Card fraud tends to get pictured as an online problem: a hacked e-commerce plugin, a phished customer, a stolen credit card number sold on a forum. But a huge share of small-business card theft never touches a website at all. It happens at the counter, at the register in a Salinas taqueria, the tasting room bar in Carmel Valley, the checkout desk at a Monterey boutique, where a customer taps or swipes a card and trusts that the machine in front of them is exactly what it looks like. Most of the time it is. Occasionally it isn't, either because someone attached a thin skimming device to the reader overnight, or because the terminal itself has been running malware for months that quietly copies every card number that passes through it. Neither attack requires the business's website, email, or even its Wi-Fi password. Both rely on the same thing: nobody looking closely at hardware and software that gets used dozens of times a day and inspected almost never.
Two different attacks, one stolen card number
A card skimmer is a physical device: an overlay that fits over a real card reader and copies the magnetic stripe or chip data as the card passes through, or a "shimmer," a paper-thin insert placed inside the card slot itself that's nearly invisible without pulling the reader apart. Whoever installs it needs only a few unsupervised minutes with the terminal, which is exactly what a slow shift, an unlocked back room, or an unattended self-checkout kiosk provides. POS malware works differently and doesn't need physical access at all. Once it's on the terminal or the server behind it, often through a compromised remote-access tool or an infected update, it uses a technique called RAM scraping: card data has to sit unencrypted in the terminal's memory for a brief moment during processing, and the malware simply reads it at that moment, before encryption ever applies. A business can have a spotless-looking terminal with an intact reader and still be bleeding card numbers to malware nobody has found, because there's nothing to visually inspect for.
Why small restaurants, wineries, and shops are easier targets than big chains
Large retailers dedicate staff to exactly this problem: fraud teams, PCI specialists, and vendors under contract to monitor and patch. A five-person restaurant or a family-run shop has none of that, and it shows in a handful of predictable ways. The POS terminal often shares a network with guest Wi-Fi or the back-office computer that handles email and bookkeeping, so a single infected machine can reach the payment system with no segmentation in the way. The POS vendor frequently installs a remote-access tool for support calls and leaves it running permanently, sometimes with a default or shared password that outlives every employee who ever knew it. Seasonal and part-time staff turn over fast enough that nobody owns the job of checking terminals for tampering, and older terminals still in service may not support EMV chip processing or point-to-point encryption at all, leaving raw card data exposed for longer than a modern terminal would allow.
- A reader that wobbles, sits at an odd angle, or doesn't match the terminal's color and texture is the clearest sign of an overlay skimmer, and it's only catchable by someone who knows what the terminal looked like before.
- A cluster of fraud complaints from customers who all paid within the same window is often the first real evidence of either type of compromise, arriving weeks after the fact through a bank, not through any internal alert.
- Remote-access software nobody remembers installing, or logins to it nobody can account for, is one of the most common ways POS malware actually gets a foothold in the first place.
What actually closes the gap
The fix starts with treating the POS environment as its own isolated system rather than one more device on the office network. That means putting payment terminals on a separate, segmented network with no path to guest Wi-Fi or general office computers, so a compromise on one side can't simply walk across to the other. It means using EMV chip and point-to-point encryption (P2PE) hardware wherever the payment processor supports it, so card data is encrypted at the reader itself instead of sitting in plaintext anywhere the terminal can be scraped. It means locking down or fully disabling the vendor's remote-access tool when it isn't actively needed for a support call, with a unique password instead of a shared default. And it means putting a simple, recurring habit on the calendar: photograph every card reader when it's installed, and compare it against that photo on a set schedule, whether that's opening shift or a weekly manager walkthrough. None of this requires a security budget a small business doesn't have; it requires deciding that the payment terminal is not just another piece of office equipment.
Where this fits
- The hospitality IT and cybersecurity post, for the broader picture of guest Wi-Fi, seasonal staffing, and PCI/POS security across restaurants, hotels, and wineries.
- The business Wi-Fi network segmentation post, for the network design that keeps a POS compromise from spreading to the rest of the business.
- The IoT device security post, for treating embedded devices like POS terminals with the same scrutiny as any other network-connected hardware.
- The PCI DSS compliance page, for what the standard requires for a small retail or restaurant merchant and how Ghosxt helps meet it.
FAQs about POS malware and card skimming
What is POS malware?
POS malware is software planted on a point-of-sale terminal or the server behind it that reads payment card data out of the device's memory in the brief moment before it gets encrypted, a technique often called RAM scraping. It doesn't need to break encryption or intercept network traffic, because it captures the card number while the terminal itself is still processing it in plain text.
What is a card skimmer and how do I spot one?
A skimmer is a physical device attached to or inserted into a card reader that copies card data as a customer pays, either an overlay that fits over the real reader or a thin "shimmer" inserted into the card slot. Warning signs include a reader that feels loose, wobbles, or sits at an odd angle; a color or texture that doesn't match the rest of the terminal; and a keypad or slot with an extra piece attached. Comparing a terminal to a dated reference photo taken when it was installed is the most reliable way to catch tampering.
Is PCI DSS compliance enough to prevent this?
PCI DSS sets the baseline, but the paperwork and the technical reality often drift apart. A business can complete its annual Self-Assessment Questionnaire and still run a POS terminal on the same flat network as guest Wi-Fi, or leave a POS vendor's remote-access tool active with a default password. Compliance is the checklist; segmentation, encryption, and physical inspection are what actually keep card data from being stolen.
What's the first thing to check if I suspect a compromise?
Check whether customer complaints about fraudulent charges cluster around a specific date range or location, physically inspect every card reader against a baseline photo, and review whether any remote-access software (TeamViewer, AnyDesk, or a POS vendor's own tool) shows login activity you can't account for. If any of those raise concerns, involve your payment processor and a security professional immediately rather than waiting for more evidence.
Not sure if your POS environment is actually locked down?
30 minutes with an engineer with DoD infrastructure experience. We'll review your POS network segmentation, remote-access exposure, and PCI posture, and show you exactly where a skimmer or malware could get a foothold, no scanner install, no obligation.
Book your free security assessment