What Is Card Cloning? How It Works and How to Prevent It in 2026

Card cloning is one of the oldest tricks in payment fraud, and it has proven remarkably hard to kill. In simple terms, it is the copying of the data stored on a payment card so that a criminal can make purchases or withdraw cash as if they were the real cardholder, all without ever stealing the physical card. The victim keeps their card in their wallet, yet the money still disappears.
The scale remains significant. Card skimming and cloning cost an estimated $1 billion a year in the United States alone, skimming accounts for roughly 60 percent of ATM fraud worldwide, and the global market for skimming devices is still growing.
At the same time, the shift to chip cards has pushed fraudsters toward online, card-not-present channels and toward AI-driven card-testing at scale.
This guide explains what card cloning is, how it works, the technologies that stop it, who is liable when it happens, and how banks, fintechs, and merchants can prevent it. It is written for awareness and defense, not as a how-to.
What Is Card Cloning?

Card cloning, sometimes called card skimming, is the unauthorized duplication of the data held on a debit, credit, or gift card. Criminals capture that data from a compromised card reader or a breached system, then encode it onto another card or use it directly online. Because the copy behaves like the original, the fraud can go unnoticed until the cardholder reviews their statement.
A cloned card is typically put to work in one of two ways, and understanding both explains why the threat spans the physical and digital worlds:
Card-present fraud: the copied data is encoded onto a blank or counterfeit card and used at an ATM or in a store.
Card-not-present fraud: the stolen card details are used for online purchases, where no physical card is needed at all.
How Card Cloning Works: The Lifecycle

Card cloning is not a single act but a chain of steps, and each link in that chain is a chance for a bank or merchant to intervene. Seen from the defensive side, the lifecycle looks like this:
Stage | What happens | Where it can be caught |
|---|---|---|
Data capture | Card data is stolen from a tampered reader, a breached website, or a data leak. | Device inspection, web integrity monitoring |
Duplication | The stolen data is copied onto another card or stored for online use. | Not visible to the victim at this stage |
Testing | Small transactions test whether the card still works before larger use. | Velocity and micro-transaction detection |
Cash-out | The clone is used for purchases, ATM withdrawals, or resale on the dark web. | Real-time transaction monitoring |
The testing stage is a gift to defenders. Fraudsters routinely run a series of tiny transactions to confirm a card is live, and that burst of low-value activity is one of the clearest signals a fraud engine can catch before the real losses begin.
Skimming, Shimming, and Digital Skimming

The method used to steal card data depends on the technology it is stored on. The main techniques share a goal but differ in how they capture data and how easy they are to spot:
Technique | How it captures data | Defensive note |
|---|---|---|
Skimming | A device placed on an ATM, pump, or terminal reads the magnetic stripe. | Inspect readers; magstripe is the weakest link |
Shimming | A thin insert reads chip data from inside the reader. | Cannot clone a working chip card, only a magstripe fallback |
Digital skimming | Malicious code on a checkout page harvests details entered online. | Web integrity and script monitoring catch it |
RFID or contactless theft | Wireless reading of a contactless card at close range. | Largely overstated; dynamic data limits real risk |
A crucial nuance is that digital, or e-skimming, has grown as chip cards squeezed out physical skimming. Malicious scripts injected into online checkout pages now feature in a large share of publicly disclosed breaches, which is why protecting the online channel matters as much as inspecting the ATM.
Card Technology and Cloning Resistance

Not all cards are equally easy to clone, and the difference comes down to whether the card sends the same static data every time or a unique code per transaction. The table below compares the main options from most to least vulnerable:
Technology | How it stores or sends data | Cloning resistance |
|---|---|---|
Magnetic stripe | Static, unencrypted data, like a cassette tape | Very low; trivial to copy and being phased out |
EMV chip | Generates unique dynamic data for each transaction | High; a copied chip cannot be reused |
Contactless / NFC | Encrypted, dynamic data sent wirelessly | High; routine RFID cloning is largely a myth |
Tokenized wallet | A device-specific token replaces the real card number | Very high; a stolen token is useless elsewhere |
EMV chip technology now handles the large majority of card transactions, over 96 percent by late 2024, and because each payment carries a one-time code, a shimmed chip cannot produce a working chip clone. The residual risk comes from magstripe fallback in regions still using it, and from the online channel where the chip plays no part.
Card Cloning Statistics and Trends in 2026

The numbers show a threat that is shifting rather than shrinking. As physical cloning gets harder, fraud is migrating online and scaling up with automation. Recent figures worth knowing include:
Card skimming and cloning cost around $1 billion a year in the US, according to the FBI.
Skimming accounts for roughly 60 percent of ATM fraud globally.
The payment card skimming market is projected to grow from about $3.99 billion in 2025 to $4.49 billion in 2026.
More than 4 million stolen card records have been found circulating online.
The UK recorded a 22 percent rise in card-not-present fraud in the first half of 2025 compared with a year earlier.
Digital skimming code has appeared in roughly three of every four publicly disclosed data breaches.
Warning Signs a Card May Be Cloned

