United Kingdom flagIndependent UK business banking research
UK Business Banking Research · BanksGB
Business typesCards & expensesCash flowSecurityDigital bankingMerchant servicesFX & tradeInsightsAll topics
BanksGB · Security

Payment terminal tampering and skimming: inspect devices before customers use them

A practical UK merchant guide to card-terminal tampering, skimming, substitution, physical inspections, staff training, inventory and incident response.

Card terminals can be attacked physically as well as online. Criminals can substitute devices, attach skimmers or alter terminals to capture payment data and PINs. Merchants should know which terminals they own, where they are located and what each one should look like before trading starts.

Maintain an inventory of every payment terminal

PCI DSS physical-security controls require merchants in scope to protect devices that capture payment-card data from tampering and substitution. Record model, serial number, location and responsible site.

When a device moves between tills or events, update the inventory. An unknown terminal should never appear in production without verification.

Inspect terminals routinely for physical changes

Train staff to look for broken seals, unexpected overlays, loose parts, damaged cables or a device that looks different from the approved model.

Inspection frequency should reflect risk and environment. A public unattended terminal can need more frequent checks than a supervised back-office device.

Control new and replacement terminal deliveries

Fraudsters can impersonate acquirers or engineers and swap terminals. Staff should verify service visits through known provider contacts and record the serial number of replacement devices.

Do not hand a terminal to an unexpected courier because they know the merchant name. Use the provider's official replacement process.

Teach employees what to do when something looks wrong

Staff should stop using a suspicious device, protect customers from further transactions and contact the approved manager or payment provider.

They should not dismantle the terminal or destroy evidence. Preserve the device and CCTV where safe and follow incident instructions.

Physical tampering can accompany network compromise

A replaced terminal can connect differently or introduce malicious hardware. Review network alerts and terminal-management records if a device is suspected.

Use encrypted, approved terminal solutions and maintain software updates. Physical inspection is one layer, not the whole card-security programme.

Notify the acquirer quickly after suspected compromise

Contact the acquiring bank or processor through its official fraud or security channel. The provider can advise whether transactions, keys or terminals need to be suspended.

Keep an incident log of discovery time, affected device, recent transactions and staff actions. That evidence supports forensic investigation and customer protection.

Worked example: a retailer has 60 terminals across 20 stores. The asset register records serial number and location, while each store manager performs a visual check at opening. If a terminal at Store 7 suddenly has a different serial number after an unplanned "engineer" visit, staff can isolate it before customers use it instead of assuming the replacement was legitimate.

Keep service-provider visit records. Genuine technicians should follow an appointment or verification process, and staff should know which provider number to call independently. Social engineering can be more effective than breaking into a store, especially where employees are used to external engineers replacing card equipment.

Review portable terminals after events. Devices used at festivals, tableside service or temporary sites can leave normal controlled areas and face greater substitution risk. Count them back in, verify serials and inspect them before returning to everyday use.

Keep spare terminals secured and inventoried. An unused device in an unlocked stockroom can be tampered with before it ever reaches the till. Staff should inspect replacements before deployment even when the serial number matches the inventory.

Review terminal placement for privacy as well as tampering. Customers should be able to enter PINs without easy observation, while staff should still be able to see if someone attaches unusual hardware. Physical layout can either strengthen or weaken the technical controls built into the terminal.

Photograph approved terminal installations where practical. A site manager can compare cable routing, seals and attached accessories with the known configuration during inspections. Visual baselines make subtle substitutions easier to spot.

Include third-party concessions or pop-up counters in the terminal inventory. Devices operated inside the company's premises can still affect brand and customer trust even when a concession partner owns them, so responsibilities for inspection and incident escalation should be explicit.

Escalate unexplained terminal reboots, network changes or repeated chip failures as well as visible damage. Tampering is not always obvious on the outside. A device behaving differently from its peers can justify inspection before more customers use it.

Include terminal security in site-opening and closing checklists. Routine inspection is more reliable when it is part of normal operations rather than an annual compliance event that staff forget during busy trading periods.

Track terminal incidents by location and device age. A pattern of faults at one site can reveal environmental or security weaknesses, while repeated issues on an older model can justify replacement before the device becomes a larger operational risk.

Record inspection completion rather than relying on verbal assurance. A simple opening checklist with date, employee and terminal count gives management evidence that the control actually happened.

Editorial Verdict

Terminal security starts with knowing exactly which devices belong in the business and checking that they have not changed.

Inventory serial numbers, verify engineers, train staff and stop using suspicious hardware immediately. Physical payment devices deserve the same security attention as ecommerce checkout.

Sources

Keep the banking structure tied to the business model

Use the provider directory, comparisons and practical guides to narrow the questions before choosing products.

Start comparison