Scammers get your debit card number through five main channels: skimming or shimming devices attached to payment terminals, phishing emails and smishing texts, data breaches at retailers and banks, malware and keyloggers on your computer or phone, and social-engineering calls from someone pretending to be your bank. In 2024, consumers filed more than 76,000 debit card fraud reports with the FTC, and reported losses reached roughly $180 million.1Federal Trade Commission. Consumer Sentinel Network Data Book 2024 Because a debit card pulls straight from your checking account, stolen money is gone from your balance immediately, and the federal protections covering debit transactions are narrower than the ones covering credit cards.
Skimmers and Shimmers at Payment Terminals
A skimmer is a small device attached over the card slot on an ATM, gas pump, or store terminal. When you swipe, it reads the data on the magnetic stripe and stores it for the thief. A shimmer is the newer version: a paper-thin circuit board slipped inside a chip reader that intercepts data from the EMV chip when you dip your card. Either one gives a scammer enough to clone a card or run online purchases.
These devices are often paired with a pinhole camera or a fake keypad overlay that records your PIN. With both the card data and the PIN, someone can pull cash from your account at any ATM.
Before you insert a card, wiggle the slot. A real reader is bolted in; a skimmer overlay tends to feel loose or crooked. At gas pumps, look for the security seal near the reader. If the label reads “void,” the panel has been opened and may contain a skimmer.2Federal Trade Commission. Best Practices to Foil Gas Station Skimmers When you can, pay inside or use contactless payment so the card never enters a slot.
Phishing Emails and Smishing Texts
Phishing emails impersonate banks, delivery services, and retailers. A typical message warns about suspicious account activity or an undelivered package and pushes you to click a link. The link opens a page built to look like your bank’s login screen, and every field you fill in — card number, expiration date, security code — goes to the scammer.
Smishing runs the same play through text messages. The links are usually shortened, which makes them hard to inspect on a phone, and mobile-sized fake pages can be almost indistinguishable from the real site on a small screen.
The rule that catches almost all of these: your bank will not send you an email or text asking you to click a link and enter your full card number, PIN, or a one-time code. If a message claims there’s a problem, don’t use its link. Call the number on the back of your card.
Data Breaches at Retailers and Banks
When hackers break into a company’s database, they can walk away with thousands or millions of card numbers at once. You have no control over this because it happens inside systems you don’t touch. The stolen data usually ends up on dark web marketplaces, where card numbers with expiration dates and security codes are sold in bulk to other criminals.
All 50 states, the District of Columbia, Puerto Rico, and the U.S. Virgin Islands have laws requiring companies to notify you when a breach exposes your personal information.3Federal Trade Commission. Data Breach Response – A Guide for Business
If you get a breach notice, take any free credit monitoring or identity theft insurance the company offers.4Federal Trade Commission. What to Do After a Data Breach Then consider a fraud alert or a credit freeze on your credit reports, which makes it harder for anyone to open new accounts in your name.
Malware and Keyloggers on Your Devices
Software installed on your computer or phone can record everything you type, card numbers and PINs included. Keyloggers run silently in the background and send captured keystrokes to a server the attacker controls. A related technique, form grabbing, pulls data out of browser fields before the browser encrypts it, which lets the scammer read information that would otherwise travel through a secure connection.
Most infections come from email attachments, fake software updates, and compromised websites. Once installed, the program hides itself and keeps harvesting during every session. Keep your operating system and antivirus software current, skip downloads from unfamiliar sources, and treat email attachments with suspicion.
Phone Calls Pretending to Be Your Bank
Voice phishing, sometimes called vishing, uses a live caller posing as a fraud investigator or bank representative. The caller says your account has been compromised and pressures you to “verify” your identity by reading your card number and PIN aloud. The urgency is manufactured to override your instincts, and a caller who already has a few real details about you — often pulled from a prior data breach — sounds more convincing.
A real bank representative will never ask for your full card number, your PIN, or a one-time security code over the phone. If a caller asks for any of that, hang up. Then call the number on the back of your card and ask whether anything is actually wrong.
What You Owe if a Scammer Uses Your Card
The Electronic Fund Transfer Act and Regulation E set the ceiling on your liability for unauthorized debit card charges. How much you can lose depends on whether your physical card was taken and how fast you report the problem.
If the card itself is lost or stolen and you report it within two business days of discovering the loss, your liability is capped at $50. Report after two business days but within 60 days of receiving the statement showing the fraud, and the cap rises to $500. Miss the 60-day window and there is no federal cap on fraudulent charges that appear after it closes.5Office of the Law Revision Counsel. 15 USC 1693g – Consumer Liability
The distinction that matters most for the methods above: when your physical card stays in your wallet but the number is stolen through phishing, a breach, malware, or a phone scam, you owe nothing as long as you report the unauthorized charges within 60 days of the statement that shows them.6Consumer Financial Protection Bureau. Regulation E 1005.6 – Liability of Consumer for Unauthorized Transfers After that window, liability can attach to any new fraud that happens until you tell the bank.
Credit cards cap unauthorized-charge liability at $50 no matter when you report.7Federal Trade Commission. Lost or Stolen Credit, ATM, and Debit Cards That gap is why real-time transaction alerts and frequent statement checks matter more for debit than for credit.
What to Do the Moment You Spot a Charge You Didn’t Make
Call your bank right away. Your federal protection clock starts when you learn about the charge, so every day matters. Ask the bank to freeze or cancel the card and send a replacement. Follow the call with a written notice. Some banks require written confirmation within 10 business days of an oral report, and skipping it can affect your rights during the investigation.8Office of the Law Revision Counsel. 15 USC 1693f – Error Resolution
Under Regulation E, your bank must investigate and report back within 10 business days. It can take up to 45 days, but only if it provisionally credits your account for the disputed amount within the first 10 business days, so you have access to the money while the review continues.8Office of the Law Revision Counsel. 15 USC 1693f – Error Resolution
File a report at IdentityTheft.gov. The site produces an official identity theft report and a step-by-step recovery plan.9Federal Trade Commission. Report Identity Theft and Get a Recovery Plan If your number was stolen rather than the card itself, pull your credit reports and look for accounts you didn’t open. A scammer with your card data may have more than the card.
Then consider a fraud alert or credit freeze. A fraud alert tells lenders to verify your identity before opening new accounts; a freeze blocks access to your credit report until you lift it.4Federal Trade Commission. What to Do After a Data Breach Both are free at each of the three major credit bureaus. Keep a written log of every call and every form. If a dispute over liability comes up later, documentation of prompt reporting is what protects you.