FBI warns of ATM Jackpotting incidents across America: What are they, how they work and how to detect one

FBI warns of ATM Jackpotting incidents across America: What are they, how they work and how to detect one

The Federal Bureau of Investigation (FBI) has released a flash to disseminate indicators of compromise (IOCs) and technical details associated with malware enabled ATM jackpotting. Threat actors exploitphysical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction. The FBI has observed an increase in ATM jackpotting incidents across the United States. Out of 1,900 ATM jackpotting incidents reported since 2020, over 700 of them with more than $20 million in losses occurred in 2025 alone. This FLASH is being provided to encourage organizations to implement the recommended mitigation steps and to outline the information requested from the public.Threat actors are deploying ATM jackpotting malware, including the Ploutus family malware, to infect ATMs and force them to dispense cash. Ploutus malware exploits the eXtensions for Financial Services (XFS), the layer of software that instructs an ATM what to physically do. When a legitimate transaction occurs, the ATM application sends instructions through XFS for bank authorization. If a threat actor can issue their own commands to XFS, they can bypass bank authorization entirely and instruct the ATM to dispense cash on demand. As a result, Ploutus allows threat actors to force an ATM to dispense cash without using a bank card, customer account, or bank authorization. Once Ploutus is installed on an ATM, it gives threat actors direct control over the machine, allowing them to trigger cash withdrawals. Ploutus attacks the ATM itself rather than customer accounts, enabling fast cash-out operations that can occur in minutes and are often difficult to detect until after the money is withdrawn.

Common methods of used to infect ATMs

After gaining access to ATMs, most often by opening an ATM face with widely available generic keys, ATM jackpotting threat actors have used several main methods to deploy malware:• Criminals remove the ATM’s hard drive, connect it to their computer, copy the malware to the hard drive, return the hard drive to the ATM, and reboot the ATM.• Criminals remove the ATM’s hard drive, replace it with a foreign hard drive or other external device with preloaded malware, and reboot the ATM.

How ATM malware works

The malware interacts directly with the ATM hardware, bypassing any communications or security of the original ATM software. The malware does not require connection to an actual bank customer account todispense cash. The malware can be used across ATMs of different manufacturers with very little adjustment to the code as the Windows operating system is exploited during the compromise.

What are the Physical Indicators of an infected ATM

* ATM door open alerts outside of planned maintenance schedule* Low/No cash indicators outside of expected use schedule* Unauthorized devices plugged into the ATM* Removal of hard drives from ATMs* ATM unexpectedly out of service

  • Related Posts

    Jensen Huang: After Nvidia share falls to zero in China, CEO Jensen Huang says: China should not have … |

    Nvidia CEO Jensen Huang has taken a firm stance on the global chip race, stating that for the company, America is the priority when it comes to selling its most…

    Anand Mahindra: “Who needs Pizza, when you can have…”: Anand Mahindra’s love for this Indian food is quite relatable

    Anand Mahindra, Chairman of Mahindra Group, is known for sharing his unfiltered thoughts on social media. From providing shelter and LPG connection to most recently gifting a SUV to para-archer…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Tamil Nadu: Can’t afford another poll, our aim to ensure stable government, says DMK | India News

    Tamil Nadu: Can’t afford another poll, our aim to ensure stable government, says DMK | India News

    West Bengal: Governor dissolves assembly even as Mamata Banerjee refuses to quit | India News

    West Bengal: Governor dissolves assembly even as Mamata Banerjee refuses to quit | India News

    Shakira teases new song for FIFA World Cup 2026; unveils ‘Dai Dai’ with Afrobeats star Burna Boy – WATCH |

    Shakira teases new song for FIFA World Cup 2026; unveils ‘Dai Dai’ with Afrobeats star Burna Boy – WATCH |

    US to revoke passports of thousands of parents over unpaid child support, starting with debts above $100,000

    US to revoke passports of thousands of parents over unpaid child support, starting with debts above $100,000

    The great white giant turns blue: The final act of Iceberg A-23A |

    The great white giant turns blue: The final act of Iceberg A-23A |

    Tanishaa Mukerji praises Dhurandhar but says Bollywood has become ‘colder’: ‘Less about values, more about money and profits’ |

    Tanishaa Mukerji praises Dhurandhar but says Bollywood has become ‘colder’: ‘Less about values, more about money and profits’ |