Back to all lessons
Awareness Lessons
last month

ATM Jackpotting Scheme Exposes Physical and Logical Security Gaps

Five Venezuelan nationals pleaded guilty after attempting to install malware on ATMs in Kansas to force unauthorized cash dispensing — a technique known as 'jackpotting.' The attack required physical access to the ATM internals, highlighting how both physical and logical security controls must work in tandem to protect financial infrastructure. With over 1,900 FBI-reported jackpotting incidents since 2020, this is a growing and organized threat vector targeting legacy or poorly secured ATM hardware. Financial institutions that fail to harden ATM configurations and monitor for anomalous dispensing behavior remain highly vulnerable to significant financial losses.

Tactical Insight

Immediate Actions

  • Conduct a physical security audit of all ATMs to ensure tamper-evident seals, locked cabinets, and surveillance cameras are in place.
  • Review and restrict ATM operating system access by disabling USB ports and external boot media to prevent malware installation.

Long-term Improvements

  • Deploy application whitelisting on ATM systems to prevent unauthorized software from executing.
  • Establish a routine patch management schedule specifically for ATM firmware and embedded operating systems.
  • Implement network segmentation to isolate ATM networks from general corporate infrastructure and limit lateral movement.

Detection Measures

  • Set up real-time alerting for anomalous cash dispensing patterns, such as rapid or after-hours withdrawals exceeding defined thresholds.
  • Integrate ATM logs into a centralized SIEM platform to enable continuous monitoring and rapid incident detection.
  • Require two-person integrity (TPI) protocols for any physical ATM servicing or maintenance activity.