Blacksec

Administrator
Staff member
ROOT
VIP
Hey hackers - a skimmer in 2026 is either a twenty-dollar board jammed inside a card slot or a phone app that relays a tap in real time, and the distance between those two products defines the entire year of fraud stats.
The 2026 skimmer trade runs on four physical form factors and one that needs no physical implant at all, and this piece reads the year straight from the seizure filings: what got built, what got caught, and where the relay tier is taking the whole business.
TL;DR: Deep inserts still own fuel dispensers, overlays still own checkout lanes, shims quietly retired themselves when ATM slots got thinner, and NFC relay - a phone holding a victim's card against it while an emulator works a real ATM - arrived as the first tier with no device to recover from a scene.
Texas filings alone this year cover 150-plus devices, 783 victims from one Dallas crew, a diesel-pump ring moving 2,500 gallons a night, and three people caught mid-install in Hewitt with an estimated $19 million in losses prevented. The money exits the same places it always did - bank drops and ATM runs - while cardless withdrawal paths absorb whatever the chip refuses to give up.

The four form factors, ranked by recovery risk​

An overlay skimmer clips over the existing card reader or keypad and reads the magnetic stripe on swipe while a pinhole camera - or a second overlay on the keypad - works the PIN.
Fuel pumps and point-of-sale terminals are the natural habitat because the panel comes off with two screws or a strip of tape, and because the checkout lane gives an install window measured in seconds when a distraction runs right.
A deep insert skimmer is the opposite bet: a thin board with a read head that slides completely inside the card throat, past the bezel, invisible from outside. It captures the stripe during the normal read and stores until Bluetooth pickup. Secret Service guidance notes these units can sit so deep they are undetectable from the ATM's exterior.
They increasingly carry a second read for the chip contacts. The install still needs the slot; the failure mode is a technician pulling the housing for service.
A shim is the chip-slot layer of the same idea - a paper-thin board inside the reader that sits between the card's contacts and the machine, siphoning the few milliamps the chip draws to power itself and logging the EMV conversation in encrypted flash. It captures what an overlay can never see.
The fourth tier needs no install window because there is no device: an NFC relay runs on two phones. One runs malware that offers Host Card Emulation to the target - "hold your card against your phone to verify" - and relays every ISO 14443 frame over a socket to a second device that replays the conversation against a real terminal. The card never leaves the wallet, the terminal authenticates a genuine chip, and the only thing recovered from a victim's phone is an app that reports itself as a payment utility.
Form factorSits whereCapturesPickup2026 status
Overlay + camerabezel and keypad, ATM or POSstripe plus PINBluetooth or Wi-Fi, minutes awayvolume workhorse, most seized
Deep insertinside the card throatstripe, sometimes chip contactsBluetooth, passive until querieddominant on fuel dispensers
Shiminside the chip readerEMV transaction data, encryptedphysical retrieval plus a download cardcontained by thinner slots
NFC relaytwo phones, no implantlive contactless chip conversationreal time over a socketgrowing, nothing to recover

What the seizure filings say​

The Dallas County District Attorney's June 2026 sentencing closes the largest retail case of the year. Between July 2025 and the arrests, Gheorge-Ciprian Hilitanu, Victor Tecu and Ionut Firan-Alexandrau fitted hidden devices across CVS and Walgreens locations in the Dallas-Fort Worth area; the search of their Airbnb returned more than 150 skimming devices, 237 re-encoded gift cards carrying stolen accounts, 25 fraudulent international identity documents, and card-making equipment. Forensics tied 783 unique victims to the haul.
Hilitanu drew 30 years on organized criminal activity plus concurrent terms for tampering with government records; Tecu and Firan-Alexandrau each drew 20.
Same quarter, different target: the Texas Financial Crimes Intelligence Center dismantled a crew running high-flow diesel pumps across North Texas, siphoning 1,500 to 2,500 gallons a night, five and six nights a week, into hidden compartments in their own vehicles.
Simultaneous warrants in Irving and Arlington on June 12, 2026 recovered 10 deep insert skimmers, 50 altered payment cards and a laptop wired to a re-encoder; investigators put the prevented loss near $10 million. Five were charged - four Cuban nationals and one Mexican national arrested arriving at Dallas on a flight three days later.
Colorado's Operation Quick Cash ran August 2025 to May 2026 across the Denver metro, eleven adults and one juvenile indicted under the organized crime statute for skimmers on ATMs and register terminals, with 7-Eleven preferred and EBT balances targeted: 447 Colorado EBT cards drained, 236 cloned cards recovered, $301,400 taken or attempted.
And in Hewitt on April 16, 2026, state agents caught three suspects mid-install of deep insert skimmers inside gas pumps - the seizure from an Austin residence included building materials for more units and a stack of clones, against an estimated $19 million prevented.

