Back to News
research

FBI says ATM ‘jackpotting’ attacks are on the rise, and netting hackers millions in stolen cash

Zack Whittaker
Loading...
3 min read
0 likes
⚡ Quantum Brief
The FBI reports a surge in ATM "jackpotting" attacks, with over 700 incidents in 2025 stealing at least $20 million. Criminals exploit physical and digital vulnerabilities to force machines to dispense cash. Hackers use generic keys to access ATM front panels, then install malware like Ploutus, which manipulates the Windows-based system to dispense cash without deducting from accounts. Ploutus malware targets XFS software, which controls ATM hardware like cash dispensers and card readers, granting hackers full control to trigger rapid cash withdrawals. Attacks occur in minutes and often go undetected until after the money is stolen, as the malware bypasses customer accounts and directly commands the ATM’s dispensing mechanism. The trend marks a shift from theoretical research—demonstrated by Barnaby Jack in 2010—to widespread criminal operations, exploiting long-known vulnerabilities in ATM security infrastructure.
AI Audio Summary
0:00 / 0:00
Click to play
gabriel-vasiliu-mdzxj9Ea7JM-unsplash.jpg
Quantum News · Media Library

In 2010, the famed security researcher Barnaby Jack spectacularly hacked into an ATM cash machine onstage at the Black Hat security conference, forcing it to spit out reams of bank notes in front of an awestruck audience. More than a decade later, ATM jackpotting — as it’s called — has broken free from the realms of theoretical security research into big business in the criminal world. According to a new security bulletin issued by the FBI, hackers have rapidly ramped up their attacks in recent years, with more than 700 attacks on cash dispensers during 2025 alone, netting hackers at least $20 million in stolen cash. Per the bulletin, the FBI says hackers are using a mix of physical access to ATM machines, such as generic keys for unlocking front panels and accessing hard drives, and digital tools, like planting malware that can force ATMs to rapidly dispense cash in a flash. The FBI warned that one particular malware, known as Ploutus, affects a variety of ATM manufacturers and cash dispensers by targeting the underlying Windows operating system that powers many ATMs. Ploutus grants the hackers full control over a compromised ATM, allowing them to issue instructions capable of tricking the dispenser into disbursing notes without drawing funds from customer accounts. Ploutus takes advantage of extensions for financial services, or XFS software, which ATMs rely on to communicate with its various other hardware components, such as the PIN keypad, the card reader, and the all-important cash dispensing unit. “Ploutus attacks the ATM itself rather than customer accounts, enabling fast cash-out operations that can occur in minutes and are often difficult to detect until after the money is withdrawn,” per the FBI bulletin. Security researchers previously found issues with XFS software that can allow hackers to trick ATMs into dispensing cash. Barnaby Jack, the late security researcher credited with the first ATM “jackpotting” attacksImage Credits:YouTube Updated the lede paragraph to amend date. Topics ATM, cash machine, cyberattacks, cybersecurity, jackpotting, Security Zack Whittaker Security Editor Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security. He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio October 13-15 San Francisco, CA Save up to $680 on your pass before February 27.Meet investors. Discover your next portfolio company. Hear from 250+ tech leaders, dive into 200+ sessions, and explore 300+ startups building what’s next. Don’t miss these one-time savings. REGISTER NOW Most Popular Meta’s own research found parental supervision doesn’t really help curb teens’ compulsive social media use Sarah Perez How Ricursive Intelligence raised $335M at a $4B valuation in 4 months Julie Bort After all the hype, some AI experts don’t think OpenClaw is all that exciting Amanda Silberling OpenClaw creator Peter Steinberger joins OpenAI Anthony Ha Hollywood isn’t happy about the new Seedance 2.0 video generator Anthony Ha The great computer science exodus (and where students are going instead) Connie Loizos A Stanford grad student created an algorithm to help his classmates find love; now, Date Drop is the basis of his new startup Amanda Silberling

Read Original

Source Information

Source: TechCrunch

Discussion

0 professional contributions

Sign in to join this professional discussion.

Be the first to add a constructive contribution.