Skip to main content

Secret Service warns of ‘jackpotting’ hackers targeting ATMs in the U.S.

atm
Hackers targeting ATMs are usually relatively subtle. Sometimes they install a “skimmer” that collects hundreds of customer PINs that can be used to drain accounts remotely, or fraudulent cards that bypass security measures and dispense hundreds of dollars, even when there’s no money in the account.

But what if you could make an ATM simply spew out all the cash it had in a matter of seconds?

These types of attacks are known as “jackpotting,” and government officials are quietly warning ATM manufacturers and financial institutions that jackpotting hackers have been spotted targeting cash machines here in the U.S.

According to a Secret Service memo obtained by Krebs on Security, the agency has received information that cybercriminals are planning to use “cash-out crews” to target ATMs manufactured by Diebold Nixdorf. It cites a series of thefts over the past ten days and warn of possible upcoming attacks across the country.

“The targeted stand-alone ATMs are routinely located in pharmacies, big box retailers, and drive-thru ATMs,” stated the alert. “During previous attacks, fraudsters dressed as ATM technicians and attached a laptop computer with a mirror image of the ATMs operating system along with a mobile device to the targeted ATM.”

The Secret Service alert says that criminals can use an endoscope — a device usually inserted into the human body during medical procedures — to look inside the ATM and find a place to connect their laptop to the internal mechanism.

Once connected, the criminals use a jackpotting malware program called Ploutus.D to remotely control the machine. “In previous Ploutus.D attacks, the ATM continuously dispensed at a rate of 40 bills every 23 seconds,” said the memo. The ATM is then emptied of cash in a matter of minutes.

The security firm FireEye first reported on Plotus attacks back in 2013 in Mexico, calling it a “technique that had never been seen before.”

If confirmed, these would be the first “jackpotting” attacks in the U.S. The Russian cyber firm Group IB previously reported similar attacks in Europe in 2016, as well as ATMs targeted in Thailand and Taiwan.

The ATM manufacturer confirmed to Reuters that it also issued a warning to banks and financial firms, but a Diebold Nixdorf spokesman declined to comment further or go into any detail about specific banks that had been targeted or how much cash had been lost.

Mark Austin
Former Digital Trends Contributor
Mark’s first encounter with high-tech was a TRS-80. He spent 20 years working for Nintendo and Xbox as a writer and…
U.K., U.S. say Russian hackers are trying to steal coronavirus research
bangladeshi bank heist foiled by spelling mistake internet hacking dark net

Russian hackers are targeting coronavirus vaccine research centers, according to a warning from security officials in the U.S., Canada, and the U.K.

Security departments from each country released a joint advisory on Thursday about the attempted hacks. The National Security Agency (NSA) said that malicious activity is from the well-known group known as APT29, which also goes by "CozyBear" or "The Dukes."

Read more
The FBI accuses China of trying to steal U.S. coronavirus vaccine research
coronavirus taiwan asia technology success science researcher getty

The FBI and the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency have accused China of attempting to steal coronavirus vaccine research from the U.S.

“The FBI is investigating the targeting and compromise of U.S. organizations conducting COVID-19-related research by PRC-affiliated cyber actors and non-traditional collectors,” according to a joint announcement Wednesday.

Read more
U.S. Senate reportedly warns members not to use Zoom
The U.S. Capitol building

The United States Senate is the latest to abandon videoconferencing app Zoom over its privacy issues, according to a report in the Financial Times.

The Senate's sergeant-at-arms has warned all senators not to use the service, which has been plagued by concerns over security and privacy. The report states senators were asked to use alternative platforms for videoconferencing but the warning stopped short of banning Zoom completely.

Read more