Americans Lost Over $20 Million From ATM Theft, FBI Reports
## Cybersecurity: ATM Jackpotting Incidents
Cybersecurity: ATM Jackpotting Incidents
According to the FBI, ATM jackpotting incidents in the United States have significantly increased. In a FLASH alert issued last week, the FBI reported that more than 700 of the 1,900 recorded incidents since 2020 occurred in 2025 alone, resulting in losses exceeding $20 million last year.
ATM jackpotting involves attackers using malware to force ATMs to dispense cash without a legitimate transaction. The FBI indicates that threat actors exploit physical and software vulnerabilities in ATMs, often gaining physical access to the machine before installing malicious code.
The United States Department of Justice has charged six additional defendants in connection with an international ATM jackpotting scheme, bringing the total number of defendants to 93. The Justice Department reported that the overall financial loss to victim institutions exceeds $6 million, with an additional $1.74 million attempted. Each jackpotting attempt typically results in losses exceeding $100,000.
The FBI notes that attackers are deploying malware from the Ploutus family to compromise ATMs. Ploutus targets the eXtensions for Financial Services (XFS), which controls the physical operations of the machine. During a legitimate transaction, the ATM application communicates with XFS for bank authorization. However, attackers can issue commands to XFS, bypassing authorization and prompting the machine to release cash. This malware does not require a bank card, customer account, or approval from a financial institution.
According to the FBI, ATM jackpotting incidents in the United States have significantly increased.
The malware targets the ATM rather than individual customer accounts, enabling attackers to withdraw cash within minutes, often before the breach is detected. Attackers frequently gain entry using generic keys available online. They may remove the hard drive, copy malware onto it, reinstall it, and reboot the ATM. Alternatively, they might replace the hard drive with another device preloaded with malicious software.
Court documents allege that Tren de Aragua, a transnational criminal organization originating from a Venezuelan prison gang, is responsible for conducting jackpotting attacks across the United States. An indictment issued in December last year alleges that members used jackpotting to steal millions of dollars and transfer proceeds among associates to conceal illegally obtained cash. Charges include conspiracy to commit bank fraud, bank burglary, computer fraud, money laundering, and providing material support to a designated foreign terrorist organization. Defendants, if convicted, face maximum penalties ranging from 20 to 335 years in prison. An indictment is an allegation, and all defendants are presumed innocent until proven guilty in court.
The FBI has identified several technical and physical indicators that may suggest an attack on Windows-based ATMs. Unexpected executable files, such as Newage.exe, Color.exe, Levantaito.exe, NCRApp.exe, sdelete.exe, Promo.exe, WinMonitor.exe, WinMonitorCheck.exe, and Anydesk1.exe, can indicate compromise. Suspicious files like C.dat, Restaurar.bat, and Logcontrol.txt may also appear, and the presence of unauthorized remote connection software such as TeamViewer or AnyDesk raises suspicion.
Physical signs include ATM doors opening outside scheduled maintenance, low or no cash alerts outside normal usage patterns, unauthorized devices plugged into the machine, and hard drive removal. USB insertion events logged as Event ID 6416 and file access events logged as Event ID 4663 may also occur during an attack.
The FBI recommends that financial institutions verify file hashes against a known gold image of approved software and treat any deviation as a potential compromise. Banks are urged to report suspicious activity to local field offices or the Internet Crime Complaint Centre.
Based on reporting by techround.co.uk.
