PIN is actually completely optional.
A rogue terminal can decide to authorize the transaction with a “signature” (there are legitimate uses for this)
Or even with no PIN at all (there are also legitimate uses for this)
It’s also possible to do either of these 2 things and then report back that the transaction what authorized with a PIN