Spain is the third-most-affected European country for stolen credit cards sold on the dark web. According to a 2025 NordVPN study, Spanish users’ banking data sells for an average of $11.68 per card, usually in bundles, suggesting the volume of compromised cards circulating in illegal markets. Meanwhile, in February 2026, Spanish banks and the OCU (Spanish Consumers’ Organization) issued alerts after detecting a wave of fraudulent charges of just a few cents, designed to test whether a card is working before the final theft.

Knowing how your card details are stolen and what they do with them afterward is the first step to avoid becoming a victim.

 

Theft of credit card data in non-face-to-face transactions

In recent years, EMV systems have been implemented to prevent the physical cloning of credit cards. EMV is a payment method based on a technical standard for smart payment cards, payment terminals, and ATMs that can accept them. EMV stands for “Europay, Mastercard, and Visa,” the three companies that created the standard.
That’s why credit card vulnerabilities are more common during card-not-present (CNP) transactions.

 

How can they steal your credit card information? Most common forms

Cybercriminals use a variety of techniques to obtain your card details in both physical and digital environments. These are the most widespread methods currently used:

Phishing, smishing, and vishing

Phishing is the most common method. The attacker impersonates your bank, a courier company, or a payment platform (Amazon, PayPal, BBVA, CaixaBank, etc.) and sends you an email or SMS with a link to a fake website where you unknowingly enter your card details.

  • Smishing: The same technique is used via SMS. You often see messages like, “Your package is being held, please enter your details to release it.”
  • Vishing: Phone call. The “fake bank technician” scam involves someone who detects a suspicious purchase and asks you to confirm details to cancel it.

In all cases, the objective is the same: for you to voluntarily enter the card number, expiry date, and CVV.

 

 

phishin to steal credit card data

Web skimming (formjacking)

Web skimming, also known as formjacking, involves injecting malicious JavaScript code into the payment page of a legitimate online store. The code is completely invisible to both the user and the merchant. It captures card details as soon as they are entered and sends them to the attacker’s server.

Skimming and shimming on ATMs and data phones

Although EMV (chip) systems drastically reduced classic skimming, criminals have evolved:

  • Skimming: Installation of a physical device over the card reader of an ATM or point-of-sale terminal that copies the magnetic stripe. Modern models incorporate Bluetooth transmission to extract data remotely.
  • Shimming: The most recent and difficult-to-detect variant involves criminals inserting an ultra-thin electronic strip (shim) into the card reader slot. This shim intercepts communication between the card’s EMV chip and the terminal, allowing them to read enough data to create fraudulent magnetic stripe cards.

Corporate data breaches

When criminals attack a company that stores payment data, they can obtain thousands or millions of card records in one fell swoop. These breaches are especially profitable for attackers and are the primary source of leaked credit card information sold on the dark web.

Data stolen in corporate security breaches can take months to appear on illegal markets. This prevents users from linking the leak to a specific incident.

Public WiFi networks and man-in-the-middle attacks

When you connect to an unencrypted public Wi-Fi network (airport, coffee shop, hotel) and make a purchase, an attacker on the same network can intercept the communication and capture your card details. This technique, known as a man-in-the-middle attack, is less common today thanks to HTTPS, but it remains an active vector in poorly configured networks.

Malware and spyware on devices

Malicious apps or infected downloads can install a keylogger or spyware that records everything you type, including your card details when making online purchases.

 

Technique Environment How it works Warning sign
Phishing / smishing Online / Mobile Email or SMS with a link to a fake bank website Suspicious URL, urgency in the message
Vishing Telephone A call from “your bank” asking for details No bank asks for the CVV over the phone.
Web skimming Online stores Malicious code in the payment form Difficult to detect as a user
Physical skimming ATMs and POS terminals Device superimposed on the reader Reader with loose or strange parts
Shimming ATMs and POS terminals Foil in the EMV chip slot Almost impossible to detect with the naked eye
Data leak Companies Database breach in a business Unknown charges weeks later
Public WiFi Open Networks Interception of the unencrypted connection Password-free Wi-Fi in public places
Malware / keylogger Own device Malicious app or download records keystrokes Strange device behavior

 

How are credit cards cloned?

Card cloning is the process by which criminals create a physical or virtual copy of your card using stolen data to make fraudulent purchases.

There are two main types:

  • Physical cloning: Using data obtained from the magnetic stripe via skimming, criminals encode a blank card with that information. This allows it to be used in stores that still accept magnetic stripe cards (increasingly less common in Europe, but still common in some Latin American countries or for in-person purchases with outdated terminals).
  • Virtual cloning (carding): Using the card’s full details (number, expiration date, and CVV), criminals can make online purchases directly, without needing to manufacture any physical object. This has been the dominant method in Spain since the widespread adoption of the EMV chip.

The entire carding process operates like an industrial chain: some criminals steal the data, others validate it by making micropayments of cents to verify that the card is active, and a third group exploits it until the available credit is exhausted.

 

What can they do with your card details?

Once your card details are in the hands of attackers, the most common uses are:

Fraudulent use Description
Direct online purchases They place orders in online stores on behalf of third parties or with an anonymous shipping address
Selling on the dark web They sell the data in packages to other criminals at an average price of €10 per card in Spain
Carding (test micropayments) They make minimal charges (€0.50–€1) to verify that the card works before operating.
Creation of cloned physical cards Using magnetic stripe data, they manufacture cards for use in chip-free POS terminals
Identity fraud They combine your card details with other personal information to impersonate you.
Fraudulent transfers or tricks In some cases, they can access online banking if they also have the login credentials.

 

 

My credit card was hacked: signs to detect it and what to do

If you suspect your credit card has been hacked, or that your data is part of a credit card leak, the signs often appear sooner than you think, although almost no one associates them with fraud until the damage is already visible.

