The FBI warns ATM jackpotting is rising nationwide, with over $20 million lost in 2025 and 1,900 incidents reported since 2020.
The FBI has warned of a sharp rise in ATM jackpotting attacks across the U.S., with losses exceeding $20 million in 2025 alone. Since 2020, about 1,900 incidents have been reported, including 700 last year. According to the Department of Justice (DoJ), total losses tied to jackpotting have reached roughly $40.7 million since 2021.
“The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate indicators of compromise (IOCs) and technical details associated with malware enabled ATM jackpotting.” reads the FLASH alert published by the FBI. “Threat actors exploit physical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction.”
Criminals are deploying ATM jackpotting malware such as Ploutus to force cash machines to dispense money without authorization. The malware targets the eXtensions for Financial Services (XFS) layer, which controls ATM hardware. By sending rogue commands directly to XFS, attackers bypass bank approval and trigger withdrawals without cards or accounts. Once installed, Ploutus gives full control of the ATM, enabling fast cash-outs in minutes.
To infect machines, attackers usually gain physical access, open the cabinet with generic keys, and either copy malware onto the hard drive or replace it with a preloaded one. Exploiting Windows systems, the malware works across different ATM brands with minimal changes.
EXPLORE MORE
Canadian Tire 2025 data breach impacts 38 million users
A data breach at Canadian Tire exposed personal data from over 38…
Wrong GoW, Right Role: Dave Bautista Reportedly Set To Play Kratos In God Of War Series
Following the on-set injury that forced lead actor Ryan Hurst to exit Prime Video's God…
Former U.S. Defense contractor executive sentenced for selling zero-day exploits to Russian broker Operation Zero
A former employee at U.S. defense contractor L3Harris got over 7 years…
Judge allows taxpayer-funded abortions to resume in Pennsylvania temporarily
HARRISBURG, Pennsylvania — Commonwealth Court Judge Matthew Wolf has declined to allow…
Claude code abused to steal 150GB in cyberattack on Mexican agencies
Hackers abused Claude Code to build exploits and steal 150GB of data…
Luxury hotel stays for just €0.01. Spanish police arrest hacker
Spanish police arrested a 20-year-old hacker accused of booking luxury hotel rooms…
The Flash alert includes Indicators of Compromise (IOCs) for these attacks.
The jackpotting technique was first proposed by white-hat hacker Barnaby Jack in 2010.
Ploutus is one of the most sophisticated ATM malware that was first discovered in Mexico back in 2013. The malicious code allows crooks to steal cash from ATMs using either an external keyboard attached to the machine or by sending SMS messages.
In January 2018, experts at FireEye Labs discovered a new version of the Ploutus ATM malware, the so-called Ploutus-D, that works on the KAL’s Kalignite multivendor ATM platform.

The experts observed the Ploutus-D in attacks against ATM of the vendor Diebold, but the most worrisome aspect of the story is that minor changes to the malware code could allow Ploutus-D to target a wide range of ATM vendors in 80 countries.
