Point-of-sale skimming is a payment-security risk that retail staff can help detect early. Criminals may tamper with a payment terminal, add an overlay, alter cabling, substitute a device, or use a fake service visit to access payment data. Staff are not expected to perform technical forensics. They are the people closest to the checkout, so their job is to notice what is different, stop unsafe activity, and report it quickly.
This guide explains how to build a practical point-of-sale skimming awareness programme for retail teams. It focuses on repeatable checks, safe escalation, and training that works across opening, closing, peak-trading, and casual shifts.
TL;DR
- Teach staff to compare terminals with an approved reference, including serial number, labels, position, cables, and accessories.
- Make a start-of-shift check part of normal opening and handover routines.
- Never allow an unverified technician, replacement device, overlay, or new connection near a payment terminal.
- If something looks different, stop using the device when safe, preserve the scene, and report through the incident process.
- Measure completed checks, reporting speed, and follow-up quality rather than blaming people for missing a subtle sign.
Why retail staff need skimming training
Skimming is the unauthorised capture and transfer of payment data for fraudulent purposes. The Payment Card Industry Security Standards Council’s merchant guidance describes several routes, including capture from a payment card, a compromised terminal or terminal infrastructure, malicious software, wireless interfaces, contactless readers, and overlays. A device can look ordinary while the compromise is hidden inside it or in the equipment around it.
That is why awareness training cannot be reduced to a poster saying “watch for unusual devices”. Retail employees need to know what normal looks like in their store, which changes require approval, and what to do when a terminal, cable, label, person, or process does not match the reference. The PCI SSC’s Skimming Prevention: Best Practices for Merchants recommends maintaining device records, inspecting terminals for tampering or substitution, training personnel, and having an incident response plan.
The goal is not to make a cashier confront a suspected criminal or dismantle a payment device. The goal is an early, safe report that gives the store manager, payment provider, and security team a chance to contain the risk.
What you will need
- A current register of every terminal, lane, stand, cable, and approved accessory
- A reference photo or approved description for each device type
- A start-of-shift and handover checklist
- A known contact for the store manager, acquirer, payment provider, and technology support
- A simple reporting route that works during busy trading and outside office hours
- Short scenarios for permanent, casual, and agency staff
The training steps
1. Map the checkout environment
Walk through the store and record where payment devices are located, who can access them, and what connects to them. Include fixed tills, self-service lanes, mobile terminals, back-office computers, routers, charging docks, spare devices, and storage areas. Note which terminals are unattended during quiet periods or after closing.
Do not assume that a small shop has a small attack surface. One heavily used terminal may process most of the store’s transactions. A quiet lane may also be easier to access without being noticed. Use a cyber security gap assessment to organise the inventory and identify missing ownership, but keep the operational checklist specific to each location.
2. Define what normal looks like
Take an approved reference photo when each terminal is installed or checked. Record the make, model, serial number, position, stand, power cable, network cable, security labels, seals, card slot, keypad, and nearby equipment. Include the normal screen, connection path, and any approved protective housing.
The reference should answer a simple question: what would a staff member notice if this device had been moved, substituted, opened, covered, or connected to something new? PCI SSC guidance recommends checking the serial number on the device against its electronic record and looking for changed labels, seams, cables, or unfamiliar equipment.
Staff should not open a terminal or try to remove a suspected overlay. A reference is for comparison and reporting, not for self-repair.
3. Build a start-of-shift check
Make the check short enough to complete before the first customer arrives. The person opening the store should confirm that the device is in the approved position, the serial number matches the record, labels and seals look unchanged, cables follow the expected route, and no extra reader, camera, attachment, or box has appeared nearby.
Ask staff to look for changes, not for a particular brand of skimmer. Warning signs can include a loose or unusually thick card slot, a new overlay, damaged or replaced labels, a different cable, an unfamiliar connection, a changed stand, a device that has been swapped, or an unannounced instruction sheet. A single sign may have an innocent explanation, but it still deserves a check through the known support route.
Add the same check to shift handover. A device that was normal at opening may be unattended later, and the next team needs to know who last inspected it.
4. Set rules for technicians and replacements
A person who claims to be a technician must not receive automatic access to a payment device. Staff should verify the visit through the store’s known provider contact, confirm the work order, check the technician’s identity according to the business process, and involve the manager before equipment is moved, replaced, connected, or taken away.
Do not use the phone number on an unexpected message, sticker, or printed instruction to verify the request. Use the number in the approved contact list or provider portal. Record the old and new serial numbers when a replacement is authorised, and keep the old device according to the provider’s instructions.
The rule is not “never let a technician work”. It is “no unverified access to payment equipment”. That distinction keeps service safe without making frontline employees responsible for judging technical credentials.
5. Protect the payment interaction
Staff should keep the payment area visible and avoid placing unapproved objects beside, above, or between the customer and the terminal. They should give customers reasonable privacy when entering a PIN and report cameras, mirrors, unusual displays, or people attempting to interfere with the device. Staff should never ask a customer to enter a PIN into a phone, an unfamiliar reader, or a device that is not the approved payment terminal.
Train employees to notice behaviour as well as hardware. Someone distracting a cashier, blocking the view of a terminal, asking to move it, or insisting on a particular connection may be creating an opportunity for tampering. Staff do not need to accuse the person. They should pause the request and call the manager.
