FBI warns of surge in ATM Jackpotting, $20 Million lost in 2025

3 Min Read

The FBI warns ATM jackpotting is rising nationwide, with over $20 million lost in 2025 and 1,900 incidents reported since 2020.

The FBI has warned of a sharp rise in ATM jackpotting attacks across the U.S., with losses exceeding $20 million in 2025 alone. Since 2020, about 1,900 incidents have been reported, including 700 last year. According to the Department of Justice (DoJ), total losses tied to jackpotting have reached roughly $40.7 million since 2021.

“The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate indicators of compromise (IOCs) and technical details associated with malware enabled ATM jackpotting.” reads the FLASH alert published by the FBI. “Threat actors exploit physical and software vulnerabilities in ATMs and deploy malware to dispense cash without a legitimate transaction.”

Criminals are deploying ATM jackpotting malware such as Ploutus to force cash machines to dispense money without authorization. The malware targets the eXtensions for Financial Services (XFS) layer, which controls ATM hardware. By sending rogue commands directly to XFS, attackers bypass bank approval and trigger withdrawals without cards or accounts. Once installed, Ploutus gives full control of the ATM, enabling fast cash-outs in minutes.


What do you think? Post a comment.


To infect machines, attackers usually gain physical access, open the cabinet with generic keys, and either copy malware onto the hard drive or replace it with a preloaded one. Exploiting Windows systems, the malware works across different ATM brands with minimal changes.

- Advertisement -

EXPLORE MORE

US Forces Sink Vessel Providing At-Sea Refueling For Cartel: SOUTHCOM

Authored by Ryan Morgan via The Epoch Times, U.S. forces, on Aug.…

Canadian journalists warned not to call 9/11 a ‘terrorist attack’

(Journalists and editors employed by the Canadian Broadcasting Corporation (CBC) were warned…

From Track Star to WWE Champion: Inside Lainey Reid’s Rise to the Top

Whether she’s dominating in the ring on WWE’s SmackDown or holding gold…

Phillies take six-inning win in first rain-shortened game since 2022 – Phillies Nation

BALTIMORE — The third tarp pull was the charm for the Phillies…

Trump admin moves to curb power of top leftist lawyers’ association

The U.S. Department of Education (DOE) is recommending that the American Bar…

U.S. CISA adds RoundCube Webmail flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds RoundCube Webmail flaws to…

The Flash alert includes Indicators of Compromise (IOCs) for these attacks.

The jackpotting technique was first proposed by white-hat hacker Barnaby Jack in 2010.

Ploutus is one of the most sophisticated ATM malware that was first discovered in Mexico back in 2013. The malicious code allows crooks to steal cash from ATMs using either an external keyboard attached to the machine or by sending SMS messages.

In January 2018, experts at FireEye Labs discovered a new version of the Ploutus ATM malware, the so-called Ploutus-D, that works on the KAL’s Kalignite multivendor ATM platform.

FBI ATM jackpotting

The experts observed the Ploutus-D in attacks against ATM of the vendor Diebold, but the most worrisome aspect of the story is that minor changes to the malware code could allow Ploutus-D to target a wide range of ATM vendors in 80 countries.

Pierluigi Paganini



Share This Article

CONVERSATION

Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted