Old-School Credit Card Scams Are Far From Dead
Old-School Credit Card Scams Are Far From Dead
老派信用卡诈骗远未消亡
Welcome to Kernel Panic! A weekly newsletter by Lily Hay Newman and Matt Burgess from inside the new world of privacy and digital security. To receive this newsletter in your inbox each week, sign up here.
欢迎来到《内核恐慌》(Kernel Panic)!这是一份由 Lily Hay Newman 和 Matt Burgess 共同撰写的每周通讯,带您深入了解隐私与数字安全的新世界。若想每周在收件箱中接收此通讯,请点击此处订阅。
When every random text message feels like it’s a scam, and with AI supercharging digital fraud, old-time credit card skimmers and bogus letters that arrive in the mail may seem laughable as potential threats in 2026. But as we all suffer through a seemingly unending barrage of potential scams, these antiquated attacks are still costing victims around the world dearly.
当每一条随机短信都像是诈骗信息,且人工智能(AI)又在助推数字欺诈时,老式的信用卡侧录器和寄到家里的伪造信件在 2026 年看来似乎已不足为惧。然而,尽管我们都在承受着看似无穷无尽的潜在诈骗轰炸,这些过时的攻击手段仍在让全球各地的受害者付出惨痛代价。
The fake-new-credit-card-in-your-mailbox trick is particularly insidious. Portugal, France, and Germany have all had waves of physical credit card scams in recent years where criminals have mailed phony replacement cards or letters to potential victims. Included letters often claim a current card is set to expire soon, whether the victim actually has one that’s about to expire or not. In order for the new (fake) card to be activated, the scam letter says, it should be registered using an included QR code or URL. Some sham cards even have real customer names printed on them, says Georg Hauer, an advisor for digital banks. “The card is almost like a token that creates the trust that is needed in order to fall for the actual trick,” he says.
“信箱里的伪造新信用卡”骗局尤为阴险。近年来,葡萄牙、法国和德国都出现了多波实体信用卡诈骗,犯罪分子向潜在受害者邮寄伪造的补发卡或信件。信中通常声称受害者当前的信用卡即将过期,无论受害者是否真的持有即将过期的卡片。诈骗信件称,为了激活这张新的(伪造)卡,必须使用随附的二维码或网址进行注册。数字银行顾问 Georg Hauer 表示,一些伪造卡片上甚至印有真实的客户姓名。“这张卡就像是一个信物,它建立了受害者上当受骗所需的信任感,”他说。
If someone scans the QR code, they’re typically redirected to a fake banking website, where they’re asked to enter their details—potentially giving cybercriminals direct access to their real accounts. “This has been escalating for close to two years, and I believe that this type of scam might have proven to be successful enough to be rolled out in other countries,” Hauer says. “The cost of producing a personalized fake card has dropped in recent years thanks to AI just being able to copy a design based on an image, and the higher conversion rate per victim might justify the extra costs.”
如果有人扫描了二维码,通常会被重定向到一个虚假的银行网站,并被要求输入个人信息——这可能让网络犯罪分子直接访问他们的真实账户。“这种情况已经持续升级了近两年,我相信这种诈骗手段可能已被证明足够成功,从而被推广到其他国家,”Hauer 说。“近年来,由于 AI 能够根据图像复制设计,制作个性化伪造卡的成本已经下降,而每个受害者带来的更高转化率足以抵消这些额外成本。”
Mail scams aren’t the only ’90s throwback on the docket. The US Attorney’s Office for the Northern District of Alabama indicted two Romanian nationals last week on charges related to alleged credit card skimming. Authorities say the pair specifically targeted government SNAP food assistance benefits distributed to recipients in most states on antiquated magnetic stripe-only debit cards, or Electronic Benefit Transfer (EBT) cards.
邮寄诈骗并不是目前唯一卷土重来的 90 年代骗术。美国阿拉巴马州北区联邦检察官办公室上周起诉了两名罗马尼亚籍人士,指控他们涉嫌信用卡侧录。当局称,这两人专门针对政府的 SNAP 食品援助福利,这些福利在大多数州是通过老式的仅含磁条的借记卡,即电子福利转账(EBT)卡发放给受助者的。
Fraud related to chip credit cards does exist as well, but this recent case serves as a reminder that classic skimmers targeting magnetic stripe credit cards are still deployed by scammers because there’s apparently still enough swiping going on to make it worth their while. The FBI says that EBT card skimming has risen in popularity among scammers since about 2021.
虽然涉及芯片信用卡的欺诈确实存在,但最近的这起案件提醒我们,针对磁条信用卡的经典侧录器仍被诈骗者广泛使用,因为显然仍有足够的刷卡行为让他们的犯罪活动“有利可图”。FBI 表示,自 2021 年左右以来,EBT 卡侧录在诈骗者中变得越来越流行。
“Skimmer fraud is rampant with losses in the United States alone reaching over $1 billion each year,” US Attorney Phillip W. Williams Jr. said in a press release about the recent indictment. (That billion dollars includes multiple types of credit card skimming, not just EBT targeting.) “It is a silent insidious theft that occurs by merely swiping a credit card at a point of sale.”
