threat_intelligence941 wordsRead on Arc Codex

Old-School Credit Card Scams Are Far From Dead

Welcome to Kernel Panic! A weekly newsletter by Lily Hay Newman and Matt Burgess from inside the new world of privacy and digital security. To receive this newsletter in your inbox each week, sign up here. When every random text message feels like it’s a scam, and with AI supercharging digital fraud, old-time credit card skimmers and bogus letters that arrive in the mail may seem laughable as potential threats in 2026. But as we all suffer through a seemingly unending barrage of potential scams, these antiquated attacks are still costing victims around the world dearly. The fake-new-credit-card-in-your-mailbox trick is particularly insidious. Portugal, France, and Germany have all had waves of physical credit card scams in recent years where criminals have mailed phony replacement cards or letters to potential victims. Included letters often claim a current card is set to expire soon, whether the victim actually has one that's about to expire or not. In order for the new (fake) card to be activated, the scam letter says, it should be registered using an included QR code or URL. Some sham cards even have real customer names printed on them, says Georg Hauer, an advisor for digital banks. “The card is almost like a token that creates the trust that is needed in order to fall for the actual trick,” he says. If someone scans the QR code, they’re typically redirected to a fake banking website, where they’re asked to enter their details—potentially giving cybercriminals direct access to their real accounts. “This has been escalating for close to two years, and I believe that this type of scam might have proven to be successful enough to be rolled out in other countries,” Hauer says. “The cost of producing a personalized fake card has dropped in recent years thanks to AI just being able to copy a design based on an image, and the higher conversion rate per victim might justify the extra costs.” Mail scams aren’t the only ’90s throwback on the docket. The US Attorney’s Office for the Northern District of Alabama indicted two Romanian nationals last week on charges related to alleged credit card skimming. Authorities say the pair specifically targeted government SNAP food assistance benefits distributed to recipients in most states on antiquated magnetic stripe-only debit cards, or Electronic Benefit Transfer (EBT) cards. Fraud related to chip credit cards does exist as well, but this recent case serves as a reminder that classic skimmers targeting magnetic stripe credit cards are still deployed by scammers because there’s apparently still enough swiping going on to make it worth their while. The FBI says that EBT card skimming has risen in popularity among scammers since about 2021. “Skimmer fraud is rampant with losses in the United States alone reaching over $1 billion each year,” US Attorney Phillip W. Williams Jr. said in a press release about the recent indictment. (That billion dollars includes multiple types of credit card skimming, not just EBT targeting.) “It is a silent insidious theft that occurs by merely swiping a credit card at a point of sale.” Gary Warner, the director of intelligence at the cybersecurity firm DarkTower points out that dozens of states continue to use mag-stripe only cards for benefits purposes. “The risk here is that if the mag stripe is compromised, a clone of the card can be created and access not only the current value, but future value as well,” he says. More broadly, Warner tells us, there are still multiple risks related to making payments using the magnetic stripes on any cards—even if they also include more secure chips that have been issued over the last decade-plus. “Non-bank ATMs and smaller non-chain merchants may expose your chip-enabled card to mag stripe reading,” Warner says. “Mag-stripe skimmers are often installed in such a way that the chip read is forced to fail.” While magnetic stripe cards have gradually been phased out in the US over many years, they’re still around. Mastercard, for example, said last month that it will stop issuing any cards with stripes in 2029, and its remaining batch will be completely out of circulation by 2033. In the meantime, financial fraud has become one of the largest overall crime types in the US and around the world. Many attacks are focused on social engineering, mass phishing message campaigns, and other fraud where money ends up being sent by victims in transactions that often look legitimate to banks and other financial institutions. Hauer says criminals will always try to use methods that let them steal as much money as possible, even if that means sending physical letters in the mail. “The real idea behind some of these scams is to not essentially try to steal €2,000 from someone’s bank account, but rather actually empty a proper savings account, which holds much more money,” he says. If you feel like you’re already dodging scams left and right, there are some (relatively) easy takeaways to protect yourself from these old time scams. Avoid swiping cards whenever possible. And when you do need to swipe—as is, of course, the case with many EBT cards—do your best to check whether the terminal you’re about to use looks unusual, altered, or broken in any way. If so, use a different terminal. And apply the same skepticism that you have about texts and calls to letters as well. It feels like the only organizations that send mail these days are marketers, healthcare providers, banks, and the IRS, but scammers are still lurking there, too. Spotted something we should include next week? Let us know at [email protected]. And stay safe out there. Comments Back to top

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached — you'll always get the same 5 for this article.