Welcome to Kernel Panic! A weekly newsletter by Lily Hay Newman and Matt Burgess from inside the new world of privacy and digital security. To receive this newsletter in your inbox each week, sign up here.
When every random text message feels like it’s a scam, and with AI supercharging digital fraud, old-time credit card skimmers and bogus letters that arrive in the mail may seem laughable as potential threats in 2026. But as we all suffer through a seemingly unending barrage of potential scams, these antiquated attacks are still costing victims around the world dearly.
The fake-new-credit-card-in-your-mailbox trick is particularly insidious. Portugal, France, and Germany have all had waves of physical credit card scams in recent years where criminals have mailed phony replacement cards or letters to potential victims. Included letters often claim a current card is set to expire soon, whether the victim actually has one that’s about to expire or not. In order for the new (fake) card to be activated, the scam letter says, it should be registered using an included QR code or URL. Some sham cards even have real customer names printed on them, says Georg Hauer, an advisor for digital banks. “The card is almost like a token that creates the trust that is needed in order to fall for the actual trick,” he says.
If someone scans the QR code, they’re typically redirected to a fake banking website, where they’re asked to enter their details—potentially giving cybercriminals direct access to their real accounts. “This has been escalating for close to two years, and I believe that this type of scam might have proven to be successful enough to be rolled out in other countries,” Hauer says. “The cost of producing a personalized fake card has dropped in recent years thanks to AI just being able to copy a design based on an image, and the higher conversion rate per victim might justify the extra costs.”
Mail scams aren’t the only ’90s throwback on the docket. The US Attorney’s Office for the Northern District of Alabama indicted two Romanian nationals last week on charges related to alleged credit card skimming. Authorities say the pair specifically targeted government SNAP food assistance benefits distributed to recipients in most states on antiquated magnetic stripe-only debit cards, or Electronic Benefit Transfer (EBT) cards.
Fraud related to chip credit cards does exist as well, but this recent case serves as a reminder that classic skimmers targeting magnetic stripe credit cards are still deployed by scammers because there’s apparently still enough swiping going on to make it worth their while. The FBI says that EBT card skimming has risen in popularity among scammers since about 2021.
“Skimmer fraud is rampant with losses in the United States alone reaching over $1 billion each year,” US Attorney Phillip W. Williams Jr. said in a press release about the recent indictment. (That billion dollars includes multiple types of credit card skimming, not just EBT targeting.) “It is a silent insidious theft that occurs by merely swiping a credit card at a point of sale.”
Gary Warner, the director of intelligence at the cybersecurity firm DarkTower points out that dozens of states continue to use mag-stripe only cards for benefits purposes. “The risk here is that if the mag stripe is compromised, a clone of the card can be created and access not only the current value, but future value as well,” he says.
More broadly, Warner tells us, there are still multiple risks related to making payments using the magnetic stripes on any cards—even if they also include more secure chips that have been issued over the last decade-plus. “Non-bank ATMs and smaller non-chain merchants may expose your chip-enabled card to mag stripe reading,” Warner says. “Mag-stripe skimmers are often installed in such a way that the chip read is forced to fail.”