These are the most frequent signs that indicate your card details may have been compromised:

  • Unknown charges on your statement, especially micropayments of cents (a classic sign of carding).
  • Notifications from your bank for purchases you did not make, even if you had the card at all times.
  • Failed attempts to access your online banking from unknown devices or locations.
  • You receive purchase confirmations for orders you didn’t place. Sometimes on platforms you don’t even know exist.
  • Your card is declined for a routine purchase for no apparent reason (this may indicate the bank blocked it due to suspicious activity detected before you).
  • Your bank details appear in a data breach alert, such as those issued by Qondar when it detects your credentials on the dark web.

Practical rule: Review your card transactions at least once a week. The sooner you identify a fraudulent charge, the easier it is to recover your money and the less damage it can do.

 

What to do if your card details have been stolen?

If you detect unauthorized charges or suspect that your data has been compromised, act in this order:

  1. Call your bank immediately to block or cancel the card. Most have a 24-hour helpline. Do it even if you’re not sure; it’s free and reversible.
  2. Document fraudulent charges with screenshots of the statement before the bank removes them from the visible history.
  3. File a complaint with the National Police or the Civil Guard. This is necessary for the bank to process the refund and for the police investigation to move forward.
  4. Request a chargeback from your bank. In cases of card fraud, European regulations (PSD2) require banks to return the amount immediately in most cases, except in cases of serious cardholder negligence.
  5. Check if your data is circulating on other platforms using monitoring tools like Qondar. Credit card data breaches often expose other personal data as well.
  6. Change the passwords on the platforms where you saved that card. (Amazon, PayPal, plataformas de streaming…).

 

How to protect your credit card data: a practical guide 2026

Online shopping

  • Only buy from websites with HTTPS and recognized trust seals.
  • Use single-use virtual cards for purchases at stores you don’t know.
  • Activate real-time notifications from your bank for every charge.
  • Avoid saving your card details on platforms if you don’t use them regularly.
  • Never make purchases while connected to a public WiFi network without a VPN.

At ATMs and card payment terminals

  • Visually inspect the reader before inserting the card. If it has loose parts, play, or anything stuck to it, do not use it.
  • Prefer contactless (NFC) payment to push notifications whenever possible: it eliminates the risk of shimming.
  • Cover the keypad with your hand when entering the PIN, even if you don’t see any cameras.
  • Preferably use ATMs located in bank offices or large establishments.

On your device and email

  • Do not click on links in SMS messages or emails that ask you to confirm bank details, even if the sender appears to be your bank. Always access your account through the official app or by typing the URL directly.
  • Keep your operating system and applications updated to close malware vulnerabilities.
  • Activate two-factor authentication (2FA) on your online banking.

Continuous monitoring

Reactive protection has its limits; you act only after you know something has happened. Continuous monitoring of your data on the dark web, like that offered by Qondar, allows you to detect a breach before it can be exploited.

Learn more about personal privacy and how to protect it.

 

Qondar: Continuous monitoring of your banking data on the web and the dark web

Most credit card fraud goes undetected until the damage is already done. The problem is that weeks or months can pass between when your data is leaked and when a criminal uses it.

Qondar, Enthec’s personal cyber-surveillance platform, solves exactly this problem. It automatically and continuously monitors whether your card details, such as the number, expiration date, and combinations with your email or phone number, appear in leaked databases, carding forums, dark web marketplaces, or any other source of exposure.

When it detects that your data is being transmitted, it alerts you in real time. So you can cancel the card, notify the bank, and block any use before the impact becomes greater.

You don’t need technical knowledge. Qondar works in the background, like a permanent alarm system for your identity and digital assets.

 

Frequently Asked Questions

How can they steal my card details without taking the card from me?

Through digital techniques such as phishing (fake websites that impersonate your bank), web skimming (malicious code in online stores), or malware on your device. They can also use physical devices installed on ATMs (skimming and shimming) that capture data when you insert your card.

What is a leaked credit card?

A leaked credit card is one whose data criminals have illegally obtained and sold or distributed on dark web marketplaces or carding forums. In 2025, Spain was the third European country with the most leaked credit cards circulating on these markets.

How are credit cards cloned?

Through skimming (devices on ATMs that read the magnetic stripe) or shimming (sheets that intercept the EMV chip), criminals obtain data to manufacture counterfeit physical cards. In online environments, virtual cloning uses the card number, expiration date, and CVV to make purchases without needing a physical card.

How can I tell if my debit or credit card has been hacked?

The clearest signs are unfamiliar charges on your statement, purchase confirmations you didn’t make, or your card being declined for no apparent reason. You may also receive alerts from your bank or tools like Qondar if your data appears in a data breach.

What can they do with my card details?

They primarily use them to make fraudulent online purchases, sell them on the dark web to other criminals, or create cloned physical cards. In some cases, they also combine them with other personal data to impersonate you with your bank.

Will the bank refund my money if my card has been hacked?

In most cases, yes, as long as you report it promptly and you were not grossly negligent. European regulations such as PSD2 require banks to refund the amount immediately in cases of card fraud.

Is it the same if my physical card is stolen as if my data is stolen?

No. If your physical card is stolen, the bank blocks it and issues a new one. If someone steals your data (number, expiration date, CVV) without you losing the card, you may keep using it without knowing it’s compromised, while criminals use it online. That’s why early detection is crucial.

How can I prevent my card details from being leaked?

Use single-use virtual cards for online purchases, activate real-time notifications, avoid entering data on websites without HTTPS, physically inspect ATMs before using them, and use continuous monitoring tools like Qondar to see whether your data has appeared in any data breaches.