How Did Someone Get My Credit Card Number: Breaches, Skimmers, Malware

If your card has never left your pocket but a charge you didn’t make just showed up, someone captured your card number remotely. There are five common ways this happens: a data breach at a company that stored your card, a phishing email or text that sent you to a fake site, a skimming or shimming device attached to a card reader you used, malware running quietly on your computer or phone, and a fake public Wi-Fi network that routed your traffic through an attacker. The FTC logged more than 458,000 credit card fraud reports in 2024 alone, and most victims never figure out exactly which method was used on them.1Federal Trade Commission. Consumer Sentinel Network Data Book 2024

A Company That Stored Your Card Was Breached

Every time you save a card at an online retailer, that number lives on someone else’s server. When attackers break into those systems they can pull millions of card numbers at once and sell them in bulk. You did nothing wrong; the failure was on the company’s end, and you often won’t learn about it until a breach notification letter arrives weeks or months later.

A related technique called formjacking targets the checkout page itself rather than the database behind it. Attackers inject code into a retailer’s payment form, and every card number typed into that page is quietly copied to a server they control while the transaction still goes through normally. High-profile breaches at major airlines and ticketing platforms have exposed millions of customers this way. Because the site looks and behaves exactly as it should, there is no visible sign anything is wrong.

If you get a breach notice, take it seriously even if no fraudulent charges have appeared. Your number may be sitting on a marketplace waiting to be sold.

You Entered It on a Site That Looked Real

Phishing messages look like they come from your bank, a shipping company, or a store you actually use. The message manufactures urgency — a locked account, a failed payment, a suspicious transaction that needs your attention right now — and the link takes you to a page that copies the real site down to the favicon. Any card details you type there go straight to the attacker.

These fakes have gotten precise. Attackers register domain names that differ from the legitimate one by a single character, then clone the visual design of the login page. If a message you weren’t expecting sends you to a login screen, open a new tab and go to the site directly instead of clicking through.

A Card Reader You Used Was Tampered With

Skimmers are small devices placed over a card reader that record the data on your magnetic stripe when you swipe. Gas pumps are frequent targets because outdoor terminals are easier to tamper with unnoticed, but ATMs and store point-of-sale terminals get hit too. The skimmer captures enough information to produce a cloned card.

Shimming is the chip-era version. A paper-thin device slid inside the card slot intercepts data as your EMV chip communicates with the reader. Chips generate unique one-time codes that block perfect cloning, but the intercepted data can still be used for online purchases that don’t require the physical chip.

You can lower your odds by checking the reader before you insert your card. If it wobbles, looks oversized, sticks out farther than the ones on neighboring pumps, or has cracks or misaligned graphics, use a different terminal. Some internal skimmers can’t be seen from the outside, so paying inside the station or using contactless payment adds another layer.

Malware Captured It From Your Own Device

Software running silently on your computer or phone can record card numbers without any visible symptom. Keyloggers capture every keystroke, including the number, expiration date, and security code you type into a checkout page, and upload the data to the attacker on a schedule. Your card may be compromised for months before the first fraudulent charge appears.

Browser autofill for payment details is another common target. Malware built to scrape stored card data from browsers can pull that information even when it’s encrypted on the device, because once the attacker has code running on your system, the keys that protect saved data become reachable. If you sync your browser across devices, one compromised account can expose saved cards on all of them.

This kind of software usually reaches you through infected downloads, malicious email attachments, or booby-trapped ads on otherwise legitimate sites. Keeping your operating system and browser updated closes many of the gaps it exploits. Digital wallets like Apple Pay and Google Pay are safer than browser autofill because they send a one-time transaction code rather than your actual card number; an intercepted code can’t be reused.

You Used a Fake Public Wi-Fi Hotspot

Public Wi-Fi is less dangerous than it used to be. The FTC now describes connecting through public networks as “usually safe” for most browsing because HTTPS encrypts traffic between your device and the site.2Federal Trade Commission. Are Public Wi-Fi Networks Safe? What You Need To Know The remaining risk is fake hotspots. An attacker sets up a network with a name that looks like a coffee shop or airport connection, and any device that joins routes traffic through their equipment.

If they then send you to a site they control, encryption won’t save you: the attacker runs the destination, so your card number arrives encrypted and is fully readable on their end. A VPN encrypts everything between your device and the VPN server, which keeps the local network from being able to read or redirect your traffic.

The First Sign Is Usually a Small Test Charge

Whichever method a thief used to get your number, the next move is almost always the same. They run a tiny purchase — a few dollars, sometimes under a dollar — to confirm the card still works and that the charge slips past fraud detection. If it clears, larger purchases follow fast, before the card is shut down.

An unfamiliar $1.07 charge from a merchant you don’t recognize is not a rounding error. It’s often the first fingerprint of a stolen number, and reporting it right away can head off the bigger charges that would have come next.

What to Do Now

Federal law caps your liability for unauthorized credit card charges at $50, and Visa and Mastercard waive even that amount under their zero-liability policies.3Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card4Visa. Visa Zero Liability Policy5Mastercard. Mastercard Zero Liability Protection Policy Once you call the issuer, any charges after that call are on them. If the compromised card is a debit card instead, the timing rules are stricter and your money leaves the account first, so speed matters more.6Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability

  • Call the number on the back of the card. Report the charges and ask for a new card with a new number.
  • Scroll back through recent statements for small charges you may have skimmed past. Flag anything unfamiliar, regardless of amount.
  • File a report at IdentityTheft.gov. It generates an FTC Identity Theft Report and a recovery plan tailored to what was compromised.7Federal Trade Commission. IdentityTheft.gov
  • Follow up in writing. To lock in your full protections under the Fair Credit Billing Act, send the issuer written notice of the disputed charges within 60 days of the statement date.8Office of the Law Revision Counsel. 15 USC 1666 – Correction of Billing Errors
  • Update anything on autopay. Subscriptions and recurring payments linked to the old number will fail once the replacement card arrives; your bank’s app usually lists which merchants have already requested the new details.

Consider a Freeze or Fraud Alert

If the theft looks like part of a bigger breach that may have exposed other personal information, a security freeze on your credit reports blocks anyone, including you, from opening new accounts until you lift it. All three major credit bureaus must place and remove freezes at no charge, typically within one business day for electronic requests.9Office of the Law Revision Counsel. 15 USC 1681c-1 – Identity Theft Prevention; Fraud Alerts and Active Duty Alerts

A fraud alert is the lighter option. An initial alert lasts one year and requires lenders to take extra steps to verify your identity before approving new credit. Confirmed identity theft victims can request an extended alert lasting seven years. A fraud alert doesn’t block your credit report; it flags it for additional verification.