There's all this emphasis on the idea that buying stuff on the internet is somehow more risky than in person, but that's hugely inaccurate. As long as you're not using something dumb like email to send your credit card (ie, you're using an SSL transaction) then it's not going to be intercepted. But the pimply faced clerk at the Blockbuster or tourist shop who swipes your card, then writes down the number from their copy of the receipt is 10x harder to track down, and 10x more likely to actually _do it_.
I had a card cloned about 5 years ago, we never found out where, but someone was trying to use the clone locally, so we're pretty sure it was a person at a face to face biz.