More

    ATM Jackpotting Incidents Skyrocketed in 2025 With the Help of Malware

    The FBI is reporting a major rise in hackers using malware to steal funds from ATMs.

    ATM jackpotting incidents, which involve manipulating the machines into dispensing cash, shot up across the US last year, the agency said in a public alert. “Out of 1,900 ATM jackpotting incidents reported since 2020, over 700 of them with more than $20 million in losses occurred in 2025 alone,” the FBI says. 

    In the past, hackers have delivered malware—including Ploutus, which has been around for over a decade—by opening the ATM’s casing and manually inserting a USB drive or even a CD. The most recent string of thefts has involved “opening an ATM face with widely available generic keys.” The criminals will then remove the machine’s hard drive and copy the malware to it. Or they’ll insert their own hard drive or external device loaded with the malware to initiate the jackpotting. 

    “Ploutus attacks the ATM itself rather than customer accounts, enabling fast cash-out operations that can occur in minutes and are often difficult to detect until after the money is withdrawn,” the alert adds. 

    In addition, Ploutus can bypass the bank authorization process and instruct the ATM to dispense cash on demand. “As a result, Ploutus allows threat actors to force an ATM to dispense cash without using a bank card, customer account, or bank authorization,” the agency added. 

    The FBI’s alert includes technical details, such as file and program names, about what banks should look for when scrutinizing their ATMs for possible signs of tampering. The agency is also urging ATM providers to consider changing standard locks, reinforcing casings, and implementing other security measures.

    The FBI released the alert after the Justice Department in December charged 54 individuals, some connected with the Venezuelan gang Tren de Aragua, for draining millions from ATMs across the US by using the Ploutus malware.  

    Images of the gang

    (Credit: DOJ)

    “These groups would conduct initial reconnaissance and take note of external security features at the ATMs,” federal officials said. “Following this reconnaissance, the groups would open the hood or door of ATMs and then wait nearby to see whether they had triggered an alarm or a law enforcement response.” 

    The suspects also “committed or attempted to commit at least 63 ATM jackpottings of the victim banks,” and targeted “at least 54 ATM jackpottings of the victim credit unions,” according to the indictment. “The overall loss to the Victim Financial Institutions was at least approximately $5,401,181, and at least an additional $1,429,738 was attempted.”

    About Our Expert

     

    Latest articles

    Related articles