Banks are facing a renewed physical threat as criminals shift tactics. The FBI warns that ATM jackpotting malware attacks are increasing across the country. Instead of stealing card details, attackers manipulate the machines directly to release cash.

What authorities observed

Investigators recorded hundreds of incidents during the past year. Losses reached tens of millions of dollars as organized groups targeted standalone and lobby ATMs. The attacks required onsite access rather than remote network intrusion.

The criminals did not breach bank databases. They targeted the hardware controlling the dispenser mechanism.

How the attack works

The method relies on opening the ATM cabinet and interacting with internal components. Many machines still use universal service keys, making entry easier than expected.

After gaining access, attackers typically:

  • Connect external devices or remove the drive
  • Install malicious software
  • Restart the machine
  • Trigger the cash dispenser remotely or via keypad input

Once infected, the ATM treats the command as legitimate maintenance activity and releases banknotes.

Malware used in the campaign

Investigators link most incidents to the Ploutus malware family. The program communicates directly with the cash dispenser using the machine’s service interface.

Because commands originate inside the system, monitoring software may not detect the activity immediately. In many cases, the machine empties before staff notice the compromise.

Why criminals favor jackpotting

This approach avoids traditional fraud detection. No stolen accounts appear, and no transfers occur. Criminals leave with physical money within minutes.

The method also reduces laundering complexity. Cash obtained onsite requires fewer financial traces compared to digital theft.

Warning signs for operators

Security teams should watch for unusual behavior around machines and internal logs showing maintenance activity outside scheduled service windows.

Common indicators include:

  • Unexpected cabinet openings
  • Sudden reboots
  • Rapid cash depletion
  • Unknown executables installed
  • Unauthorized devices connected internally

Conclusion

The rise of ATM jackpotting malware demonstrates how cybercrime now blends physical intrusion with software abuse. Protecting networks alone is no longer enough. Financial institutions must secure the machines themselves, limit service access, and monitor hardware activity to stop future attacks.


0 responses to “ATM Jackpotting Malware Surge Triggers FBI Alert”