Skip to content
Security & Trust

Mailed fake cards and stripe skimming still cost victims, WIRED reports

A QR-code letter scam in Europe and a US skimming indictment show physical card fraud channels are still in use

W
WebPulse Newsroom
AI-assisted · 3 min read
Share on X LinkedIn
Mailed fake cards and stripe skimming still cost victims, WIRED reports
Key finding

Annual US losses from card skimming: Over $1 billion (Source: US Attorney Phillip W. Williams Jr., quoted by WIRED Kernel Panic newsletter. The figure covers several types of skimming, not only EBT cards.)

Two physical fraud methods are still in use

The WIRED Kernel Panic newsletter, written by Lily Hay Newman and Matt Burgess, describes two card-fraud methods that predate the current wave of AI-assisted scams: counterfeit cards sent through the post, and skimmers that read magnetic stripes. WIRED says both are still costing victims around the world. The story is relevant to organisations that issue cards, process payments or administer benefits.

Over $1 billion
Annual US losses from card skimming
Source: US Attorney Phillip W. Williams Jr., quoted by WIRED Kernel Panic newsletter. The figure covers several types of skimming, not only EBT cards.

How the mailed-card scam works

WIRED reports that Portugal, France and Germany have each seen waves of this scheme. Victims receive a replacement card or a letter saying their current card is about to expire, whether or not that is true. To activate the new card, the letter directs them to register through a QR code or URL. The link leads to a fake banking site that collects their details, potentially giving criminals direct access to real accounts.

Some of the counterfeit cards carry real customer names. Georg Hauer, who advises digital banks, says a printed name gives the recipient a reason to trust the mailing, which is what lets the follow-up trick work. He puts the build-up of the scheme at roughly two years. In his assessment, AI has made it cheaper to personalise a fake card by copying a design from an image. That is one expert's view, not a measured trend. He also says the aim of some of these scams is to empty savings accounts rather than take a smaller sum from a current account.

WIRED separately notes that social-engineering fraud often results in transactions that look legitimate to banks, because victims send the money themselves. It does not say this of the mailed-card scam, where criminals use stolen details to reach accounts. Whether activity that follows a fake-site login is harder to tell from routine customer behaviour is our inference, not a finding in the source.

Skimming: an indictment and a phase-out date

Two Romanian nationals face charges from the US Attorney's Office for the Northern District of Alabama in a case involving alleged card skimming that targeted SNAP food benefits. In most states those benefits are distributed on Electronic Benefit Transfer (EBT) cards that use magnetic stripes only. The FBI says EBT skimming has grown more popular with scammers since about 2021.

About 2021
Year the FBI says EBT card skimming began rising
Source: FBI, as reported by WIRED Kernel Panic newsletter

Gary Warner, director of intelligence at cybersecurity firm DarkTower, says dozens of states still issue stripe-only benefit cards. A compromised stripe lets criminals clone the card and reach both the current balance and future deposits. He also warns that chip cards are not fully insulated: ATMs not run by banks and smaller independent merchants may process a swipe, and tampered readers can be made to reject the chip so the stripe is used instead.

2029 / 2033
Mastercard: stop issuing stripe cards / fully out of circulation
Source: Mastercard, as reported by WIRED Kernel Panic newsletter

What this means for budget-holders

The source describes no single new vulnerability. Its relevance is that the exposure touches several functions at once: fraud monitoring, customer communications, terminal management and benefits administration. Mastercard's stated timeline leaves several years between its 2029 and 2033 dates in which stripe-based risk coexists with chip cards.

Questions to put to your team

1. If we issue cards, do our customer communications explain how we send replacements and state that we do not ask people to register cards through a QR code? Who owns that wording?

2. After a card-replacement campaign, does fraud monitoring pay attention to log-ins or detail changes on affected accounts? We cannot say from the source whether such activity looks routine to a bank, so this is worth testing rather than assuming.

3. If we accept payments or run terminals, how often are they inspected for signs of tampering, and do chip-read failures trigger a review rather than a silent fallback to the stripe?

4. If we administer benefits or stored-value products on stripe-only cards, what is the migration plan and budget, and what interim controls limit losses after a clone?

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Wired.

Share this insight