Credit card theft works in four main ways: someone takes the physical card, tampers with a card reader to capture your data, tricks you into handing over your details online, or breaks into a merchant’s database and steals millions of accounts at once. The stolen information is then used to buy goods, cloned onto blank cards, or sold on dark web marketplaces to someone else who will. Federal law treats all of it as a felony under 18 U.S.C. § 1029, and it caps what you personally can be forced to pay when a thief uses your card.
Physical Theft and Tampered Card Readers
The oldest version of credit card theft is still around: pickpocketing, grabbing a card left on a restaurant table, or intercepting mail with a newly issued card inside. The account number, expiration date, and CVV are printed on the plastic, so a thief with the card in hand has everything needed for most online purchases.
Hardware attacks are the next step up. Skimmers are small devices placed over legitimate card readers at gas pumps and ATMs. They read the magnetic stripe as you insert or swipe, while a hidden camera or a keypad overlay captures your PIN. Shimming is a newer variant aimed at chip cards: an ultra-thin circuit board slipped inside the reader slot intercepts data passing between the chip and the terminal. Chip data is harder to clone than magnetic stripe data, but it can still be used for online, card-not-present fraud.
You can spot some tampered readers before using them. A reader that wiggles when you tug on it, one bulkier than the readers on neighboring pumps, or a keypad that feels unusually stiff or raised are all warning signs. When in doubt, pay inside or use a contactless method that never enters the slot.
Phishing and Network Interception
Most card theft now happens without anyone touching your wallet. Phishing emails that mimic bank alerts, text messages claiming suspicious activity (smishing), and phone calls impersonating fraud departments (vishing) all try to manufacture enough urgency that you enter your card details before questioning the request. The fake login pages are often pixel-perfect copies of real bank sites, and the URLs are close enough to fool anyone not reading the address bar carefully.
Network interception is less common but harder to notice. In a man-in-the-middle attack, someone sets up a rogue Wi-Fi hotspot in a place like a coffee shop or airport, or compromises an existing unsecured network. When you connect and make a purchase, the attacker sits between your device and the merchant’s server, reading card numbers and passwords as they pass. Sticking to HTTPS sites and using a VPN scrambles the traffic even if someone is listening.
Retail and Payment Database Breaches
Individual theft nets one victim at a time. Breaking into a retailer’s database can net millions in a single attack. Hackers hunt for weaknesses in the backend systems of merchants, payment processors, and banks. SQL injection — feeding malicious commands through a website’s input fields to trick the database into returning its contents — remains one of the most common techniques. Server-side malware is another: once installed, it quietly watches live transactions or scrapes stored logs, pulling names, addresses, and card details out in bulk.
Cardholders rarely know a breach happened until the company discloses it publicly. That gap between the intrusion and the notice is where most of the damage occurs, because charges can pile up for weeks before anyone realizes the data was taken.
How Stolen Card Data Gets Used
Stolen data has to be turned into something valuable, and the method depends on what the thief has. Card-not-present fraud is the most common path: the number, expiration date, and CVV are used to buy goods online or by phone, usually electronics, gift cards, and other items that resell quickly.
When a thief has full magnetic stripe data from a skimmer, they can write it onto a blank card with a magnetic stripe encoder and use the clone in physical stores. Chip data is harder to duplicate, which is one reason the U.S. move toward EMV terminals has cut in-person counterfeit fraud. But magnetic stripe readers still exist at plenty of retailers, and cloned cards keep working there.
Before running up big charges, experienced thieves usually test the card first. This is called carding or account testing: they charge a small amount, sometimes under a dollar, to check whether the card is still active. If it clears, they move to larger purchases quickly, trying to drain the credit line before the real cardholder notices. Merchants push back with velocity checks that flag rapid small-dollar transactions, CAPTCHA challenges, and device fingerprinting that spots the same computer testing hundreds of numbers in sequence.
The Dark Web Resale Layer
The hackers who breach databases or deploy skimmers often don’t use the stolen data themselves. They sell it in bulk on dark web marketplaces and encrypted messaging channels. Listings are sorted by how complete the data is. A basic “dump” might include just the card number and expiration date, while “fullz” packages contain the cardholder’s name, address, Social Security number, date of birth, and sometimes bank login credentials. Prices reportedly range from a few dollars for a basic number to over $100 for a full identity profile, depending on the card’s credit limit and whether the account is verified as active. Cryptocurrency is the standard payment method, which makes tracing hard. The separation between whoever steals the data and whoever uses it is deliberate, and it makes life harder for investigators trying to connect a breach to the person eventually charging things in a store.
