Old-School Credit Card Scams Are Far From Dead

Staff
By Staff 16 Min Read

Welcome to Kernel Panic, a weekly newsletter by Lily Hay Newman and Matt Burgess. We spend our days inside the strange, sprawling world of privacy and digital security, and every week we try to make sense of what matters. In 2026, that world often feels like a never-ending scam simulator. Random texts promise free gifts, urgent voicemails warn about suspicious charges, and AI has made fraudulent messages scarier and more persuasive than ever. It’s tempting to laugh at the old-school threats: the sticky card skimmer wedged into an ATM, the suspicious letter with a fake check, the stranger asking for your PIN. But those outdated tricks haven’t gone away. They’re still quietly hurting people, sometimes more efficiently than before because they exploit our belief that physical objects and paper mail must be trustworthy. This week, we’re looking at two old-fashioned frauds that are having a strange renaissance, and why the “good old days” of scams never really ended. There’s the fake replacement credit card that arrives in your mailbox, complete with your name printed on it, and the decades-old magnetic stripe skimmer still draining government benefit cards. Both remind us that even as the digital world invents new threats, the analog world can be just as dangerous—especially when criminals combine old tricks with new technology. You might think you’d never fall for a letter when you’re already bracing yourself for phishing emails, but the criminals who send these letters are counting on that confidence. They know trust is a fragile thing, and they’ve learned how to weaponize it. It’s a theme we keep coming back to in our reporting: the more we focus on the next generation of threats, the more the last generation quietly flourishes. That’s why these stories matter. They aren’t just curiosities. They are blueprints for how criminals think.

The fake card scam is particularly nasty because it arrives in a place people still tend to trust: the mailbox. Portugal, France, and Germany have all seen waves of this scheme in recent years. Criminals send out fake replacement cards or official-looking letters to potential victims. The letters typically warn that your current credit card is about to expire, whether or not you actually have one with that expiration date. They tell you to activate the enclosed replacement card by scanning a QR code or visiting a URL. Some of these fake cards are so convincing that they have the recipient’s real name printed on them. Georg Hauer, an advisor for digital banks, says the card itself is essentially a prop, a “token” that creates enough trust to make the rest of the scam work. You hold it in your hand and think, “Well, this must be real.” Once you scan the QR code, you’re taken to a website that looks just like your bank’s login page. Enter your credentials and you haven’t just activated a card—you’ve handed a criminal the keys to your actual account. It’s a phishing attack, but with a physical object doing the persuading. That makes it feel more authentic, more personal, and for many people, harder to resist. The scammers are not relying on a generic email that lands in spam. They are spending money to print cards, mail envelopes, and design fake pages. And that investment is paying off. Hauer says the scheme has been escalating for close to two years, and he believes it may already be successful enough to expand to other countries. In other words, the moment you’re reading this, the templates and techniques are probably being adapted for new markets. That’s a chilling thought for anyone who still assumes that paper mail is somehow safe from the digital age. The people who fall for this aren’t gullible; they’re normal. They’re someone sorting through bills on a Tuesday evening, worried about their bank card, grateful that a replacement has arrived. That moment of relief is exactly what the scammer is targeting.

Why now? AI has changed the economics of these physical scams. Creating a fake personalized credit card used to require graphic design skills, specialized printers, and a fair amount of trial and error. Today, artificial intelligence can copy a bank’s card design from a single image, and printing on plastic has become cheaper and more accessible. Hauer notes that the cost of producing a personalized fake card has dropped dramatically in recent years. At the same time, the conversion rate per victim is higher, because a fake card with your actual name on it feels compelling. That combination makes the extra cost worthwhile for criminals. So the old trick has been reinvented as a boutique, targeted fraud. And it isn’t only about credit cards. The same principle—make something physical look official, then let the victim do the work—applies to other mail frauds, from fake toll invoices to bogus package delivery notices. But the credit card version is uniquely scary because it asks for nothing up front except a scan and a login. The scam doesn’t need to steal your card number; it needs you to willingly give it up. There’s no skimming device, no hidden camera at an ATM. The victim is the delivery mechanism. That’s part of why these attacks are so insidious. They also reveal how our mental models of security have not caught up with the reality of fraud. We’ve trained ourselves to be suspicious of email links and text message sender IDs, but a physical letter with a plastic card still feels solid, official, real. The scammers are exploiting that psychological gap, and they’re doing it with tools that get cheaper and more powerful every month. The lesson, as unpleasant as it sounds, is that no channel is too old-fashioned to be weaponized. If scammers can print it, they can fake it. If they can fake it, they can monetize it. When a scam becomes cheap to run at scale, it becomes a business. And like any business, it grows where the customers are. Our attention is the product; our trust is the inventory.

