Drooid Logo
Back to story perspectives

Full Breakdown

Surge in ATM Jackpotting Attacks: A Growing Cybersecurity Concern

3/24/2026, 1:30:22 AM

Overview of ATM Jackpotting Attacks

The Federal Bureau of Investigation (FBI) has issued a cybersecurity alert regarding a significant increase in ATM jackpotting attacks across the United States. These attacks involve hackers manipulating ATMs to dispense cash without legitimate transactions. Since 2020, nearly 1,900 such incidents have been reported, with over a third occurring in the last year alone. In 2025, losses attributed to these attacks have already surpassed $20 million.

Mechanism of Attack

ATM jackpotting typically involves physical access to the machine. Attackers often use generic keys to open the ATM's maintenance cabinet, where they can remove the storage drive. They then load malware, such as the Ploutus strain, onto the drive. This malware targets the XFS software that ATMs use to communicate with bank networks, allowing the attackers to bypass standard authorization processes and command the machine to dispense cash.

Vulnerabilities in ATM Systems

Many ATMs operate on outdated versions of Windows, which were released in 2009 and are no longer supported. This obsolescence creates vulnerabilities that attackers can exploit across various ATM brands and financial networks. The FBI has noted that these attacks are not limited to specific banks or manufacturers, highlighting a widespread issue within the ATM infrastructure.

Recommendations for Financial Institutions

In response to the rising threat, the FBI has recommended several defensive measures for financial institutions, including:

  • Monitoring ATMs for unauthorized files and suspicious executables.
  • Disabling USB ports to prevent malware installation.
  • Replacing generic locks with keypad systems.
  • Enhancing physical security with secondary alarms.

While these measures are practical, their nationwide implementation is a slow process, leaving many ATMs vulnerable to ongoing attacks.

Broader Implications for Consumers

Although jackpotting attacks primarily target banks, the financial repercussions can indirectly affect consumers. When banks incur losses, they may pass these costs onto customers through higher fees, increased service charges, and stricter policies. Thus, while individuals may not be the direct victims, they ultimately bear the financial burden of these cybercrimes.

Personal Safety Measures at ATMs

Consumers can take proactive steps to protect themselves when using ATMs:

1. Use ATMs located in well-lit, secure areas.

2. Avoid isolated machines, especially at night.

3. Be vigilant for unusual ATM behavior, such as unexpected reboots.

4. Check for signs of tampering before using a machine.

5. Cover the keypad when entering a PIN to prevent shoulder surfing.

6. Enable real-time transaction alerts for account activity.

7. Regularly review bank statements for unauthorized charges.

8. Consider identity theft monitoring services.

9. Utilize contactless or in-app ATM withdrawals when available.

10. Keep banking apps updated to ensure security patches are applied.

Conclusion

The rise in ATM jackpotting attacks underscores the importance of cybersecurity in everyday financial transactions. As technology evolves, so do the tactics of cybercriminals, making it essential for both financial institutions and consumers to remain vigilant and proactive in safeguarding their assets.