Maker.io main logo

Sparkfun Takes On Gas Pump Skimmers

2017-09-21 | By jenntoso

 

Sparkfun was recently asked by some important people in fancy suits if they could dig inside a few credit card skimmers and report what they had found. Along with tearing them down, they were also tasked to figure out a way to combat these unscrupulous devices so that people such as you and I could learn to protect ourselves – and our money.

What They Are, What You Need to know, and How to Protect Yourself

via @sparkfun

We were given three skimmers found installed within gas pumps with the request that we try to get the data off the board so that the agents could let those who've had their credit card compromised know so they can get a new card. Not great, but it's a start. Second task: can we build a jig or system so that they can more easily poke at these systems in the future. We were able to accomplish both as well as build an app that detects known skimmer in the area. You can get the free Android app here from google play - search for the name 'Skimmer Scanner' from SparkX.

For those who don’t want to read through the gritty details here's the summary:

   1. These skimmers are cheap and are becoming more common and more of a nuisance across north america.

   2. The skimmer broadcasts over bluetooth as HC-05 with a password of 1234. If you happen to be at a gas pump and happen to scan for bluetooth devices and happen to see an HC-05 listed as an available connection then you probably don't want to use that pump.

   3. The bluetooth module used on these skimmers is extremely common and used on all sorts of legitimate products end educational kits. If you detect one in the field you can confirm that it is a skimmer (and not some other device) by sending the character 'P'; to the module over a terminal. If you get a 'M' in response then you have likely found a skimmer and you should contact your local authorities.

Read the entire tutorial and tear down from Sparkfun right here

Have questions or comments? Continue the conversation on TechForum, DigiKey's online community and technical resource.