The shim decade, and how it closed​

Shimming started in 2015 as a genuine cryptographic problem. The thin board slotted into the chip reader had no battery: it siphoned a few milliamps off the current the ATM sends to the card, recorded the EMV exchange, and slept in encrypted flash until someone retrieved it. Banks in Mexico and Latin America found them first, and for years the seized units were, in a former Secret Service agent's phrase, encrypted gibberish - MasterCard's UK lab confirmed what it did but not what it said.
The break came from operator sloppiness, not cryptanalysis. A Romanian crew mass-producing the shims had hardcoded the same stolen Austrian card number into every unit as a handshake key. That number traveled the card networks each time a fresh ATM was compromised, which turned a tracker into a global sweep, and the 2017 New York unit matched the Mexican ones byte for byte.
Search warrants on the crew's lab found the shimmer blanks in untrimmed sheet metal and the retrieval tool - a two-piece download card with chip contacts on a ribbon, the hardcoded PAN opening an encrypted session, a green LED when the dump finished.
The same syndicate later ran an ATM company, Intacash, whose Riviera Maya fleet exceeded a hundred machines and whose cloned data and PINs pulled north of $1.2 billion from tourist accounts before Florian "The Shark" Tudor was arrested.
Hardware ended the era more than law enforcement did. Slimmer card slots on newer ATMs will not physically fit a shimmer plus a download card, and the slot-height change shipped faster than any signature rule.

The relay tier, running live​

The April 2026 sample that landed on MalwareBazaar under an Unicaja Banco impersonation is the year's cleanest relay reference: an NGate-family banking trojan where the whole theft is a conversation between two phones. The victim is talked into holding a contactless card against their own handset, the malware answers through Host Card Emulation, and every ISO 14443 frame is wrapped in protobuf and pushed over a raw TCP socket to a relay server - measured in milliseconds, fast enough to proxy a live ATM transaction.
From the terminal's side the chip is genuine, the cryptograms check out, and the skimmer that used to sit in the slot has been replaced by software with nothing to pull from a scene.
The operator's own mistakes are what make this case readable. The configuration decrypts under a hardcoded AES-128 key stamped in the binary; the relay endpoint sat at 163.73.76.22 on a fixed port while the control server ran from a Spanish host with MySQL and RDP exposed straight to the internet; harvested PINs posted to an unauthenticated endpoint that accepted writes under a header token and held 151 of them by the time anyone looked.
Exfiltration rode the official Telegram API, a config cache keeps the relay pointed at a known IP for a day after the domain dies, and the sample carries an Xposed hook class name that doubles as a signature.
None of that slowed adoption - the Devil NFC branding shows up across the artifacts because branding is marketing here.

Pickup, write, convert​

Everything physical still ends in the same three moves. Pickup: a Bluetooth or Wi-Fi walk-by within a hundred feet, or a return visit if the unit stores locally - which is why install-to-pickup windows shrank to hours in dense cities. Write: a magnetic stripe encoder moves the captured track onto blank plastic - the chip still refuses to be cloned from shim data, so most crews run stripe logic and eat the fallback codes. Convert: cash at an ATM
Immediate resale through gift card platforms when the capture was retail, or remote spend through card-not-present checkout where the stripe never has to exist as plastic at all.
Conversion routeNeeds from the captureMain friction in 2026
ATM cash runtrack plus PIN from the camera layerdaily limits, counterfeit detection, camera-rich plazas
Retail plastic, gift cardstrack to write, PIN optionalre-encode forensics - Dallas crews fell on exactly this
Card-not-present checkouttrack or full record plus billing datarisk scoring, velocity checks, AVS mismatches
Onward resale of the datanothing - the list itself is the productbuyer trust, combo-list rot, rapid invalidation

What actually gets crews caught​

Devices rarely convict anyone on their own. The affidavits this year read like a list of everything around the device: a short-term rental where the build materials are still on the table, the re-encoder laptop sitting next to the finished cards, a phone full of pickup traffic, fuel logs matching a van's pattern at four truck stops in one week, employees at a returning store who recognize the man from last month. In the relay tier the scene is even thinner.
The takedown path runs through infrastructure instead - an exposed database port, a registrar abuse form, a hardcoded key that lets anyone decrypt the config and read the endpoint list. The ticket that opened the Dallas case and the sample that opened the Devil NFC analysis were both receipts from poor habits rather than clever forensics.
BEZEL: pull gently - overlays move, factory bezels do not, and fresh adhesive shine on a weathered machine is the tell. KEYPAD: resistance, deeper travel or a slightly raised membrane means a pinhole is riding above it. THROAT: shine a light - a deep insert skimmer sits flush behind the entry point and its edge catches light the plastic around it does not. BLUETOOTH: a scanner app listing an unknown serial device in the immediate air means someone is in range for pickup.
TAP: the relay tier inverted the old advice. Contactless still beats a swipe on a dirty slot, but a physical card held to an untrusted phone prompt is now the attack - use the tokenized card inside your wallet app on your own device, and never authenticate a "verification" by touching plastic to glass. Anything that asks for the card itself is the request that ends the check.

The stance that holds​

Four tiers, one direction of travel. Overlay and insert operations keep getting seized in rental houses because the device has to come back for pickup, the shim tier closed when the hardware changed shape, and the relay tier - no implant, no pickup, a conversation instead of a board - is where the trade's engineering money went this year. The skimmer market did not shrink; it split, and the half with nothing to recover from a crime scene is the half that grows.
The conversion leg stays the weak point in every version of this. Stripe data burns fast, PIN capture is still mostly a camera problem, and every exit route adds a counterparty who can be interviewed. Read the seizure filings before the marketing: the crews who lasted past a season were the ones who treated pickup windows, re-encoder hygiene and exit logistics as the business - and treated the device itself as the cheapest, most disposable part of it. Test the bezel, cover the keypad, and move on.