ATM Jackpotting Exposed: How Malware Turns Bank Machines Into Cash Dispensers for Criminals + Video

Listen to this Post

Featured Image

Introduction: When an ATM Becomes the Target

An ATM is designed to do one simple thing: give customers access to their money. But in recent years, criminals have discovered a dangerous way to turn these machines against the financial institutions that operate them. Instead of stealing cards, guessing PINs, or physically breaking into cash machines, sophisticated crews can attack the computer inside an ATM and force it to dispense cash on command.

This technique, commonly known as ATM jackpotting, has become an increasingly serious cybersecurity and physical-security threat. It combines malware, unauthorized physical access, social engineering, and carefully planned movements to transform a protected banking terminal into an automated cash dispenser for criminals.

The latest case highlights just how persistent the threat has become. Five Venezuelan nationals have pleaded guilty in the United States to participating in attempts to steal money from ATMs using malware. Their operations in Kansas ultimately failed, but surveillance footage, alarms, and law-enforcement investigations helped bring the alleged conspirators to justice.

The case also comes against the backdrop of a much larger wave of ATM jackpotting attacks across the United States, with federal authorities warning that criminals stole more than $20 million through these schemes during the previous year.

The important lesson is not simply that several criminals were arrested. It is that an ATM is no longer just a physical machine containing cash. It is a computer connected to a highly valuable financial process—and that computer must be defended accordingly.

Five Defendants Plead Guilty

Five Venezuelan nationals have pleaded guilty to one count of conspiracy to commit bank larceny in connection with ATM jackpotting attempts.

The defendants identified in the case are 27-year-old Luis Alberto Velasquez-Artigas, 29-year-old Royder Adrian Figuera-Perez, 27-year-old Javier Mejia Jr., 33-year-old Gabriel Alejandro Corales-Garcia, and 26-year-old Italo Lizandro Corrales-Carrillo.

Velasquez-Artigas has already been sentenced to nine months in prison. The remaining defendants were awaiting sentencing at the time described in the original report.

The guilty pleas bring a legal conclusion to one part of the investigation, but the broader threat remains far from over.

The Dangerous Idea Behind ATM Jackpotting

ATM jackpotting works by attacking the computer system that controls an automated teller machine rather than directly attacking a customer’s bank account.

A compromised ATM can potentially be manipulated into treating unauthorized commands as legitimate instructions. If attackers succeed in gaining control of the machine’s internal computer, they may attempt to communicate with the cash dispenser and instruct it to release banknotes.

That is why the term “jackpotting” is so appropriate. Criminals are effectively trying to make the ATM behave like a slot machine that pays out whenever they issue the right command.

Unlike traditional ATM theft, this approach can allow attackers to extract large quantities of cash without needing thousands of stolen payment cards or customer PINs.

Malware Has Become a Major Weapon

Over the years, researchers and law-enforcement agencies have identified numerous malware families associated with ATM jackpotting.

Examples mentioned in connection with these attacks include ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus.

These malware families demonstrate how ATM attacks have evolved from crude physical theft into specialized cybercrime.

The

The technical details vary between malware families and ATM models, but the underlying concept is remarkably consistent: gain access to the machine’s computing environment, bypass its normal controls, and abuse its legitimate cash-dispensing functionality.

Physical Access Still Matters

One of the most interesting aspects of ATM jackpotting is that it sits directly between cybersecurity and physical security.

A criminal does not necessarily need to remotely compromise a bank’s entire network. In some scenarios, physical access to an ATM can provide an attacker with an opportunity to interact directly with the machine’s internal hardware.

Attackers have historically used devices such as USB keyboards or interacted with built-in ATM input mechanisms to deliver commands after compromising the system.

This makes physical security just as important as firewalls and endpoint protection.

A perfectly secured corporate network does not automatically protect an ATM that an attacker can physically manipulate.

The Kansas Attempts Failed

The five defendants were arrested in December 2025, after unsuccessful ATM jackpotting attempts in Wamego and Manhattan, Kansas.

The Wamego operation reportedly failed before the criminals could successfully install the malware.

More importantly, their activity triggered an alarm.

