Policy & Regulation
FBI warns of rising ATM jackpotting attacks
The FBI reports a surge in ATM jackpotting, with more than 700 attacks in 2025 resulting in at least $20 million in stolen cash.
The Federal Bureau of Investigation (FBI) has issued a security bulletin warning that ATM jackpotting attacks are increasing and becoming a significant criminal business. According to the FBI, the technique has transitioned from a theoretical security concern into an active threat. The agency recorded more than 700 attacks on cash dispensers during 2025 alone. These incidents have resulted in at least $20 million in stolen cash.
The FBI bulletin details how hackers are using a mix of physical access and digital tools to execute these attacks. Physically, hackers gain access to the ATM itself by using methods such as generic keys to unlock front panels and access hard drives. Digitally, they deploy malware to force the machines to dispense cash. The FBI warned that one particular malware, known as Ploutus, affects a variety of ATM manufacturers and cash dispensers by targeting the underlying Windows operating system that powers many ATMs. By compromising the operating system, Ploutus grants hackers full control over the machine, allowing them to force the cash dispensers to release funds.
Specifically, Ploutus exploits Extensions for Financial Services (XFS), the software ATMs use to communicate with hardware components like the PIN keypad, card reader, and cash dispensing unit. According to the FBI bulletin, “Ploutus attacks the ATM itself rather than customer accounts, enabling fast cash-out operations that can occur in minutes and are often difficult to detect until after the money is withdrawn,”. This distinction is critical: the attack targets the physical cash reserves of the machine itself, meaning individual customer accounts and balances are not directly drawn from or affected during the theft.
The rise of these attacks marks a shift in the threat landscape. ATM jackpotting was once a theoretical concept. In 2010, security researcher Barnaby Jack demonstrated the technique at the Black Hat security conference, hacking an ATM to force it to dispense cash in front of an audience. More than a decade after that demonstration, ATM jackpotting has broken free from the realms of theoretical security research to become a significant criminal business.
Why it matters
The FBI’s warning highlights the evolution of ATM jackpotting from theoretical research into a lucrative, high-volume criminal enterprise that bypasses customer accounts to target hardware directly.