Federal Penalties for Credit Card Theft
The core federal statute is 18 U.S.C. § 1029, which criminalizes using, trafficking in, or possessing unauthorized “access devices” with intent to defraud. Access device is defined broadly enough to include card numbers, PINs, and account codes, not just physical plastic. The law doesn’t require anyone to actually swipe a card: possessing 15 or more counterfeit or unauthorized access devices is enough for a federal charge, and so is producing or trafficking in device-making equipment.1Office of the Law Revision Counsel. 18 USC 1029 – Fraud and Related Activity in Connection With Access Devices
The most commonly charged offenses — using unauthorized access devices, trafficking in them, or possessing device-making equipment — carry up to 10 years in federal prison for a first offense. Some offenses involving counterfeit access devices or scanning receivers carry up to 15 years. A repeat conviction under any subsection raises the maximum to 20 years.1Office of the Law Revision Counsel. 18 USC 1029 – Fraud and Related Activity in Connection With Access Devices Fines can reach $250,000 for an individual, the standard federal felony maximum.2Office of the Law Revision Counsel. 18 USC 3571 – Sentence of Fine
When card data is stolen through a computer intrusion, prosecutors can also charge under 18 U.S.C. § 1030, the Computer Fraud and Abuse Act. Unauthorized access to a protected computer to obtain financial information carries up to five years for financial gain or in furtherance of another crime, and up to ten years for a repeat offense.3Office of the Law Revision Counsel. 18 USC 1030 – Fraud and Related Activity in Connection With Computers
Courts must also order restitution in fraud cases with identifiable victims. Under the Mandatory Victims Restitution Act, 18 U.S.C. § 3663A, a convicted defendant has to repay the value of property lost or damaged, including amounts drained from victims’ accounts.4Office of the Law Revision Counsel. 18 USC 3663A – Mandatory Restitution to Victims of Certain Crimes Every state also has its own credit card fraud or theft-by-deception statutes, so a single scheme can trigger both state and federal prosecution.
What You Can Be Forced to Pay
Federal law caps your liability for unauthorized credit card charges at $50. Under 15 U.S.C. § 1643, a cardholder’s maximum exposure is $50 per card, and only for use that occurred before you notified the issuer. Once you report the card lost or stolen, your liability for future charges drops to zero.5Office of the Law Revision Counsel. 15 USC 1643 – Liability of Holder of Credit Card Visa and Mastercard both offer zero-liability policies that eliminate even that $50 for most cardholders in practice.
Debit cards work differently, and the difference catches people off guard. Under the Electronic Fund Transfer Act, 15 U.S.C. § 1693g, your liability depends on how fast you report. Report within two business days of learning about the theft and your maximum loss is $50. Wait more than two days but report within 60 days of your statement, and your exposure jumps to $500. Miss the 60-day window entirely, and you can be on the hook for everything the thief took.6GovInfo. 15 USC 1693g – Consumer Liability That’s one of the strongest practical reasons to use a credit card rather than a debit card for everyday purchases.
What to Do If Your Card Is Compromised
Call your card issuer as soon as you spot an unauthorized charge and ask for a new card number. Under the Fair Credit Billing Act, 15 U.S.C. § 1666, you have 60 days from the date the issuer sends the billing statement containing the error to dispute it in writing. While the dispute is pending, the issuer can’t try to collect the disputed amount or report it as delinquent.7Office of the Law Revision Counsel. 15 USC 1666 – Correction of Billing Errors
If more than the card was exposed — your Social Security number, date of birth, or bank login — file a report at IdentityTheft.gov. The site generates a personalized recovery plan, pre-fills dispute letters you can send to the credit bureaus, and produces an Identity Theft Report that serves as your official record of the crime.8IdentityTheft.gov. Identity Theft Letter to a Credit Bureau Some creditors and bureaus also accept a police report, though one isn’t always required for a basic card dispute.
To keep the thief from opening new accounts in your name, place a credit freeze with Equifax, Experian, and TransUnion. A freeze blocks anyone, including you, from opening new credit until you lift it. Under federal law it’s free to place and remove, it lasts until you take it off, it doesn’t affect your credit score, and it has no impact on your existing accounts. If you want a lighter option, an initial fraud alert lasts one year and requires businesses to verify your identity before opening new credit, but it doesn’t actually block access to your credit report the way a freeze does.9Consumer Advice – FTC. Credit Freezes and Fraud Alerts For confirmed fraud, the freeze is the option that shuts the door completely.