Swiss authorities are warning the public about a sharp rise in sophisticated banking fraud that targets physical payment card chips through direct social engineering rather than traditional high-tech ATM skimming. According to the Federal Office for Cyber Security (BACS), criminals are tricking victims into destroying their cards while preserving the microchip, which is subsequently collected and used to drain thousands of francs from accounts.
Evolution from Magnetic Stripe Skimming to Chip Targeting
Traditional skimming relied on physical attachments placed on automated teller machines or payment terminals to capture static data from a card’s magnetic stripe alongside the accompanying PIN. Modern payment cards utilize embedded computer chips that generate unique cryptographic security codes for every individual transaction, rendering static stripe data useless to attackers. According to BACS data, contemporary threat actors bypass robust chip cryptography entirely by convincing account holders to surrender the functional chip components voluntarily.
The Social Engineering Playbook and Card Mutilation Tactics
The fraudulent scheme begins with an SMS message falsely attributed to a banking institution, claiming that the recipient’s account has experienced suspicious activity or unauthorized transactions. The text instructs targets to dial a specific phone number where a fraudster posing as a bank representative claims the card must be destroyed immediately for security reasons. Victims are directed to cut their physical plastic cards with scissors while carefully avoiding the embedded chip module. According to BACS incident reports, fraudsters then instruct targets to place the mutilated card into an envelope for postal return or direct home collection by a supposed bank courier. Attackers subsequently repair the recovered chip, pair it with a stolen personal identification number, and execute fraudulent ATM withdrawals. In one documented Swiss case investigated by authorities, criminals stole more than 10,000 Swiss francs after convincing a victim to cut their card and artificially inflate daily transaction limits.

Official Guidance and Preventative Measures
Financial institutions and cybersecurity regulators emphasize that banks never dispatch representatives to residential addresses to collect payment cards, partial card components, microchips, or security credentials. BACS advises consumers never to sever or mutilate payment cards based on instructions received via unsolicited telephone calls, text messages, or electronic mail. Account holders should never disclose PIN codes over the phone, regardless of whether the caller claims to represent a recognized financial institution. Individuals who suspect they have fallen victim to this social engineering tactic must immediately contact their bank via official customer service channels to lock their accounts and prevent further unauthorized transactions.
Worth a look