“侧录欺诈非常猖獗,仅在美国,每年的损失就超过 10 亿美元,”美国联邦检察官 Phillip W. Williams Jr. 在关于此次起诉的新闻稿中表示。(这 10 亿美元包括多种类型的信用卡侧录,不仅仅是针对 EBT 的。)“这是一种无声且阴险的盗窃行为,仅仅通过在销售终端刷卡就会发生。”
Gary Warner, the director of intelligence at the cybersecurity firm DarkTower points out that dozens of states continue to use mag-stripe only cards for benefits purposes. “The risk here is that if the mag stripe is compromised, a clone of the card can be created and access not only the current value, but future value as well,” he says.
网络安全公司 DarkTower 的情报总监 Gary Warner 指出,仍有数十个州继续使用仅含磁条的卡片来发放福利。“这里的风险在于,如果磁条被破解,就可以制作出一张克隆卡,不仅能获取当前的余额,还能获取未来的福利金,”他说。
More broadly, Warner tells us, there are still multiple risks related to making payments using the magnetic stripes on any cards—even if they also include more secure chips that have been issued over the last decade-plus. “Non-bank ATMs and smaller non-chain merchants may expose your chip-enabled card to mag stripe reading,” Warner says. “Mag-stripe skimmers are often installed in such a way that the chip read is forced to fail.”
更广泛地说,Warner 告诉我们,使用任何卡片的磁条进行支付都存在多种风险——即使这些卡片在过去十多年里已经配备了更安全的芯片。“非银行 ATM 机和较小的非连锁商户可能会让你的芯片卡被迫使用磁条读取,”Warner 说。“磁条侧录器通常安装得非常巧妙,会强制芯片读取失败。”
While magnetic stripe cards have gradually been phased out in the US over many years, they’re still around. Mastercard, for example, said last month that it will stop issuing any cards with stripes in 2029, and its remaining batch will be completely out of circulation by 2033. In the meantime, financial fraud has become one of the largest overall crime types in the US and around the world. Many attacks are focused on social engineering, mass phishing message campaigns, and other fraud where money ends up being sent by victims in transactions that often look legitimate to banks and other financial institutions.
虽然磁条卡在美国多年来已逐渐被淘汰,但它们依然存在。例如,万事达卡(Mastercard)上个月表示,将于 2029 年停止发行任何带有磁条的卡片,剩余的卡片将在 2033 年前完全退出流通。与此同时,金融欺诈已成为美国乃至全球范围内最大的犯罪类型之一。许多攻击集中在社会工程学、大规模网络钓鱼活动以及其他欺诈手段上,受害者最终在银行和其他金融机构看来“合法”的交易中转出了资金。
Hauer says criminals will always try to use methods that let them steal as much money as possible, even if that means sending physical letters in the mail. “The real idea behind some of these scams is to not essentially try to steal €2,000 from someone’s bank account, but rather actually empty a proper savings account, which holds much more money,” he says.
Hauer 表示,犯罪分子总是会尝试使用能让他们窃取尽可能多钱的方法,即使这意味着要寄送实体信件。“这些诈骗背后的真正意图,本质上并不是试图从某人的银行账户中偷走 2000 欧元,而是要清空一个存有更多资金的储蓄账户,”他说。
If you feel like you’re already dodging scams left and right, there are some (relatively) easy takeaways to protect yourself from these old time scams. Avoid swiping cards whenever possible. And when you do need to swipe—as is, of course, the case with many EBT cards—do your best to check whether the terminal you’re about to use looks unusual, altered, or broken in any way. If so, use a different terminal. And apply the same skepticism that you have about texts and calls to letters as well. It feels like the only organizations that send mail these days are marketers, healthcare providers, banks, and the IRS, but scammers are still lurking there, too.
如果你觉得你已经在四处躲避诈骗,这里有一些(相对)简单的建议可以保护你免受这些老派骗局的侵害。尽可能避免刷卡。当你确实需要刷卡时——当然,许多 EBT 卡就是这种情况——请尽力检查你即将使用的终端是否有异常、被篡改或损坏的迹象。如果有,请换一个终端。同时,对信件也要保持像对待短信和电话一样的怀疑态度。如今似乎只有营销人员、医疗服务提供商、银行和国税局(IRS)才会寄信,但诈骗者也潜伏在其中。
Spotted something we should include next week? Let us know at [email protected]. And stay safe out there.
发现了我们下周应该报道的内容吗?请通过 [email protected] 告诉我们。祝大家平安。