That alarm gave law enforcement an opportunity to respond, and the attackers did not return to the location.

The Manhattan attempt also failed to make the ATM dispense cash.

Both incidents were captured by surveillance cameras, creating valuable evidence that investigators could use to identify and eventually arrest the suspects.

Surveillance Became a Critical Defense

The Kansas incidents demonstrate why modern ATM security cannot rely entirely on software.

The criminals may have been attempting to exploit a technological weakness, but traditional security systems—including alarms and cameras—helped stop the operation.

This is a powerful reminder that cybersecurity is rarely about a single layer of defense.

An alarm can stop an intrusion that software fails to detect.

A camera can identify an attacker that an antivirus system never sees.

A bank employee can notice suspicious activity that an automated monitoring system misses.

The strongest security strategy combines all of these layers.

A Warning From Federal Authorities

U.S. Attorney Ryan A. Kriegshauser described ATM jackpotting criminals as a growing nationwide problem and emphasized that attackers deliberately search for ATMs they believe are more vulnerable to malware.

His warning also pointed toward an important defensive strategy: financial institutions need to invest in technologies and security updates capable of preventing jackpotting.

The message is straightforward.

ATM security cannot remain static while criminal techniques evolve.

Financial institutions have to continuously update operating systems, harden physical interfaces, monitor unusual behavior, restrict unauthorized devices, and ensure that ATM software cannot be easily manipulated.

The $20 Million Warning

The case becomes even more significant when viewed alongside a warning issued by the FBI in February.

According to the report, criminals stole more than $20 million during the previous year through a major increase in ATM jackpotting activity.

That figure illustrates why the threat deserves attention from financial institutions, law enforcement, cybersecurity professionals, and ATM manufacturers.

A single successful attack can potentially generate a significant financial loss in a very short period of time.

When criminal groups coordinate attacks against multiple ATMs, the damage can multiply rapidly.

The Tren de Aragua Connection

Federal investigations have also connected a major wave of ATM jackpotting activity to members of the Venezuelan criminal organization Tren de Aragua.

Authorities have alleged that members of the organization participated in large-scale ATM jackpotting operations involving Ploutus malware.

The use of a specialized malware family illustrates the increasingly professional nature of ATM crime.

This is not simply a matter of someone breaking open an ATM with a crowbar.

It can involve reconnaissance, malware, physical access, transportation, surveillance avoidance, cash collection, and coordination between multiple participants.

The more organized these operations become, the more important layered defenses become.

Dozens of Defendants Charged

The broader investigation has resulted in the Justice Department charging 87 alleged Tren de Aragua members in connection with criminal activity described in the case.

The defendants face potentially severe penalties, with maximum prison terms varying significantly depending on the charges.

These prosecutions also demonstrate that authorities are attempting to attack the criminal ecosystem rather than treating each ATM theft as an isolated incident.

That distinction matters.

When multiple attacks are connected to organized criminal networks, investigators can potentially identify common infrastructure, transportation patterns, money trails, accomplices, and repeat offenders.

Deportation After Conviction

The United States has also pursued immigration consequences in related ATM jackpotting cases.

In January, federal prosecutors in South Carolina announced that two Venezuelan nationals convicted in connection with jackpotting attacks would be deported after completing their sentences.

This reflects a broader approach in which criminal prosecution and immigration enforcement can intersect when foreign nationals are convicted of serious crimes.

Why ATM Jackpotting Is Different From Card Fraud

Traditional ATM fraud usually targets customers.

Criminals might steal payment cards, capture PINs, use skimmers, or obtain account credentials through phishing and malware.

Jackpotting takes a different path.

Instead of trying to withdraw a small amount from many customer accounts, criminals attempt to attack the ATM itself.

The victim therefore becomes the bank or ATM operator rather than an individual customer.

This changes the economics of the attack.

A successful jackpotting operation can potentially extract large quantities of cash from one physical location without compromising hundreds of individual bank accounts.

The ATM Is Essentially an Embedded Computer

One reason jackpotting remains possible is that modern ATMs are sophisticated computing platforms.

