Drooid Logo
Back to story perspectives

Full Breakdown

Surge in ATM Jackpotting Attacks: FBI Reports Over $20 Million Lost in 2025

2/21/2026, 3:54:06 AM

Overview of ATM Jackpotting Incidents

The Federal Bureau of Investigation (FBI) has issued a warning regarding a significant rise in ATM jackpotting incidents across the United States, with over 700 attacks recorded in 2025 alone, resulting in losses exceeding $20 million. Since 2020, approximately 1,900 jackpotting incidents have been reported, highlighting a troubling trend in cybercrime targeting automated teller machines (ATMs).

How Jackpotting Works

ATM jackpotting involves cybercriminals exploiting both physical and software vulnerabilities in ATMs to dispense cash without legitimate transactions. Attackers typically gain physical access to the machines using widely available generic keys, allowing them to open the ATM's maintenance panel. Once inside, they can either remove the hard drive to install malware or replace it with a preloaded hard drive containing malicious software. One of the most prevalent strains of malware used in these attacks is Ploutus, which targets the eXtensions for Financial Services (XFS) software layer that controls ATM operations. By issuing unauthorized commands through XFS, attackers can bypass bank authorization and trigger cash disbursements directly from the machine.

The Impact of Ploutus Malware

Ploutus malware, first identified in Mexico in 2013, has evolved into a sophisticated tool for cybercriminals. It allows attackers to gain complete control over infected ATMs, enabling rapid cash withdrawals that can occur in minutes. The FBI has noted that these attacks do not target individual customer accounts but rather the ATM itself, making them difficult to detect until after the funds have been withdrawn. The total losses attributed to jackpotting since 2021 have reached approximately $40.73 million, according to the U.S. Department of Justice.

Recommendations for Prevention

In response to the rising threat of ATM jackpotting, the FBI has outlined several recommendations for financial institutions to enhance their security measures. These include:

  • Installing threat sensors and security cameras around ATMs.
  • Changing standard locks and conducting regular audits of ATM devices.
  • Configuring automatic shutdown protocols to activate upon detecting signs of compromise.
  • Implementing device allowlisting to restrict unauthorized access.
  • Maintaining comprehensive logs of ATM operations to monitor for suspicious activity.

Criticism and Concerns

Despite the FBI's proactive measures and recommendations, concerns remain regarding the effectiveness of current security protocols in preventing jackpotting attacks. Critics argue that many ATMs still operate on outdated software and hardware, leaving them vulnerable to exploitation. Additionally, the reliance on physical security measures may not be sufficient to deter determined attackers.

Conclusion

The surge in ATM jackpotting incidents poses a significant threat to financial institutions and their customers. As cybercriminals continue to refine their tactics, it is imperative for banks and ATM operators to adopt robust security measures to safeguard against these increasingly sophisticated attacks. The FBI's alert serves as a crucial reminder of the need for vigilance in protecting critical financial infrastructure from evolving cyber threats.