Bruce Schneier has a blog post about attacking bank-card PINs.

Basically, the paper describes an inherent flaw with the way ATM PINs are encrypted and transmitted on the international financial networks, making them vulnerable to attack from malicious insiders in a bank.

Just the fact that there are standalone ATMs in places like bus stations, seedy bars, and convenience stores worries me. Any bank in the whole ATM network could be the weak link.