Old-School Credit Card Scams Are Far From Dead
Welcome to Kernel Panic! A weekly newsletter by Lily Hay Newman and Matt Burgess from inside the new world of privacy and digital security. To receive this newsletter in your inbox each week, sign up here.
When every random text message feels like itās a scam, and with AI supercharging digital fraud, old-time credit card skimmers and bogus letters that arrive in the mail may seem laughable as potential threats in 2026. But as we all suffer through a seemingly unending barrage of potential scams, these antiquated attacks are still costing victims around the world dearly.
The fake-new-credit-card-in-your-mailbox trick is particularly insidious. Portugal, France, and Germany have all had waves of physical credit card scams in recent years where criminals have mailed phony replacement cards or letters to potential victims. Included letters often claim a current card is set to expire soon, whether the victim actually has one that’s about to expire or not. In order for the new (fake) card to be activated, the scam letter says, it should be registered using an included QR code or URL. Some sham cards even have real customer names printed on them, says Georg Hauer, an advisor for digital banks. āThe card is almost like a token that creates the trust that is needed in order to fall for the actual trick,ā he says.
If someone scans the QR code, theyāre typically redirected to a fake banking website, where theyāre asked to enter their detailsāpotentially giving cybercriminals direct access to their real accounts. āThis has been escalating for close to two years, and I believe that this type of scam might have proven to be successful enough to be rolled out in other countries,ā Hauer says. āThe cost of producing a personalized fake card has dropped in recent years thanks to AI just being able to copy a design based on an image, and the higher conversion rate per victim might justify the extra costs.ā
Mail scams arenāt the only ā90s throwback on the docket. The US Attorneyās Office for the Northern District of Alabama indicted two Romanian nationals last week on charges related to alleged credit card skimming. Authorities say the pair specifically targeted government SNAP food assistance benefits distributed to recipients in most states on antiquated magnetic stripe-only debit cards, or Electronic Benefit Transfer (EBT) cards.
Fraud related to chip credit cards does exist as well, but this recent case serves as a reminder that classic skimmers targeting magnetic stripe credit cards are still deployed by scammers because thereās apparently still enough swiping going on to make it worth their while. The FBI says that EBT card skimming has risen in popularity among scammers since about 2021.
āSkimmer fraud is rampant with losses in the United States alone reaching over $1 billion each year,ā US Attorney Phillip W. Williams Jr. said in a press release about the recent indictment. (That billion dollars includes multiple types of credit card skimming, not just EBT targeting.) āIt is a silent insidious theft that occurs by merely swiping a credit card at a point of sale.ā
Gary Warner, the director of intelligence at the cybersecurity firm DarkTower points out that dozens of states continue to use mag-stripe only cards for benefits purposes. āThe risk here is that if the mag stripe is compromised, a clone of the card can be created and access not only the current value, but future value as well,ā he says.
More broadly, Warner tells us, there are still multiple risks related to making payments using the magnetic stripes on any cardsāeven if they also include more secure chips that have been issued over the last decade-plus. āNon-bank ATMs and smaller non-chain merchants may expose your chip-enabled card to mag stripe reading,ā Warner says. āMag-stripe skimmers are often installed in such a way that the chip read is forced to fail.ā