Because a cloned card mimics the real one, detection depends on spotting activity that does not fit the genuine cardholder. For banks and merchants, the strongest signals appear in the transaction data, and several together are far more telling than any one alone:
A transaction in a location far from where the card was just used, an impossible-travel pattern.
A cluster of small test transactions followed by a large purchase or cash withdrawal.
Magnetic stripe use on a card that normally transacts by chip or contactless.
A mismatch between the card's home country and the merchant's country.
Many different cards processed from the same device or IP address in quick succession.
Who Is Liable When a Card Is Cloned?
One of the most confusing aspects of card cloning is who ends up paying, and the answer depends on the card technology, the channel, and the jurisdiction. In broad terms, liability breaks down as follows:
Party | Typical liability position |
|---|---|
Cardholder | Strongly protected; US law caps liability for unauthorized card use at $50, and many issuers offer zero liability. In the EU, unauthorized payments are generally refunded. |
Merchant | Under the EMV liability shift, a merchant that has not upgraded to chip-capable terminals can bear the loss for counterfeit card-present fraud, and merchants generally absorb card-not-present fraud. |
Issuer | Often bears counterfeit-fraud losses where the merchant is chip-compliant, and refunds cardholders. |
How Businesses Prevent Card Cloning

For banks, fintechs, and merchants, preventing card cloning means layering controls so that if one fails, another catches the fraud. No single tool is a silver bullet, but the following combination closes most of the gaps that cloning exploits:
Enforce EMV and tokenization. Chip acceptance and network or device tokenization ensure that intercepted data is useless to a fraudster.
Monitor transactions in real time. Continuous transaction monitoring with behavioral profiling flags the impossible travel, card-testing, and velocity patterns that mark a clone in use.
Use device and network intelligence. Device fingerprinting spots a single device attempting many cards, a hallmark of card-testing rings and increasingly of AI-driven bot farms.
Apply strong authentication. Two-factor and 3-D Secure checks on online payments block the card-not-present fraud that cloning feeds.
Verify identity at onboarding. Robust identity verification during digital onboarding cuts off the mule accounts fraudsters use to cash out cloned cards.
The EU Angle: PSD2 and Strong Customer Authentication
For European firms, card cloning sits inside a specific regulatory framework that most global explainers overlook. Under PSD2, most electronic payments in the EU require Strong Customer Authentication, meaning the payer must confirm their identity with at least two independent factors, and dynamic linking ties each authentication to a specific amount and payee.
This is powerful against cloning because a stolen card number alone is not enough to complete a payment. The incoming PSD3 and Payment Services Regulation go further, tightening authentication and shifting more fraud liability onto providers that fail to authenticate properly.
For an EU business, meeting these authentication duties is both a compliance obligation and one of the most effective anti-cloning controls available.
Card Cloning and Money Laundering
Card cloning is rarely the end of the story. The cash and goods obtained with cloned cards have to be moved and disguised, which makes cloning a feeding mechanism for money laundering. Criminal networks use cloned cards for coordinated ATM cash-outs, route proceeds through money-mule accounts, and layer the funds to obscure their origin. That is why the same
real-time monitoring and AML controls that detect a cloned card in use also help disrupt the money laundering that follows it, and why fraud and financial-crime teams increasingly work from a single view of the customer and their transactions.
How Cardholders Can Protect Themselves
Individuals are not powerless against cloning, and a few habits sharply reduce the risk of a card being compromised in the first place. The most effective steps are simple:
Inspect ATMs, fuel pumps, and terminals for loose, bulky, or mismatched parts before using them.
Cover the keypad when entering a PIN to defeat hidden cameras.
Prefer tap-to-pay or a mobile wallet, which use tokens rather than your real card number.
Turn on transaction alerts so you are notified of activity in real time.
Review statements regularly and report anything unfamiliar to your bank immediately.
Stop Card Fraud at the Identity and Transaction Layer with Qoobiss
Qoobiss helps banks, fintechs, and payment platforms cut card fraud where it does the most damage. Fraud prevention and real-time transaction monitoring detect the card-testing and cash-out patterns behind cloned cards, while identity verification stops the mule accounts that launder the proceeds. See how Qoobiss supports fintech and payments teams, or get in touch to see it in action.
Frequently Asked Questions
Can chip cards be cloned?
Are mobile wallets safer than physical cards?
How was my card cloned if I still have it?
What should I do if my card is cloned?
Is card cloning illegal?