The same theme emerges in a much older form of fraud: credit card skimming. Last week, the US Attorney’s Office for the Northern District of Alabama indicted two Romanian nationals on charges related to skimming. The pair allegedly targeted SNAP food assistance benefits, distributed in most states on Electronic Benefit Transfer, or EBT, cards. These cards are often little more than magnetic stripe-only debit cards, with no chip technology, no contactless payment, and no PIN pad security beyond the basic magnetic stripe data. That makes them easy prey for skimmers. The FBI says EBT card skimming has risen in popularity among scammers since about 2021. Skimmers are tiny devices attached to card readers at checkout terminals, ATMs, or other payment kiosks. When a person swipes a card, the skimmer records the magnetic stripe data. Criminals can then copy that data onto a blank card and use it to drain the victim’s account. For EBT cards, the stolen benefits often go to food, then the card is thrown away. But the damage is immediate and brutal. For a family relying on SNAP to buy groceries, having those benefits stolen can mean going hungry before the next allotment arrives. US Attorney Phillip W. Williams Jr. described skimmer fraud as “rampant,” with losses in the United States alone reaching more than $1 billion each year. That billion includes multiple types of credit card skimming, not just EBT, but the human cost is staggering. Williams called it “silent insidious theft” that happens every time someone swipes a card at a point of sale. No warning, no suspicious email, no chance to think. You run your card, and a criminal now owns a copy of it. The victims may not realize anything happened until they try to buy groceries and the card is declined. By then, their monthly benefits could be gone, lost in a transaction that lasted a fraction of a second. It’s a violation that’s easy for criminals to commit and hard for victims to fight.

The EBT skimming case is a reminder that many of the most vulnerable people are still using some of the oldest and least secure payment technology. Gary Warner, director of intelligence at DarkTower, points out that dozens of states continue to distribute benefits on magnetic stripe-only cards. If a mag stripe is compromised, a clone of the card can be created, and that clone can access not only the current value on the card but also future benefits loaded onto it later. So a victim may be robbed many times over, not just once. Warner also warns that this isn’t only a risk for EBT cards. Even if you carry a modern chip-enabled credit card, you might still be exposed to magnetic stripe skimmers. Some non-bank ATMs and smaller independent merchants still rely on the older magnetic stripe technology, either because their hardware hasn’t been upgraded or because the terminal is set up in a way that forces the chip read to fail. The chip on your card is supposed to be a more secure way to pay, but if the terminal doesn’t support it, or if a skimmer is designed to intervene, the fallback is the magnetic stripe. In those moments, your card’s secret data is exposed exactly as it was decades ago. The result is that even people who think they have modern protection can still be victims. Skimmers are often installed in a way that looks almost identical to the normal card reader, and they can be placed inside gas stations, bodegas, or unattended parking meters. The only defense is vigilance: check for loose parts, tug on the reader, use contactless payment when possible, and never let a stranger make you rush through a payment. This is especially hard for people who have no other way to pay, or who live far from a bank branch. The scam doesn’t care whether you have easy access to technology or a support system; it just takes whatever data it can get. That’s why the burden should not fall entirely on consumers.

What are we supposed to do with all this? First, remember that old scams never die; they just evolve. The fake card in your mailbox and the skimmer on an ATM are both symptoms of the same problem: criminals will always search for the path of least resistance, and that path often runs right through our own expectations. We expect email to be dangerous, so they use mail. We expect online login pages to be risky, so they print plastic. We expect chip readers to be secure, so they attack the magnetic stripe. The most human response is to become numb, to shrug off every new warning as another reason to feel overwhelmed. But the better response is to build small habits of skepticism. Read the source of a URL before you type your password. Call your bank using the number on the back of your real card if you receive a replacement you didn’t ask for. Never scan a QR code from a letter that shows up unsolicited. Choose contactless or chip payment over swiping whenever you can, and tell your elected officials that giving vulnerable people insecure magnetic stripe cards is an injustice that needs fixing. We also need to hold the institutions accountable: banks, card networks, and government agencies must do more to protect people, instead of pushing the burden entirely onto individuals. That’s where we come in. At Kernel Panic, our mission is to help you navigate this messy landscape without losing your mind. We’ll keep tracking the new scams and the old ones that refuse to fade away. We’ll keep reporting on what works, what doesn’t, and what the industry should be doing better. And we’ll keep providing you, our readers, with the context you need to live a safer digital life. If this newsletter was forwarded to you, the best way to protect yourself is to stay informed—so sign up to get it directly in your inbox each week. The war on our attention and our money is never going to end, but that doesn’t mean we have to lose it silently. We can start by refusing to let nostalgia become a security hole. The past is not always safer. Sometimes it’s just an older way to be fooled. So be kind to yourself when you feel overwhelmed, and be kind to others who might not have the same awareness. Share what you learn. Warn your parents, your friends, your neighbors. A simple conversation can be the difference between a suspicious email being ignored and a fake card being scanned. We’ll be here every week to help.

Share This Article
Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *