EMV-Bypass Cloning: What It Is, How It Works, and What Chargeback Code It Generates

EMV-bypass cloning copies data from a chip card's insertion onto a counterfeit magnetic stripe, generating a counterfeit card-present chargeback under Visa 10.1, Mastercard 4870, or American Express F30 that merchants can fight only if their terminal actually completed the chip read.

EMV-bypass cloning is a fraud technique where criminals lift the data off a chip card, then write it onto a counterfeit card's magnetic stripe. The fraudster swipes that card at a terminal that still accepts swipes. That swipe skips the chip's protection.

I deployed alert tooling on my own stores before I ever advised anyone on it. One lesson stuck. An alert only helps if the charge behind it is already recognizable. This is exactly the kind of dispute you want caught early.

Below is the mechanism, the reason code it generates, and what to do when one lands.

Key takeaways

  • Criminals copy chip data, then write it onto a counterfeit magnetic stripe.
  • Expect Visa 10.1, Mastercard 4870, or American Express F30 on these disputes.
  • Ask your processor whether stripe fallback is enabled on your terminals.
  • Two 2020 breaches exposed over 720,000 cards through this technique.
  • Enforce chip-or-decline so a counterfeit magnetic stripe has nowhere to work.

Want counterfeit-fraud disputes flagged before they turn into chargebacks? See how alerts work.

What is EMV-bypass cloning?

EMV-bypass cloning copies data from a chip card onto a counterfeit card's magnetic stripe, then runs it through a terminal that takes a swipe. The goal is getting around EMV. The chip itself stays intact.

Insert a chip card and it makes a fresh code for that one sale, so a copy of yesterday's code is worthless today.

Stripe data works the opposite way. It's fixed, and it repeats on every swipe. That gap between the two formats is what criminals sell.

The swipe is also the limit of the attack. A counterfeit stripe only pays off where a terminal accepts one.

Why EMV cards were introduced

EMV, short for Europay, Mastercard, and Visa, is the chip standard behind credit, debit, or prepaid cards with a chip that checks each sale. Card networks pushed them because stripe fraud had become cheap. Copy a stripe once, and the card was reusable until the account closed.

The chip changed that math by making each sale's data useless afterward. The stripe stayed on the back of the card, and that leftover stripe is what this fraud runs on.

Can someone clone my card with a chip?

Criminals can copy the account data your chip sale exposes and write it onto a counterfeit card, though the chip itself resists copying. The difference sounds small, and it changes what you can do about it.

Cloning normally means making a working duplicate, which the chip's security prevents. Criminals settle for the account data underneath, which is enough to build a card that swipes.

Check whether your terminal declines a card after a failed chip read, or ask your processor whether stripe fallback is on.

A counterfeit card only becomes dangerous where something takes that fallback swipe.

Summary: The account data behind the chip can be moved onto a counterfeit stripe, even though the chip resists duplication.

How are hackers bypassing EMV cards?

A shimmer sits inside the chip slot and reads data during a real chip sale, while a skimmer sits over the stripe reader and reads data during a swipe. This fraud needs chip-sale data. A shimmer takes it one terminal at a time, and a system breach takes it in bulk.

A shimmer is a paper-thin circuit slipped into the reader's chip slot. The slot still looks and works normally. It reads the exchange between chip and terminal while your purchase goes through, so the sale looks fine to you and the cashier.

The two devices differ on every axis that matters:

DeviceWhere it sitsWhat it readsWhich sales it sees
ShimmerInside the chip slotChip-sale dataChip insertions
SkimmerOver the stripe readerStripe dataSwipes only

A skimmer only sees sales that skipped the chip, so it never reaches the chip data this fraud runs on.

That difference matters when you read a fraud report and work out what happened at your counter.

When did EMV-bypass cloning start?

Researchers described the weakness behind EMV-bypass cloning in 2013 and 2014, years before criminals used it at scale. Both confirmed large-scale cases came in 2020.

Security research runs well ahead of criminal use. Published work shows attackers what's possible in theory, and building a working operation takes hardware and a way to cash out.

That gap is why decade-old papers still surface when you search this topic.

A known flaw can sit in the research for years before anyone builds a business on it.

Should I worry about EMV-bypass cloning?

Worry in proportion to your terminal setup, because this fraud only works where a stripe swipe can stand in for a chip read. You're exposed anywhere your terminal still takes a swipe after a failed chip read.

Some processors leave that fallback on by default, because turning it off means turning away customers with damaged cards.

Chip-enforcing hardware puts you at much lower risk than a terminal that allows fallback swipes.

How does EMV-bypass cloning affect businesses?

The direct result is a counterfeit-fraud chargeback, and the EMV liability shift decides who eats the loss. The fraud costs you the goods either way. The liability rule decides whether it also costs you the money.

Whichever party skipped the chip read pays. Swipe a chip card on a terminal that didn't read the chip, and the fraud loss becomes yours instead of the issuer's.

You lose more than the disputed amount:

  • The goods, which are already gone with the fraudster.
  • A chargeback fee on top of the reversed sale.
  • One more dispute on the ratio your processor watches.

That ratio is what triggers reserves or a monitoring program.

Fully compliant terminals keep you protected even when someone hands over a counterfeit card, because the liability stays with the issuer.

What chargeback code does EMV-bypass cloning generate?

EMV-bypass cloning produces a counterfeit card-present chargeback, filed as Visa 10.1, Mastercard 4870, or American Express F30. Visa's 10.4 covers card-absent fraud, a different situation.

Each network wrote its code to carry out the liability shift, so all three describe a counterfeit card used where the chip wasn't read:

NetworkCodeWhat it covers
Visa10.1"A counterfeit chip card was used at a point-of-sale device that did not complete an EMV chip read, moving liability to the merchant."
Mastercard4870"Card-present transactions where an EMV-chip card was swiped instead of read by a chip-ready terminal."
American ExpressF30"Code F30 is a chargeback tied to a card-present transaction where the cardholder says they did not authorise the payment, and the issuer believes a counterfeit card was involved."

Getting the code right changes what you send back. These disputes turn on terminal evidence, while a card-absent case wants delivery confirmation. Merchants who send that second packet here lose.

When one lands, pull the chip tag data from your processor first. Our reason code lookup tool confirms the code before you build the response.

Three things belong in the packet when the chip read did complete:

  1. The chip tag data for the disputed sale. It shows the chip was read rather than swiped.
  2. Proof the terminal is EMV-certified. Your processor or vendor holds that record.
  3. The authorization response. It ties the approval to the chip read.

Visa allows 30 days to respond and Mastercard allows 45, and your processor will set a shorter deadline than either.

Then be honest about your odds. A completed chip read shifts liability back to the issuer and gives you a case worth fighting. A fallback swipe leaves you holding a counterfeit card and a rule saying you could have stopped it.

A dispute response rarely rescues that one, which is why catching the charge early beats fighting it later.

Can you prevent EMV-bypass cloning?

You can close the swipe path at your own checkout and catch the fallout early, even though shimming elsewhere stays outside your control. Prevention here does two jobs. It declines the counterfeit swipe, then shortens the time before you hear about the fraud.

Your terminal's fallback setting is what makes the attack possible. Turn it off and the counterfeit swipe gets declined.

Turn off stripe fallback first, then layer on the rest:

  1. Set terminals to chip-or-decline: Ask your processor to turn off stripe fallback so a failed chip read ends the sale.
  2. Confirm full EMV data passes on every authorization: Ask your processor for the chip tag data on a sample of sales and check the chip read is transmitted rather than stripped.
  3. Inspect card readers on a schedule: Pull on the chip slot and bezel at open and close, and keep a photo of each terminal for comparison.
  4. Enroll in chargeback alerts: An alert tells you a cardholder disputed a charge, which buys you time to refund before it becomes a 10.1 you can't win.

Alerts cover the cards cloned somewhere else, which your own terminal settings can do nothing about. Ethoca alerts are the Mastercard-owned network behind many of these notices.

Your online orders need a different set of controls, because a card-absent order has no chip to read. CVV checks are the baseline there.

EMV SRC authenticates online checkouts the way a chip read does at the counter.

Protecting customers from EMV-bypass cloning

Give customers two habits, which are tapping instead of inserting, and reading statements weekly. A shimmer sits in the chip slot, so it never sees a contactless tap.

Statement checks catch charges on a card that was already cloned. A cloned card usually gets tested with a small charge before anything large, so a weekly read catches it early.

Real-world examples of EMV-bypass cloning

Two confirmed 2020 breaches exposed over 720,000 card records that criminals could monetize this way. Recorded Future traced both of them:

BreachLocationsFoundData taken
Key Food Stores60+ stores, five statesJanuary 2020Chip data including iCVV
Wine and liquor store, Suwanee, Georgia1June 2020Chip data including iCVV

The stolen data showed up on dark web markets, and the iCVV made it usable. That code differs from the CVV on a card's stripe, and the two get checked separately. Swapping one for the other should fail.

It worked anyway, because the banks weren't checking which code arrived. Recorded Future found the attack breaks wherever a bank checks every card security code.

The attackers reached the checkout systems remotely and took chip data in bulk, the only way to cover 60-plus stores at once.

Hobbyists have written chip data to blank cards in a public demo thread. Two breaches and a few community experiments are the full public record, so this stays rare.

Summary: Two 2020 breaches proved the technique works at scale, and both succeeded because banks skipped a verification step.

How to recognize EMV cloning attempts

Watch for a customer who asks your staff to swipe a chip card, and for terminals reporting chip read failures on cards that should work fine. A counterfeit card only works on a swipe, so both signs point the same way.

A counterfeit card carries working stripe data and a dead chip, so whoever holds it needs a swipe. That leaves two ways to get one. Someone talks your cashier into it ("the chip's damaged, can you swipe it?"), or your terminal falls back on its own after a failed read.

A damaged card produces the same failure. Treat a run of chip errors on one shift as a reason to inspect the reader, not proof of fraud.

Counter vigilance only catches attempts made in front of you. Data cloned from your terminals gets sold and used elsewhere, which is why the configuration fix beats staff training.

FAQ

Can an EMV chip be hacked?

Criminals go after the system around the chip, taking the account data a chip sale exposes and running it as a magnetic stripe swipe. The chip's own per-transaction code holds up, because it can't be reused.

How can I stop my credit card from being cloned?

Tap to pay wherever contactless is offered, because a shimmer in the chip slot can't read a tap. Report a small unfamiliar charge straight away, since that's the usual test before a large one.

Can a contactless debit card be cloned?

The magnetic stripe on the back stays the weak point, because contactless taps use the same per-transaction code as a chip insert. A captured tap holds static account data that only pays off as a swipe.

Can ATMs detect cloned cards?

Modern ATMs that require a chip read reject a counterfeit card with a dead chip. Older machines that accept a magnetic stripe fallback approve it, which is the same weakness that makes this fraud work at retail terminals.

Do online-only businesses need EMV-compliant terminals?

This is card-present fraud, so it applies the moment you take an in-person sale. A seller working only online stays out of scope for this pattern.

Verlaag vandaag nog uw geschillenpercentage

Sluit je aan bij meer dan 800 bedrijven die Chargeback gebruiken om terugboekingen automatisch te voorkomen — de installatie duurt minder dan 2 minuten.