The PCI Security Standards Council (PCI SSC) announced earlier this week in a press release a new paper that educates merchants on indoor payment terminal data protection aimed at preventing credit card skimming attacks.
The paper, Skimming Prevention: Best Practices for Merchants, includes actionable recommendations that address physical location and security, terminal and terminal infrastructure security, and staff and service access to payment devices.
The Council’s Pin Entry Device (PED) Working Group, incorporating input from law enforcement officials and industry experts, developed the paper. Its guidelines are intended to help merchants:
- Evaluate the risks relating to skimming;
- Understand the vulnerabilities inherent in the use of point-of-sale terminals and terminal infrastructure;
- Assess challenges associated with staff that has access to consumer payment devices;
- Prevent or deter criminal attacks against point-of-sale terminals and terminal infrastructure;
- Identify any compromised terminals as soon as possible and notify the appropriate agencies to respond and minimize the impact of a successful attack.
“In today’s heightened threat environment, skimming remains a popular method of data compromise,” said Troy Leach, technical director, PCI Security Standards Council. “Merchants can protect their business and their customers by educating themselves on risk, and taking active steps to protect their terminal infrastructure from fraud. By following the guidelines outlined in this document, merchants can improve security levels in their terminal environment and defend against this type of attack.”
The PCI SSC Skimming Prevention paper can be downloaded online. (NOTE: before you download, this is a large 40MB file).