Kiss from a Rogue: Evaluating Detectability of Pay-at-the-Pump Card Skimmers
Nolen Scaife, Jasmine D. Bowers, Christian Peeters, Grant Hernandez, Imani N. Sherman, Patrick Traynor, Lisa Anthony
Abstract
Credit and debit cards enable financial transactions at unattended "pay-at-the-pump" gas station terminals across North America. Attackers discreetly open these pumps and install skimmers, which copy sensitive card data. While EMV ("chip-and-PIN") has made substantial inroads in traditional retailers, such systems have virtually no deployment at payat-the-pump terminals due to dramatically higher costs and logistical/regulatory constraints, leaving consumers vulnerable in these contexts. In an effort to improve security, station owners have deployed security indicators such as low-cost tamper-evident seals, and technologists have developed skimmer detection apps for mobile phones. Not only do these solutions put the onus on consumers to notice and react to security concerns at the pump, but the efficacy of these solutions has not been measured. In this paper, we evaluate the indicators available to consumers to detect skimmers. We perform a comprehensive teardown of all known skimmer detection apps for iOS and Android devices, and then conduct a forensic analysis of real-world gas pump skimmer hardware recovered by multiple law enforcement agencies. Finally, we analyze anti-skimmer mechanisms deployed by pump owners/operators, and augment this investigation with an analysis of skimmer reports and accompanying security measures collected by the Florida Department of Agriculture and Consumer Services over four years, making this the most comprehensive long-term study of such devices. Our results show that common gas pump security indicators are not only ineffective at empowering consumers to detect tampering, but may be providing a false sense of security. Accordingly, stronger, reliable, inexpensive measures must be developed to protect consumers and merchants from fraud.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 955a10a5-35fc-409e-b7c7-a4f697306cbbCited by top-tier papers5
- Please Pay Inside: Evaluating Bluetooth-based Detection of Gas Pump SkimmersNishant Bhaskar, Maxwell Bland, Kirill Levchenko, Aaron SchulmanUSENIX Security 2019 · 12 citations
- Doing good by fighting fraud: Ethical anti-fraud systems for mobile paymentsZain ul Abi Din, Hari Venugopalan, Henry Lin, Adam Wushensky et al.S&P 2021 · 8 citations
- Swiped: Analyzing Ground-truth Data of a Marketplace for Stolen Debit and Credit CardsMaxwell Aliapoulios, Cameron Ballard, Rasika Bhalerao, Tobias Lauinger et al.USENIX Security 2021 · 7 citations
- In Wallet We Trust: Bypassing the Digital Wallets Payment Security for Free ShoppingRaja Hasnain Anwar, Syed Rafiul Hussain, Muhammad Taqi RazaUSENIX Security 2024
- Boxer: Preventing fraud by scanning credit cardsZain ul Abi Din, Hari Venugopalan, Jaime Park, Andy Li et al.USENIX Security 2020
Builds on2
- Fear the Reaper: Characterization and Fast Detection of Card SkimmersNolen Scaife, Christian Peeters, Patrick TraynorUSENIX Security 2018 · 34 citations
- The Cards Aren't Alright: Detecting Counterfeit Gift Cards Using Encoding JitterNolen Scaife, Christian Peeters, Camilo Velez, Hanqing Zhao et al.S&P 2018 · 11 citations
Related papers
- MagTracer: Detecting GPU Cryptojacking Attacks via Magnetic Leakage SignalsRui Xiao, Tianyu Li, Soundarya Ramesh, Jun Han et al.MobiCom 2023 · 20 citations
- Inducing Authentication Failures to Bypass Credit Card PINsDavid A. Basin, Patrick Schaller, Jorge Toro-PozoUSENIX Security 2023
- Zombie Cards Back Online: Reviving Expired Credit Cards for Contactless PaymentsRaja Hasnain Anwar, Gerard DeCunha, Muhammad Taqi RazaUSENIX Security 2026
- Broken Fingers: On the Usage of the Fingerprint API in AndroidAntonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel et al.NDSS 2018 · 33 citations
- The EMV Standard: Break, Fix, VerifyDavid A. Basin, Ralf Sasse, Jorge Toro-PozoS&P 2021 · 69 citations
