Skip to main content
  1. Home
  2. Emerging Tech
  3. Legacy Archives

Infrared cameras can be used to steal PINs from ATMs

Add as a preferred source on Google
Image used with permission by copyright holder

Cameras, fake card readers, you name it… the list of schemes used to steal customer PINs at ATM machines is endless. Now it’s time to add another possible technique. Researchers at the University of California, San Diego recently presented the results of a study in which they found infrared cameras could be used to steal a PIN even after the customer left the ATM.

Led by Keaton Mowery, a doctoral student in computer science, the team found that they could measure the residual heat of ATM users’ fingers on the keypad. Using custom software that automated the camera’s heat-seeking abilities, they had 21 volunteers try out 27 random four-digit PINs on both plastic and brushed metal keypads.

Recommended Videos

The plastic pads were more insecure. If used immediately after the user entered his or her PIN, the team’s cameras accurately found the four digits in the PIN 80 percent of the time. After a minute, the success rate was still 50 percent.

With metal’s higher thermal conductivity, heat dissipated from those keypads almost instantly, making stealing numbers nearly impossible.

An additional issue is the fact that, while the team was able to find the digits users pressed, it wasn’t feasible to regularly discover their order. Still, that’s only 24 possible combinations to test out versus the 10,000 a thief would have to work through if he or she started from scratch. Also, with the concept already proven, it’s possible that further refinements could measure the heat difference between the button pressed first and those following, although that’s yet to be shown.

So should you just completely give up ATMs, force your employer to pay you in cash and walk around with stacks of twenties in your pockets? Well, you can if you want, but it’s probably not necessary. One, as a rule it’s not a good idea to use an ATM with camera guys lurking around anyway, and this is no exception. Two, using a metal keypad pretty much eliminates the possibility of this scam working unless a hidden camera was filming the whole time. In that case, it’s already prudent practice to cover the keypad while you enter your PIN. Common sense and a preference for metal keypads should protect the average Joe from this particular scheme, but you’re more than welcome to ice your fingertips beforehand if it makes you feel safer. 

Photo credit: Keaton Mowery, via PhysOrg

Derek Mead
Former Digital Trends Contributor
Google and Cathay Pacific are using AI to tackle aviation’s overlooked climate problem
A third of aviation's climate impact comes from contrails most people never think about.
Aircraft, Flight, Transportation

Those wispy white lines trailing behind airplanes (called contrails) sure look harmless from the ground, but they're doing more damage to the climate than we realize.

As part of Operating Blue Skies, Google has partnered with Cathay Pacific, one of the major international airlines operating both passenger and cargo flights, to test and deploy AI-driven contrail mitigation technology across a region where air travel is growing faster than anywhere else: Asia Pacific. 

Read more
The best tech of IFA 2026: a repairable laptop, liquid-cooled power bank, AI toothbrush, and more
From an AI toothbrush to a liquid-cooled battery, this is the best tech of IFA 2026
Best Of IFA 2026

IFA Berlin brought innovation from across the globe into one giant exhibition, and we got the chance to experience the new-gen "tech" firsthand. Walking through Messe Berlin, we saw a laptop designed to be repaired at home to a power bank with visible liquid coolant, an AI-powered toothbrush with a camera inside your mouth, and a robot vacuum carrying another.

The variety is what makes IFA one of the best tech shows. IFA 2026 runs from September 4 through 8, and we've spent our time in Berlin chasing down the products that caught our eyes. Some of these are clever ideas that may change how we use tech every day, while others solve a problem that I didn't realize existed.

Read more
OpenAI admits it needs to rethink what happens when AI goes rogue
As increasingly capable AI agents move beyond controlled tests, OpenAI is confronting a difficult question: When does strange model behavior become an incident the public deserves to know about?
OpenAI logo on blurred background

OpenAI has spent plenty of time explaining how it plans to stop increasingly capable AI agents from doing things they shouldn't. Now, the company says it needs to get better at telling everyone when those things have already happened. The admission follows reports of another previously undisclosed incident involving OpenAI's AI agents, this time affecting a German-language programming wiki. According to Reuters, agents made more than 15,000 unauthorized edits to DseWiki, using the site to communicate and share ways to bypass restrictions, cheat on tasks, and avoid detection.

OpenAI has now acknowledged what it calls the "wiki incident" and says the episode exposed a larger problem with how AI companies disclose unexpected model behavior. The company says it is developing a framework for deciding when and how to make incidents involving misaligned AI public.

Read more