6. Teach the safe response
Use a four-part response that every shift can remember:
- Stop: do not continue a transaction on a device that may be altered or substituted, unless the manager or payment provider gives a safe direction.
- Protect: keep customers and staff away from the suspected equipment when it can be done safely; do not touch, unplug, open, or dismantle it.
- Report: tell the manager and use the approved incident route, including the terminal location, serial number, time, people involved, and visible change.
- Preserve: leave messages, photos, work orders, receipts, and device details available for the authorised response team.
A human risk reporting workflow can help collect reports and assign follow-up. If payment data, a device, or a customer may be affected, the store’s incident owner should contact the acquirer, payment provider, insurer, or relevant adviser through the established process.
7. Practise across every shift
Run short exercises during team meetings, opening briefings, and manager handovers. Use realistic but harmless scenarios: a terminal has a different label, a replacement arrives without a work order, a cable is routed differently, an unfamiliar person requests access after closing, or a new object appears beside a self-service reader.
Ask staff to show where they would report the concern and what they would say. Do not use a live payment device, real card data, real customer information, or an exercise that could cause a genuine transaction to stop unexpectedly. The desired behaviour is a fast report and safe isolation, not a perfect diagnosis.
Include casual and agency workers. A five-minute briefing at onboarding is more reliable than assuming a temporary worker will learn the process from observing a busy shift. Security awareness training can reinforce the same stop, protect, report, and preserve pattern across payment, phishing, and social-engineering scenarios.
8. Measure the control, not the person
Track whether each location completed its scheduled device checks, whether handovers recorded the last inspection, how quickly concerns reached the manager, and whether follow-up was documented. Review repeated changes by lane, shift, supplier, or store. A rise in reports can be healthy if staff are reporting earlier and the reports are being resolved.
Avoid a target that rewards zero reports. It can teach employees to ignore subtle changes. Use phishing awareness practice as a model for safe coaching: explain the signal, reinforce the safer action, and make reporting easier the next time. If the business is comparing training platforms, the security awareness platform comparison can help assess assignments, reporting, and evidence.
Troubleshooting
- The store has no reference photo. Ask the payment provider or manager to approve a current image and record the terminal details before starting the routine.
- The serial number is hard to find. Do not guess. Ask the provider for the approved location and update the register during a scheduled check.
- A technician arrives during a rush. Pause access until the manager verifies the work order; urgency does not replace verification.
- A device looks different after a legitimate repair. Keep it out of service until the new serial number, labels, cables, and approval are recorded.
- Staff are afraid to report a false alarm. Explain that an early report is the expected behaviour and that authorised support decides whether the change is legitimate.
- Several stores use the same device model. Keep the reference and serial register location-specific; a correct model can still be substituted or moved.
A practical 30-day rollout
In the first week, inventory terminals and appoint an owner for each store. In the second, approve reference photos, contact routes, and the start-of-shift checklist. In the third, brief every shift and run one harmless scenario. In the fourth, review completion, response time, and any confusing step, then update the checklist. Repeat the exercise after a terminal replacement, store refit, payment-provider change, or real incident.
Keep the PCI SSC skimming guidance with the procedure, and use security awareness training to maintain the wider reporting habit. The programme should sit alongside payment-provider controls and the current PCI DSS standard information; staff training does not replace technical, contractual, or compliance requirements.
What to do next
Choose one store and complete a supervised terminal walk-through. Produce the reference record, run the two-minute check, and ask a staff member to report a simulated change. Fix the process where the report gets stuck before rolling it across the rest of the retail network.
FAQ
What is point-of-sale skimming?
Point-of-sale skimming is the unauthorised capture of payment data for fraudulent use. It may involve a payment card, a terminal, terminal infrastructure, software, wireless communication, contactless equipment, or an overlay.
Can staff spot every skimming device?
No. Some compromises are hidden and cannot be identified by visual inspection. Staff can still reduce risk by comparing devices with an approved reference, reporting changes, controlling access, and stopping use when the manager or provider directs it.
What should a cashier do if a terminal looks different?
The cashier should stop using it when safe, avoid touching or dismantling it, keep customers away if necessary, tell the manager, and record the location, time, serial number, and visible change. The authorised response team should decide whether it is safe to return the terminal to service.
How should retail staff handle an unexpected technician?
They should not grant access automatically. They should verify the visit and work order through a known provider contact, involve the manager, and record any approved device movement, replacement, or new serial number.
How often should POS terminals be checked?
Set a routine that fits the store, such as at opening, during handover, and after an unattended period, then review it with the payment provider and security owner. The important controls are consistent inspection, clear ownership, and a response route when something changes.
Does staff training replace PCI DSS controls?
No. Training supports the people and process side of payment security. It must operate alongside approved devices, provider controls, access management, incident response, and the organisation’s current PCI DSS obligations.
Should staff take a terminal apart to investigate?
No. Staff should not open, unplug, remove overlays, or repair a suspected device unless authorised support directs the action. Handling the device can create safety, evidence, and payment-acceptance problems.
One last thing
A retail employee does not need to identify a skimmer to protect the store. They need permission to pause, a reference for what normal looks like, and a reporting route that responds quickly.
Related guides
Sources
- Skimming Prevention: Best Practices for Merchants, PCI Security Standards Council, accessed August 2026.
- PCI Data Security Standard, PCI Security Standards Council, accessed August 2026.