They contain operating systems, applications, network connections, peripheral devices, storage, authentication mechanisms, and specialized hardware.

The cash dispenser is simply one component of that larger system.

From a cybersecurity perspective, that means ATM manufacturers and financial institutions have to think about ATMs like highly specialized endpoints.

They require secure configurations, controlled software execution, patch management, application allowlisting, logging, physical tamper protection, and continuous monitoring.

Treating an ATM as “just a cash machine” is an increasingly dangerous mindset.

Deep Analysis: Understanding the Defensive Attack Surface

The First Layer: Physical Security

Financial institutions should begin with physical controls.

ATM cabinets, maintenance ports, USB interfaces, service panels, and internal components should be protected against unauthorized access.

Tamper detection should generate alerts when critical components are opened or manipulated.

Security cameras should cover ATM areas and provide sufficient visibility for investigators.

The Second Layer: Application Control

ATMs should run only authorized software.

Application allowlisting can help prevent unknown executables or unauthorized programs from running.

This is particularly important because jackpotting malware often attempts to operate within the ATM’s software environment.

The Third Layer: Device Control

Unauthorized USB devices should be restricted wherever operationally possible.

If a maintenance process requires external devices, banks should establish strict controls around who can use them, which devices are permitted, and when they can be connected.

The Fourth Layer: Network Isolation

ATM networks should be strongly segmented from ordinary corporate environments.

An attacker who compromises an ATM should not automatically gain a pathway into critical banking systems.

Network segmentation can reduce the potential blast radius of a successful intrusion.

The Fifth Layer: Monitoring

Security teams should monitor ATMs for unusual behavior.

Unexpected software changes, suspicious processes, unusual administrative activity, repeated errors, unexplained cash-dispensing events, and physical tampering should all trigger investigation.

Defensive Command Examples

For Linux-based ATM infrastructure or security monitoring systems, administrators can use defensive commands such as:

Review currently running processes

ps aux

Review listening network services

ss -tulpn

Check recent authentication activity

last

Review system authentication logs

journalctl --since "24 hours ago" | grep -Ei "auth|login|sudo"

Find recently modified executable files

find /usr /opt -type f -perm /111 -mtime -1 2>/dev/null

Generate SHA-256 hashes for approved files

sha256sum /path/to/application

These commands are examples for authorized defensive investigation. Actual ATM environments are highly specialized, and administrators should follow the platform manufacturer’s security guidance rather than blindly applying generic Linux procedures.

Windows-Based Monitoring

Where ATM infrastructure relies on Windows-based systems, defenders can use PowerShell to investigate running processes and services:

List running processes

Get-Process

List running services

Get-Service | Where-Object {$_.Status -eq "Running"}

Review recent Windows events

Get-WinEvent -LogName System -MaxEvents 100

Review security events

Get-WinEvent -LogName Security -MaxEvents 100

The goal is not simply to collect logs.

The goal is to establish a baseline and identify behavior that does not belong.

Why Legacy Systems Create Risk

Many specialized financial systems operate for years because replacing them is expensive and operationally difficult.

That creates an uncomfortable security problem.

A machine may still be functioning perfectly from a business perspective while running software that is increasingly difficult to secure.

Legacy operating systems, outdated applications, unsupported drivers, weak administrative controls, and obsolete interfaces can create opportunities for attackers.

This is one reason ATM modernization should be considered a security investment rather than merely an infrastructure upgrade.

Patch Management Is Not Optional

Security updates can address vulnerabilities that criminals may otherwise exploit.

But patching an ATM fleet is more complicated than patching ordinary office computers.

Banks must consider hardware compatibility, transaction availability, vendor certification, uptime requirements, and regulatory obligations.

Nevertheless, complexity cannot become an excuse for permanent stagnation.

Institutions need a structured process for testing and deploying security updates across ATM fleets.

The Human Element Remains Important

Technology alone cannot eliminate jackpotting.

Employees responsible for ATM maintenance need training to recognize suspicious behavior.

Physical access procedures must be documented.

Service credentials should be tightly controlled.

Maintenance sessions should be logged.

Third-party technicians should be authenticated and monitored.

