PCI Compliance After a Card Skimmer

By · Updated · 4 min read

Finding card-stealing code on your checkout is a different category of problem from finding spam on your blog. There is a defined framework governing what happens next, contracts you have already signed that require certain actions, and potential financial consequences that are not proportional to the size of your business. Here is the shape of it, in plain terms.

What PCI DSS is to you

The Payment Card Industry Data Security Standard is a set of security requirements that applies to anyone handling payment card data. You agreed to it when you signed up with your payment processor, even if nobody walked you through it, and it is contractual rather than statutory — which does not make it less binding.

The practical consequence of a skimmer is that a compromise of card data brings obligations under those agreements: notification, investigation, and remediation, with the specifics depending on your merchant level and your acquirer's requirements.

What to do in the first hours

Stop the harm. Disable checkout or take the store offline, because every additional order while a skimmer is live is another customer's card details taken and another increment of liability. This is the scenario where downtime is unambiguously the right call.

Preserve evidence before cleaning, because a forensic investigation may be required and altering the system first can compromise it — my guide on preserving evidence covers doing this quickly. Then notify your payment processor and acquiring bank promptly. That notification is typically a contractual requirement and delaying it tends to make everything that follows worse.

Forensic investigation

Depending on your transaction volume and your acquirer, you may be required to engage a PCI Forensic Investigator — an approved firm that conducts a formal investigation and reports to the card brands. This is not something you choose or run yourself, and it is not the same as a malware cleanup.

If that applies, it changes the order of operations significantly: preserve the system and take direction on when and how to remediate rather than cleaning first and asking later. Your acquirer will tell you whether it is required. If it is not required, you still need a proper technical cleanup, which is where my malware removal service comes in, and my guide on card skimmers covers the technical side.

The financial exposure

Be realistic about this. Potential costs include forensic investigation fees, card brand fines passed through by your acquirer, the cost of reissuing affected cards, liability for fraudulent transactions, and increased processing rates afterwards. For a small business these can be significant.

Two things reduce it: acting quickly, since the exposure scales with how many cards were taken and how long the skimmer ran, and cooperating fully. Cyber insurance, if you hold it, may cover a meaningful portion — notify your insurer early, because policies typically require prompt notification and may specify which responders you can use.

Reducing your scope in future

The structural lesson from most skimmer incidents is that the merchant was handling card data on pages they controlled, when they did not need to be. Moving to a hosted payment page or properly isolated payment fields means card details are entered into infrastructure your processor controls, so a compromise of your site cannot read them.

That reduces your PCI scope, simplifies your compliance obligations, and removes the most valuable target from your site. It comes with a small cost in checkout flow control, and after a skimmer incident that trade looks very different than it did before.

Beyond PCI

PCI obligations are not the whole picture. Card data is personal data, so data protection law may also apply, with its own regulator notification and customer notification requirements running on their own timetable — my guide on breach notification obligations covers that, and telling customers after a hack covers the communication.

Get professional advice rather than working from a guide, including mine. What this page can usefully do is tell you the shape of what is coming and the order to act in: stop the harm, preserve the evidence, notify your processor, take direction, then remediate.

Common questions

Do I have to report a skimmer to my payment processor?

Almost certainly yes — it is typically a contractual requirement under the agreement you signed, and prompt notification is generally required. Delaying tends to worsen every part of what follows, including your standing with the acquirer and any fines that are assessed.

Will I need a forensic investigator?

It depends on your merchant level and your acquirer's requirements. Higher transaction volumes commonly trigger a mandatory investigation by an approved firm. Your acquirer will tell you. If it applies, do not remediate before taking direction, because altering the system can compromise the investigation.

What might this cost?

Potentially forensic fees, fines passed through from the card brands, card reissuance costs, fraud liability and higher processing rates afterwards. The total scales with how many cards were exposed and for how long, which is why stopping the bleeding immediately matters so much financially.

Does using a payment processor mean I am not liable?

Not if the card details were entered on pages you control, because that is where the skimmer reads them. Using a hosted payment page or properly isolated payment fields, where the data goes directly to the processor's infrastructure, is what genuinely reduces both your risk and your compliance scope.

Is PCI the only obligation I have?

No. Card data is also personal data, so data protection law may apply with separate regulator and customer notification requirements on their own timelines. The two frameworks run in parallel and satisfying one does not satisfy the other.