Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FBI Warns of Rising ATM Jackpotting Losses Exceeding M

FBI Warns of Rising ATM Jackpotting Losses Exceeding $20M

Posted on February 20, 2026 By CWS

The Federal Bureau of Investigation (FBI) has raised concerns over a surge in ATM jackpotting incidents nationwide, which have resulted in financial losses exceeding $20 million in 2025 alone. Since 2020, there have been 1,900 reported cases of such attacks, with 700 occurring in the past year. In December 2025, the U.S. Department of Justice (DoJ) reported that a total of $40.73 million has been lost to these attacks since 2021.

Understanding the Jackpotting Threat

ATM jackpotting involves cybercriminals exploiting both physical and software vulnerabilities in ATMs, often by deploying malware to dispense cash unlawfully. The FBI, in a recent bulletin, highlighted that threat actors use sophisticated malware, such as Ploutus, to gain unauthorized control over ATM systems. Commonly, attackers access machines using widely available generic keys, allowing them to open the ATM face and inject the malware.

The malware is usually installed by either removing the ATM’s hard drive and connecting it to an attacker’s computer or replacing it with a foreign drive preloaded with malicious software. Once installed, the malware interacts directly with ATM hardware, bypassing the existing security measures of the original software. This enables the malware to operate across various ATM models with minimal code modifications, exploiting the Windows operating system.

Mechanics of Malware Deployment

First observed in Mexico in 2013, Ploutus has evolved to provide cybercriminals with full control over ATMs, facilitating rapid and undetectable cash withdrawals. According to the FBI, the malware manipulates the eXtensions for Financial Services (XFS) software, which directs ATM actions. By issuing unauthorized commands through XFS, attackers can bypass the usual bank authorization process, making it possible to dispense cash on demand.

This sophisticated attack method requires no bank card or customer account interaction, significantly increasing its effectiveness and reach. The FBI emphasized the urgency of understanding these tactics to implement effective countermeasures.

Preventive Measures and Recommendations

In response to the growing threat, the FBI has suggested several strategies to mitigate the risks associated with ATM jackpotting. Key recommendations include enhancing physical security by installing threat sensors, security cameras, and replacing standard locks on ATM devices. Additionally, financial institutions are advised to audit ATM devices regularly, change default credentials, and configure automatic shutdowns when compromise indicators are detected.

Further measures involve enforcing device allowlisting to prevent unauthorized connections and maintaining comprehensive logs for monitoring purposes. These steps aim to bolster security protocols and reduce the vulnerability of ATMs to jackpotting attacks.

As cyber threats continue to evolve, it is imperative for organizations to remain vigilant and proactive in safeguarding their financial assets against such sophisticated criminal activities.

The Hacker News Tags:ATM security, ATM vulnerabilities, banking security, cash dispensing, Cybercrime, Cybersecurity, FBI, financial crime, financial losses, Jackpotting, Malware, Ploutus, security measures, U.S. Department of Justice, XFS software

Post navigation

Previous Post: AI-Driven Penetration Testing with 20+ Integrated Tools
Next Post: Ransomware Attack Targets Advantest’s Network

Related Posts

Russian Group Linked to Malware Attacks on Ukraine Russian Group Linked to Malware Attacks on Ukraine The Hacker News
Why Default Passwords Must Go Why Default Passwords Must Go The Hacker News
175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign 175 Malicious npm Packages with 26,000 Downloads Used in Credential Phishing Campaign The Hacker News
Entra ID Data Protection: Essential or Overkill? Entra ID Data Protection: Essential or Overkill? The Hacker News
NVIDIA Triton Bugs Let Unauthenticated Attackers Execute Code and Hijack AI Servers NVIDIA Triton Bugs Let Unauthenticated Attackers Execute Code and Hijack AI Servers The Hacker News
Critical WordPress Plugins, Themes Vulnerabilities Exposed Critical WordPress Plugins, Themes Vulnerabilities Exposed The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AppViewX Enhances AI Security with New Tools
  • Cyberattack Exposes Data of Over 1 Million in Arizona Courts
  • Criminal IP Unveils AITEM: Revolutionizing Cybersecurity
  • Iranian Hackers Exploit Fake Coding Test to Infiltrate Iraqi Systems
  • Aembit Enhances Security for AI Agents in Enterprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AppViewX Enhances AI Security with New Tools
  • Cyberattack Exposes Data of Over 1 Million in Arizona Courts
  • Criminal IP Unveils AITEM: Revolutionizing Cybersecurity
  • Iranian Hackers Exploit Fake Coding Test to Infiltrate Iraqi Systems
  • Aembit Enhances Security for AI Agents in Enterprises

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark