Domenica 26 Luglio 2026 18:53:36 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContattiLogin
ItalianoEnglish

Ransomware & Extortion

Criminal Hackers Crack Open America’s Cash Machines: Inside the 2025 ATM Jackpotting Epidemic

Published: 20 February 2026 01:07Category: Ransomware & ExtortionGeo: North AmericaAuthor: SECPULSE

Subtitle: FBI reveals more than 700 ATM jackpotting attacks in 2025 alone, exposing banks and credit unions to over $20 million in losses.

It starts with a simple key-one you can buy online for a few dollars. In the dead of night, a small team approaches an unsuspecting ATM. Within minutes, they’re inside the machine, not to steal cash with crowbars, but with something far more potent: malware. By dawn, the criminals have vanished, leaving behind an empty vault and a trail that’s nearly impossible to follow.

Fast Facts

  • Over 700 ATM jackpotting incidents struck the U.S. in 2025, causing more than $20 million in losses.
  • The FBI has tracked nearly 2,000 attacks since 2020, with the notorious Ploutus malware leading the charge.
  • Criminals exploit both physical and software vulnerabilities, often bypassing bank authorization entirely.
  • A single gang indicted in 2025 stole at least $5.4 million from 63 ATMs in less than two years.
  • ATMs from multiple manufacturers-using Windows operating systems-remain vulnerable to these attacks.

The Anatomy of a Jackpotting Attack

The FBI’s recent flash alert paints a stark picture: ATM jackpotting, once a niche cybercrime, has become a nationwide epidemic. The core technique? Deploying advanced malware such as Ploutus, which lets criminals take direct control of an ATM and order it to spit out cash-no card, no PIN, no legitimate transaction required.

Here’s how these jackpotters operate: Using generic keys, they open the ATM’s case and access the hard drive. In some cases, they swap it out entirely; in others, they connect it to a laptop and load the malware. Once Ploutus is installed, the malware communicates directly with the ATM’s hardware, bypassing all the security built into the bank’s software. The result: rapid, undetectable theft, often completed before anyone notices.

The secret sauce lies in exploiting “eXtensions for Financial Services” (XFS)-a software layer that normally routes legitimate instructions from the ATM to the bank. But with Ploutus, hackers can issue their own commands straight to XFS, sidestepping all checks and balances.

The attacks aren’t limited by brand or geography. Since its first appearance in Mexico in 2013, Ploutus has evolved to target ATMs from major vendors like Diebold Nixdorf and Kalignite, adapting to different models with minimal tweaks, thanks largely to their reliance on the Windows operating system.

The FBI and Justice Department are playing catch-up. A recent indictment exposed a nationwide network that looted millions from credit unions, with single machines sometimes losing $100,000 or more in a night. Yet for every gang caught, dozens more are learning, adapting, and refining their methods.

The Road Ahead

Experts have sounded the alarm for years: as long as ATMs remain physically accessible and run on aging software, the jackpotting threat will persist. For banks and credit unions, the message is clear-bolster both digital and physical security, or risk being the next victim in this high-stakes cybercrime spree.

WIKICROOK

  • ATM Jackpotting: ATM jackpotting is a cyberattack where criminals force ATMs to dispense cash illegally by exploiting software or hardware vulnerabilities.
  • Ploutus: Ploutus is advanced ATM malware that enables attackers to dispense cash and erase evidence, posing a major threat to financial institutions.
  • XFS (eXtensions for Financial Services): XFS is a software framework that standardizes communication between ATMs and banking systems, enabling secure and efficient device integration for banks.
  • Hard Drive Swap: A hard drive swap involves physically replacing a device’s storage unit to install, run, or hide unauthorized code, often bypassing security controls.
  • Windows Operating System: Windows OS, developed by Microsoft, is a popular platform for PCs and ATMs, making it a frequent target for malware and cyberattacks.