed to be handed that token.
Card addition, device change, reported loss, and card replacement form a single, connected sequence of high-risk events, not four unrelated ones. Strong multi-factor authentication, device and account risk signals, token revocation, and fresh verification after any material change break the chain before stolen details ever become spendable.
How can you tell if a card has been cloned, and can it be traced?
The clearest signal is still the oldest one, a transaction or a cash withdrawal nobody recognises. Small unexplained charges deserve a second look rather than instant panic, because legitimate merchants run temporary verification holds that look identical to a fraudster testing whether a card is live. Check the merchant name first, then act.
Other signals are quieter. An unexpected decline on a card with money available. A payment alert from a city the cardholder has never visited, or from a device they do not own. Or a card that simply stops working one morning. Any of these warrants a freeze, a call to the issuer on a trusted number, and a review of every wallet linked to the account, rather than just the recent transactions.
The transaction itself can often be traced, within limits. Authorisation records include the merchant, the time, the entry method, and, frequently, a terminal or acceptance identifier. Line up several victims, and those records usually point to an issuer or a network towards a likely common point of purchase, which is how skimmer locations get found. What the records will not reliably do is identify the person holding the clone or show where the money eventually went.
For the cardholder, none of that matters as much as speed. Report it, keep the alerts and receipts, dispute the transactions, and ask the issuer to review payment tokens and linked devices when the card is replaced. On the issuer side, fraud reporting, card reissue, and token revocation should be handled in a single workflow, because a compromised digital credential that survives physical replacement is a loss waiting to happen twice.
How to prevent card cloning
Card cloning prevention is a three-party job, and any vendor claiming that one control covers it all is selling something. Merchants own the point where data gets captured. Issuers decide which transactions and which tokens get approved. Cardholders control how much they expose and how quickly they react. A program that covers only one of the three has a hole, and the measure that matters is whether suspicious activity is stopped before money leaves the account.
For issuers and merchants
- Cut magnetic-stripe acceptance and fallback wherever business rules and regulations allow. This is the one that matters most, because physical clones live or die on whether a copied stripe gets accepted, and declining those transactions removes the payout at source rather than chasing it afterward. Where an exception is genuinely unavoidable, put a risk-based step-up behind it and review how often it fires.
- Check payment terminals regularly for signs of tampering and keep a record of each inspection. Criminals are more likely to target unattended or rarely monitored terminals. Use tamper-evident seals and remove any terminal from service immediately if it looks damaged or altered. Regular checks can help detect physical tampering before stolen card data is used for fraud.
- Treat adding a card to a wallet as a high-risk event in its own right. Billing details and other knowledge-based checks already sit in breach data, so multi-factor authentication belongs there, not just at account opening.
- Revoke or re-authenticate tokens after every loss report and every reissue. Kill anything suspicious linked to the old credential, and require fresh verification before a replacement card is moved to a different device.
- Watch the whole payment flow rather than single transactions. A shared point of purchase across several victims, repeated low-value authorisations, an unusual entry mode, a sudden device change, and activity spread across multiple accounts. For online payments, pair those signals with cardholder authentication and transaction-risk controls.
For cardholders
Nothing below is exotic, and most of it takes seconds.
- Choose contactless, a wallet, or a chip insertion over a swipe whenever the option exists. Chip payments generate a transaction-specific cryptogram, and tokenised wallets replace the account number with a restricted token, so both reduce your exposure to reusable Stripe data. Lock the device and the payment account with a strong passcode and multi-factor authentication.
- Look at the reader before your card goes anywhere near it. A card slot, keypad, or surrounding panel that sits loose, crooked, damaged or simply different from the machine next to it is reason enough to walk away. Well-lit and supervised beats convenient.
- Cover the keypad with your other hand. A skimmer can still take card data and walk away with nothing usable at a cash machine, provided the PIN never made it onto the camera.
- Turn on transaction alerts and still read the statement. Real-time notifications shorten the gap between misuse and action, but alerts get delayed and filtered, so the monthly read-through is not redundant.
- Treat every unexplained charge as real until you have checked the merchant. Freeze first, call the issuer on a trusted number, and ask whether wallet tokens or linked devices need to be removed as well as the card itself.
Is the magnetic stripe going away?
Slowly, and on one network’s schedule rather than the industry’s. Mastercard published a phase-out timetable that has been running since 2024, when newly issued Mastercard credit and debit cards stopped being required to carry a stripe in most markets. From 2027, US banks will no longer be required to issue chip cards. By 2029, no new Mastercard credit or debit card will be issued with a stripe at all, and by 2033, none will still carry one. Prepaid cards in the US and Canada are currently exempt.
Read that as a shrinking attack surface rather than a finished problem. Other networks, other markets, and the long tail of cards already sitting in wallets all move at their own pace, and a clone only needs one place that still takes a swipe.
The wider numbers make the case for layering. Payment card fraud losses worldwide dipped 1.2% to USD 33.41 billion in 2024, and the Nilson Report projects USD 41.06 billion by 2030. Those figures cover credit, debit, and prepaid fraud in total rather than cloning on its own, and that is rather the point. Losses keep moving between channels faster than any single control can follow them.
Staying ahead of card cloning
Card cloning is becoming harder as chip and contactless payments replace magnetic stripes, but stolen card data remains valuable across online payments and digital wallets. That means prevention cannot stop at the physical card. Merchants need secure terminals, issuers need stronger transaction and wallet controls, and cardholders need to respond quickly to suspicious activity. The strongest defence is one that follows the payment credential wherever it is used.
Frequently Asked Questions
Q: Is it possible to clone a card?
A magnetic stripe can be copied because it presents the same static data every time. An EMV chip cannot, because it generates a fresh cryptogram for each transaction. A copied stripe only works where a swipe or a stripe fallback is still accepted.
Q: Can cloned cards be traced?
Issuers and card networks can investigate authorisation records covering the merchant, time, entry method and often the terminal. Across several victims, those records frequently point to a common point of purchase. They do not reliably identify the person using the clone or show where the money went.
Q: What is the difference between card cloning and card skimming?
Skimming is the theft of magnetic-stripe data through an unauthorised reader. Cloning is the later act of copying that data onto another stripe. Shimming sits inside a chip reader and intercepts data, but it cannot reproduce the chip's one-time cryptogram or create a working EMV clone.
Q: How can I tell if my card has been cloned?
Look for transactions or withdrawals you do not recognise, unexpected declines, payment alerts from unfamiliar places, or a card that suddenly stops working. A tiny unknown charge can be a fraudster testing the card, or a legitimate verification hold. Check the merchant, freeze the card, then call your issuer.
Q: Does a new card stop the fraud?
Not always. Wallet tokens created from the old card can survive a physical reissue, so ask your issuer to review and revoke every wallet and linked device connected to the compromised card, not just to post you a replacement.















