Annual US losses from card skimming: Over $1 billion (Source: US Attorney Phillip W. Williams Jr., quoted by WIRED Kernel Panic newsletter. The figure covers several types of skimming, not only EBT cards.)
Two physical fraud methods are still in use
The WIRED Kernel Panic newsletter, written by Lily Hay Newman and Matt Burgess, describes two card-fraud methods that predate the current wave of AI-assisted scams: counterfeit cards sent through the post, and skimmers that read magnetic stripes. WIRED says both are still costing victims around the world. The story is relevant to organisations that issue cards, process payments or administer benefits.
How the mailed-card scam works
WIRED reports that Portugal, France and Germany have each seen waves of this scheme. Victims receive a replacement card or a letter saying their current card is about to expire, whether or not that is true. To activate the new card, the letter directs them to register through a QR code or URL. The link leads to a fake banking site that collects their details, potentially giving criminals direct access to real accounts.
Some of the counterfeit cards carry real customer names. Georg Hauer, who advises digital banks, says a printed name gives the recipient a reason to trust the mailing, which is what lets the follow-up trick work. He puts the build-up of the scheme at roughly two years. In his assessment, AI has made it cheaper to personalise a fake card by copying a design from an image. That is one expert's view, not a measured trend. He also says the aim of some of these scams is to empty savings accounts rather than take a smaller sum from a current account.
WIRED separately notes that social-engineering fraud often results in transactions that look legitimate to banks, because victims send the money themselves. It does not say this of the mailed-card scam, where criminals use stolen details to reach accounts. Whether activity that follows a fake-site login is harder to tell from routine customer behaviour is our inference, not a finding in the source.
Skimming: an indictment and a phase-out date
Two Romanian nationals face charges from the US Attorney's Office for the Northern District of Alabama in a case involving alleged card skimming that targeted SNAP food benefits. In most states those benefits are distributed on Electronic Benefit Transfer (EBT) cards that use magnetic stripes only. The FBI says EBT skimming has grown more popular with scammers since about 2021.
Gary Warner, director of intelligence at cybersecurity firm DarkTower, says dozens of states still issue stripe-only benefit cards. A compromised stripe lets criminals clone the card and reach both the current balance and future deposits. He also warns that chip cards are not fully insulated: ATMs not run by banks and smaller independent merchants may process a swipe, and tampered readers can be made to reject the chip so the stripe is used instead.
What this means for budget-holders
The source describes no single new vulnerability. Its relevance is that the exposure touches several functions at once: fraud monitoring, customer communications, terminal management and benefits administration. Mastercard's stated timeline leaves several years between its 2029 and 2033 dates in which stripe-based risk coexists with chip cards.
Questions to put to your team
1. If we issue cards, do our customer communications explain how we send replacements and state that we do not ask people to register cards through a QR code? Who owns that wording?
2. After a card-replacement campaign, does fraud monitoring pay attention to log-ins or detail changes on affected accounts? We cannot say from the source whether such activity looks routine to a bank, so this is worth testing rather than assuming.
3. If we accept payments or run terminals, how often are they inspected for signs of tampering, and do chip-read failures trigger a review rather than a silent fallback to the stripe?
4. If we administer benefits or stored-value products on stripe-only cards, what is the migration plan and budget, and what interim controls limit losses after a clone?
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Wired.