An attacker who obtains legitimate maintenance credentials may be able to bypass defenses that would stop an ordinary intruder.

Credentials Can Become a Weak Link

One of the most important lessons from modern cybersecurity is that valid credentials can be just as dangerous as malware.

If criminals acquire legitimate credentials, defenders may struggle to distinguish malicious activity from authorized maintenance.

Financial institutions should therefore implement strong authentication, privileged-access management, credential rotation, least-privilege principles, and detailed auditing.

Administrative accounts should never have broader permissions than necessary.

Jackpotting Is Also an Intelligence Problem

Stopping these attacks requires more than protecting individual ATMs.

Banks need visibility across their entire ATM fleet.

If suspicious activity appears at one machine, security teams should be able to determine whether similar activity is occurring elsewhere.

Centralized logging can help identify patterns.

Threat intelligence can help identify known ATM malware.

Physical security teams can correlate camera footage with cybersecurity alerts.

The combination of these signals can reveal attacks much earlier.

Criminals Look for Weak Machines

The statement that attackers deliberately seek vulnerable ATMs is particularly important.

Cybercriminals do not necessarily need to compromise the strongest target.

They only need to find a weak one.

If an ATM fleet contains thousands of machines, a small number of poorly configured systems could become attractive targets.

That creates a fleet-wide security challenge.

The weakest ATM may effectively become the entry point for an expensive incident.

The Economics Favor Automation

Criminal organizations are constantly looking for ways to make theft more scalable.

ATM jackpotting fits that model.

Once a group understands a particular ATM platform, the same knowledge may potentially be applied to other machines using similar configurations.

Specialized malware can also make the process more repeatable.

That is why a successful jackpotting campaign should be treated as a potential indicator of a broader threat rather than an isolated event.

Banks Need More Than Antivirus

Traditional antivirus software has a role, but it should not be the only defense.

Specialized ATM environments require multiple controls working together.

These can include application allowlisting, secure boot, endpoint monitoring, hardware tamper detection, network segmentation, strong authentication, centralized logging, physical surveillance, and behavioral monitoring.

A criminal should have to defeat several independent security mechanisms rather than one.

The Importance of Secure Boot

Secure Boot and related platform-integrity mechanisms can help prevent unauthorized software from executing during the system startup process.

When properly implemented, they make it harder for an attacker to replace critical system components with malicious versions.

The effectiveness of such controls depends heavily on configuration and key management.

A security feature that exists only on paper does not provide meaningful protection.

Cash Dispensing Should Be Monitored

Banks should pay particular attention to unusual cash-dispensing behavior.

A machine that suddenly begins dispensing large quantities of cash outside normal customer patterns should be treated as a high-priority security event.

Behavioral detection can potentially identify suspicious activity faster than traditional signature-based malware detection.

This is especially important because attackers may modify malware or use previously unknown variants.

Physical and Digital Evidence Must Work Together

The Kansas case demonstrates the value of combining cybersecurity evidence with physical evidence.

Digital logs can reveal what happened inside a machine.

Cameras can show who was physically present.

Alarm systems can establish when suspicious activity occurred.

Access records can show which personnel were authorized to interact with the ATM.

Together, these sources create a much stronger investigative picture.

The Bigger Cybersecurity Lesson

ATM jackpotting is a reminder that cybersecurity increasingly extends into the physical world.

The same principles that protect servers and cloud infrastructure also matter for machines sitting on a street corner.

Every connected device can become part of an attack surface.

Every outdated operating system can become a liability.

Every unnecessary service can increase risk.

And every poorly protected physical interface can give an attacker an opportunity to cross the boundary between the digital and physical worlds.

What Undercode Say:

1. ATM Jackpotting Is a Hybrid Threat

ATM jackpotting is particularly dangerous because it combines cybercrime with physical crime.

2. The ATM Is the Endpoint

Banks should treat every ATM as a specialized endpoint requiring continuous security monitoring.

3. Physical Access Changes Everything

A criminal standing directly in front of a machine has opportunities that a remote attacker may not have.

4. Malware Makes Theft Scalable

Specialized malware can turn a complicated physical robbery into a repeatable technical operation.

5. Criminals Are Becoming More Specialized

The existence of dedicated ATM malware demonstrates the professionalization of financial cybercrime.

6. Legacy Technology Is a Risk

Older systems may continue working perfectly while becoming increasingly difficult to secure.

7. Security Updates Matter

Vendor-supported security updates should be treated as part of the ATM’s lifecycle rather than optional improvements.

8. Network Isolation Is Critical

An ATM should never have unnecessary access to sensitive corporate systems.

9. A Compromised ATM Should Stay Contained

Segmentation limits the damage if an individual machine is compromised.

10. Physical Security Is Cybersecurity

Locks, alarms, cameras, and tamper sensors can prevent digital attacks from becoming physical theft.

11. Cameras Remain Extremely Valuable

The Kansas incidents show that old-fashioned surveillance can complement sophisticated cybersecurity.

12. Alarms Can Stop the Attack Early

A triggered alarm can prevent attackers from completing the malware installation process.

13. Banks Need Centralized Visibility

Security teams should be able to monitor large ATM fleets from a central platform.

14. One Weak ATM Can Attract Criminals

Attackers often search for the easiest target rather than the most valuable one.

15. Fleet Security Must Be Consistent

Security standards should be applied across every ATM rather than only high-value locations.

16. Credentials Deserve Special Protection

Legitimate maintenance credentials can become extremely powerful weapons if stolen.

17. Least Privilege Should Apply Everywhere

Administrative access should be limited to precisely what technicians need.

18. Logging Should Be Comprehensive

Banks need enough telemetry to reconstruct suspicious activity after an incident.

19. Behavioral Detection Is Becoming More Important

Security teams cannot depend exclusively on known malware signatures.

20. Attackers Can Change Their Malware

New variants may evade traditional detection systems.

21. Hardware Security Matters

Secure hardware configurations can prevent some classes of unauthorized modification.

22. Secure Boot Can Strengthen Trust

The system should verify critical components before allowing them to execute.

23. USB Ports Should Be Controlled

External interfaces can become dangerous when physical access is not properly restricted.

24. Maintenance Needs Strong Governance

Every maintenance session should have a clear owner, authorization, and audit trail.

25. Third Parties Increase Complexity

Banks must also consider the security practices of vendors and contractors maintaining ATM fleets.

26. Jackpotting Is an Intelligence Challenge

Detecting one attack can provide clues about attacks against other machines.

27. Threat Intelligence Can Accelerate Defense

Knowledge about ATM malware families can help defenders identify suspicious behavior faster.

28. Law Enforcement Benefits From Better Telemetry

Detailed records can help investigators connect separate incidents to the same criminal network.

29. Criminal Networks Create Economies of Scale

Once attackers understand a particular ATM platform, that knowledge may potentially be reused.

  1. Financial Loss Is Only Part of the Damage

Banks can also face operational disruption, investigation costs, reputational damage, and customer concern.

31. ATM Security Should Be Risk-Based

Not every ATM faces identical threats, but every machine should meet a strong baseline.

32. Geographic Patterns Matter

Repeated attacks in particular areas can help investigators identify organized activity.

33. Timing Can Reveal Coordination

Multiple incidents occurring within a narrow period may indicate a coordinated campaign.

34. Security Teams Should Practice Incident Response

Banks need predefined procedures for isolating compromised ATMs and preserving evidence.

35. Detection Speed Matters

The faster suspicious cash dispensing is detected, the less money criminals may be able to steal.

36. Prevention Is Cheaper Than Recovery

Replacing compromised equipment and investigating theft is usually more expensive than maintaining adequate security controls.

37. Cybersecurity and Physical Security Must Collaborate

Neither department can fully solve ATM jackpotting independently.

38. ATM Manufacturers Also Carry Responsibility

Security must be designed into the hardware and software rather than added only after attacks occur.

39. The Threat Will Continue Evolving

As banks improve their defenses, criminals will search for new weaknesses and new ways to bypass controls.

  1. The Real Lesson Is Bigger Than ATMs

The same principle applies to payment terminals, smart kiosks, industrial systems, medical devices, and other connected machines: when a computer controls something valuable in the physical world, cybersecurity becomes physical security too.

✅ Five Defendants Pleaded Guilty

The supplied article identifies five Venezuelan nationals and states that each pleaded guilty to one count of conspiracy to commit bank larceny.

✅ The Kansas Attempts Were Unsuccessful

The source states that the Wamego and Manhattan ATM attacks failed to produce the intended cash theft and that both incidents were captured by surveillance systems.

✅ ATM Jackpotting Uses Malware

The description of jackpotting as an attack involving malware designed to manipulate an ATM’s cash-dispensing capabilities is consistent with the central technical explanation provided in the source.

✅ Multiple ATM Malware Families Have Been Reported

The article names ATMii, ATMitch, GreenDispenser, Alice, RIPPER, Skimer, SUCEFUL, and Ploutus as malware associated with ATM jackpotting activity.

⚠️ The $20 Million Figure Requires Context

The supplied article attributes the more-than-$20-million figure to an FBI warning concerning the previous year’s ATM jackpotting activity. Because the figure is time-dependent, it should be presented with its original reporting date and source when published independently.

⚠️ Criminal-Organization Attribution Should Be Carefully Worded

The supplied report links a major ATM jackpotting scheme to members of Tren de Aragua. Such allegations should be attributed to U.S. authorities rather than presented as proof that every person associated with the organization participated in ATM attacks.

⚠️ Sentencing Details Can Change

Velasquez-Artigas is described as having received a nine-month sentence, while the other defendants were awaiting sentencing in the source. Final sentencing information should therefore be updated if the article is republished later.

Prediction

(+1) ATM Security Will Become More Layered

Financial institutions are likely to increase investment in ATM hardening, application allowlisting, secure boot, tamper detection, network segmentation, and centralized behavioral monitoring as jackpotting becomes more sophisticated.

The future of ATM defense will probably not depend on one magical security product.

Instead, banks will build several defensive layers around every machine.

An attacker may still find a vulnerability, but successfully converting that vulnerability into cash theft will become increasingly difficult.

(+1) AI Will Improve ATM Threat Detection

Artificial intelligence and behavioral analytics could increasingly help financial institutions identify unusual dispensing patterns, suspicious maintenance behavior, anomalous software activity, and coordinated attacks across large ATM fleets.

The strongest use of AI here will not necessarily be replacing security teams.

It will be helping them recognize weak signals across thousands of machines that would be nearly impossible to correlate manually.

(+1) Physical Security Will Become More Cyber-Aware

ATM surveillance systems, tamper sensors, access-control systems, and cybersecurity platforms are likely to become more tightly integrated.

An unusual physical event could automatically trigger a cybersecurity investigation.

Likewise, suspicious software activity could cause security personnel to inspect the physical machine.

That convergence could make jackpotting significantly harder to execute unnoticed.

(-1) Criminals Will Search for Older ATMs

As modern machines become harder to compromise, criminals may increasingly concentrate their efforts on older, poorly maintained, or inadequately monitored ATM fleets.

This could create an uneven security landscape in which outdated machines become preferred targets.

(+1) Jackpotting Will Remain a Major Financial-Crime Concern

The arrest of individual attackers does not eliminate the underlying economics.

ATMs continue to hold physical cash, making them attractive targets.

As long as criminals can find machines with exploitable weaknesses, jackpotting will remain an area of concern for banks, ATM manufacturers, law enforcement, and cybersecurity researchers.

The Kansas case ultimately ended without the criminals successfully emptying the targeted ATMs. But the larger warning is impossible to ignore: the next ATM attack may not fail.

The financial industry therefore has a choice—wait for criminals to discover the next weak machine, or assume that every ATM is already being tested by someone looking for a way in. The institutions that choose the second approach will be far better prepared for the future of ATM security.

Condense the repetitive analysis section
Add a stronger reader-focused conclusion

▶️ Related Video (82% Match):

🕵️‍📝Let’s dive deep and fact‑check.

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

References:

Reported By: www.bleepingcomputer.com
Extra Source Hub (Possible Sources for article):
https://www.digitaltrends.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon | 📺Youtube