FBI warns of ATM Jackpotting incidents across America: What are they, how they work and how to detect one

FBI warns of ATM Jackpotting incidents across America: What are they, how they work and how to detect one

The Federal Bureau of Investigation (FBI) has released a flash to disseminate indicators of compromise (IOCs) and technical details associated with malware enabled ATM jackpotting. Threat actors exploitphysical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction. The FBI has observed an increase in ATM jackpotting incidents across the United States. Out of 1,900 ATM jackpotting incidents reported since 2020, over 700 of them with more than $20 million in losses occurred in 2025 alone. This FLASH is being provided to encourage organizations to implement the recommended mitigation steps and to outline the information requested from the public.Threat actors are deploying ATM jackpotting malware, including the Ploutus family malware, to infect ATMs and force them to dispense cash. Ploutus malware exploits the eXtensions for Financial Services (XFS), the layer of software that instructs an ATM what to physically do. When a legitimate transaction occurs, the ATM application sends instructions through XFS for bank authorization. If a threat actor can issue their own commands to XFS, they can bypass bank authorization entirely and instruct the ATM to dispense cash on demand. As a result, Ploutus allows threat actors to force an ATM to dispense cash without using a bank card, customer account, or bank authorization. Once Ploutus is installed on an ATM, it gives threat actors direct control over the machine, allowing them to trigger cash withdrawals. Ploutus attacks the ATM itself rather than customer accounts, enabling fast cash-out operations that can occur in minutes and are often difficult to detect until after the money is withdrawn.

Common methods of used to infect ATMs

After gaining access to ATMs, most often by opening an ATM face with widely available generic keys, ATM jackpotting threat actors have used several main methods to deploy malware:• Criminals remove the ATM’s hard drive, connect it to their computer, copy the malware to the hard drive, return the hard drive to the ATM, and reboot the ATM.• Criminals remove the ATM’s hard drive, replace it with a foreign hard drive or other external device with preloaded malware, and reboot the ATM.

How ATM malware works

The malware interacts directly with the ATM hardware, bypassing any communications or security of the original ATM software. The malware does not require connection to an actual bank customer account todispense cash. The malware can be used across ATMs of different manufacturers with very little adjustment to the code as the Windows operating system is exploited during the compromise.

What are the Physical Indicators of an infected ATM

* ATM door open alerts outside of planned maintenance schedule* Low/No cash indicators outside of expected use schedule* Unauthorized devices plugged into the ATM* Removal of hard drives from ATMs* ATM unexpectedly out of service

  • Related Posts

    Jensen Huang: After Nvidia share falls to zero in China, CEO Jensen Huang says: China should not have … |

    Nvidia CEO Jensen Huang has taken a firm stance on the global chip race, stating that for the company, America is the priority when it comes to selling its most…

    Anand Mahindra: “Who needs Pizza, when you can have…”: Anand Mahindra’s love for this Indian food is quite relatable

    Anand Mahindra, Chairman of Mahindra Group, is known for sharing his unfiltered thoughts on social media. From providing shelter and LPG connection to most recently gifting a SUV to para-archer…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Taurus Horoscope Today, May 8, 2026: Buy quality, not quantity

    Taurus Horoscope Today, May 8, 2026: Buy quality, not quantity

    ‘Crime against children’ rises by 6% in 2024 compared to 2023, over 69000 POCSO cases registered: NCRB | India News

    ‘Crime against children’ rises by 6% in 2024 compared to 2023, over 69000 POCSO cases registered: NCRB | India News

    Did Vijayan’s over-projection prove its undoing? CPM begins analysis of Kerala debacle | India News

    Did Vijayan’s over-projection prove its undoing? CPM begins analysis of Kerala debacle | India News

    Cuncolim woman loses Rs 2 lakh to cyber fraudsters posing as Delhi Police, Google officials | Goa News

    Cuncolim woman loses Rs 2 lakh to cyber fraudsters posing as Delhi Police, Google officials | Goa News

    Pakistani green card holder spent 21 years behind bars for murder in New York, arrested again by ICE after release

    Pakistani green card holder spent 21 years behind bars for murder in New York, arrested again by ICE after release

    Filmmaker Raj Chakraborty announces decision to quit politics after poll setback |

    Filmmaker Raj Chakraborty announces decision to quit politics after poll setback |