That light piece of paper that comes out of the ATM has the harmless look of nothing. It is taken, folded badly, slipped into a pocket or ends up in the bin next to the counter, on top of other identical receipts, in that little landfill of automatic habits that no one really looks at. Yet right there, among faded thermal paper, cut numbers and timetables printed by the minute, a scam that is much less imaginative than it seems can begin.
The ATM receipt scam works like this: Someone retrieves a document we left lying around after a withdrawal and uses those details to build a credible phone call. No movies, no hooded hackers in front of seven green monitors. Much simpler. A piece of paper, a telephone, a fairly confident voice, the usual urgency disguised as protection.
On the receipt, depending on the branch and the bank, data such as date and time of the operation, place of withdrawal, amount withdrawn, last digits of the card and sometimes even the available balance may appear. On their own they seem like poor fragments. Put together, they become context. And the context, in banking scams, is worth a lot.
The leaflet that gives credibility
The scammer needs one thing even before the codes: to be believed. If he calls saying “I’m from your bank”, our distrust can still hold. If you add “the contact for the collection carried out today at 3.12pm at the street counter…” the body changes posture. The brain lets its guard down. That information is true, so the rest might be, too.
This is where social engineering comes into play, that is, the ability to manipulate a person using real information, emotional pressure and time pressure. The ATM receipt becomes a kind of script. The fake operator talks about suspicious movements, urgent checks, temporary blocks, security procedures. It all sounds as technical as it gets. Everything seems to be done to protect us.
Then comes the request that should trigger the alarm: password, PIN, OTP code, confirmation on the app, immediate authorization of an operation. The ABI, in its indications against scams, recalls a very clear rule: when the bank contacts the customer, it never asks to provide personal access codes directly and invites people to be wary of urgent requests for credentials or sensitive data. At that moment the receipt has already done its dirty work: it has made a foreign voice familiar.
Small card, big risk
Your ATM receipt falls into that annoying category of documents that seem too trivial to merit attention. The US Federal Trade Commission explicitly includes it among the documents to be destroyed before being thrown away, along with other papers with personal or financial information. The advice is simple: when a document contains economic or identifying data, it should be destroyed; without paper shredder, at least shredded in a serious way.
The practical point is even drier: the paper receipt is rarely needed. Today almost all operations can be traced from the bank app, from home banking or from the bank statement. Printing the sheet and then leaving it next to the counter is a double lightness: it produces useless paper and gives details to those who know how to use them.
Of course, one abandoned receipt alone is usually enough to empty an account. The damage occurs when that data is linked to other pieces: an already available telephone number, an email address that ended up in some old data leak, an overly generous social profile, a well-constructed call. Modern scams thrive on entanglements. They collect crumbs and turn them into a plausible story.
The most convenient rule is also the safest
The first defense is to stop printing. Really. If the receipt only serves to reassure us for ten seconds, it is better to check the movement from the app or keep it in the digital bank statement. The less paper we turn around, the less data remains hanging on our distraction.
However, when the receipt is used for a check, it must be taken and taken away. Never left in the bin at the counter, never placed on the edge of the ATM, never thrown whole in the bin at the next bar. Once the operation is verified, it is destroyed. Cutting it in two with a symbolic air is of little use. Better to break it into small pieces, especially in the part where the location, time, amount and numbers of the card appear.
And if a suspicious call comes in, it shuts down. Without long explanations, without feeling rude, without getting dragged into the emergency play. Then you call the bank using the official number, that of the app, the site or the back of the card. Those who really work to protect us can wait those thirty seconds. Those who demand haste usually really want to stop us from thinking.
You might also be interested in: